Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.2) | 0.20% | — | DiscordchatexporterAI | 21/8/2026 | 30/9/2026 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter.Core/Exporting/MessageGroupTemplate.cshtml and render it without HTML entity… | |
| Aplazada | Media (4.1) | 0.16% | — | DiscordchatexporterAI | 21/8/2026 | 30/9/2026 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates emoji.Name into the alt attribute and emoji.Code into the title attribute without HTML entity encoding. This affects HTML exports regardless of… | |
| Analizada | Media (4.3) | 0.34% | — | Rocket.chat | 21/8/2026 | 4/9/2026 | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6. 8.3.8, 8.2.8, 8.1.8, and 7.10.15, the Meteor DDP methods getThreadsList and getThreadMessages accept rid / tmid as raw, untyped parameters with no schema validation. A MongoDB operator object (e.g. {"$gt": "4"}) can be substituted for a string room-id… | |
| Analizada | Alta (7.5) | 0.48% | — | Rocket.chat | 21/8/2026 | 4/9/2026 | Rocket.Chat in versions before 8.8.0, 8.7.1, 8.6.2, 8.5.3, 8.4.6, 8.3.8, 8.2.8, 8.1.8, and 7.10.15 has a REST API endpoint POST /api/v1/livechat/visitor that accepts an unauthenticated, unsanitized name field for Livechat visitors. This name is stored raw and later rendered via dangerouslySetInnerHTML in the… | |
| Aplazada | Alta (7.1) | 0.25% | — | Premio Chaty PROAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Chaty Pro <= 3.5.8 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Gingerplugins Sticky Chat WidgetAI | 18/8/2026 | 20/8/2026 | Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions. | |
| Aplazada | Media (6) | 0.21% | — | Aotuman Grab Wechat ArticlesAI | 18/8/2026 | 20/8/2026 | Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions. | |
| Aplazada | Alta (7.5) | 0.39% | — | FormychatAI | 18/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in FormyChat <= 2.15.7 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Wise ChatAI | 18/8/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcin Wise Chat wise-chat allows Stored XSS.This issue affects Wise Chat: from n/a through 3.4.2. | |
| Aplazada | Alta (8.3) | 0.35% | — | StoatchatAI | 17/8/2026 | 24/9/2026 | stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumerate members and monitor profile updates of private servers without membership. Attackers can subscribe to any server's member-update topic by sending a Subscribe message… | |
| Aplazada | Alta (7.1) | 0.38% | — | StoatchatAI | 16/8/2026 | 26/8/2026 | stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requiring ReadMessageHistory. Attackers with ViewChannel access but ReadMessageHistory denied can retrieve individual message content by ID, bypassing the intended history… | |
| Aplazada | Media (6.9) | 0.36% | — | StoatchatAI | 16/8/2026 | 31/8/2026 | stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass protections via the /proxy and /embed endpoints. Attackers can craft requests using IPv6 literal syntax to access services on the loopback interface and retrieve… | |
| Aplazada | Alta (8.7) | 0.34% | — | StoatchatAI | 16/8/2026 | 24/9/2026 | stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas. | |
| Modificada | Media (6.5) | 0.64% | — | Microsoft Github Copilot Chat | 11/8/2026 | 24/9/2026 | No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. | |
| Pendiente de análisis | Media (4.3) | 0.33% | — | Rocketchat Rocket ChatAI | 10/8/2026 | 9/9/2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the channels.convertToTeam REST endpoint allows an authenticated registered user with the create-team permission to convert an unrelated public channel by supplying… | |
| Pendiente de análisis | Media (5.4) | 0.22% | — | Rocketchat Rocket ChatAI | 10/8/2026 | 9/9/2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 7.10.14, 8.0.8, 8.1.7, 8.2.7, 8.3.7, 8.4.5, 8.5.2, and 8.6.1, the stream-notify-user stream in the WebSocket protocol allows an authenticated user to write arbitrary notification bodies because the sender is not checked, and… | |
| Aplazada | Media (6.7) | 0.57% | — | ChatwootAI | 10/8/2026 | 9/9/2026 | Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules, Macros, and Twilio Channels to other accounts through the writable account_id parameter. This could break tenant isolation and cause cross-account data exposure,… | |
| Aplazada | Alta (7.6) | 0.28% | — | Lobehub Lobe-chatAI | 10/8/2026 | 28/8/2026 | A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary JavaScript into the application by uploading a crafted SVG file as a user avatar. | |
| Pendiente de análisis | Media (4.3) | 0.27% | — | Jenkins Google Chat NotificationAI | 5/8/2026 | 31/8/2026 | Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use. | |
| Aplazada | Alta (7.5) | 2.0% | — | Aiwu AI Chatbot Workflow AutomationAI | 5/8/2026 | 12/8/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without authentication or authorization checks. The… | |
| Aplazada | Media (6.5) | 0.43% | — | Chatwoot Chat WidgetAI | 4/8/2026 | 26/8/2026 | The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate the type, extension, content, or size of files submitted to its public response endpoint and stores them under the uploads directory, so an unauthenticated user can upload… | |
| Aplazada | Alta (7.5) | 0.41% | — | AI Chatbot FOR WoocommerceAI | 2/8/2026 | 26/8/2026 | The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to… | |
| Aplazada | Alta (8.1) | 0.38% | — | Chat ON Desk Order NotificationsAI | 1/8/2026 | 26/8/2026 | The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS… | |
| Analizada | Crítica (9.8) | 0.38% | — | Rocket.chat | 30/7/2026 | 25/8/2026 | Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature… | |
| Aplazada | Media (5.3) | 0.30% | — | Lets ChatAI | 28/7/2026 | 30/7/2026 | Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server by sending a DELETE request to the rooms handler without ownership verification. Attackers can enumerate room IDs via the rooms listing endpoint and permanently archive… |