Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.86% | — | Gaizhenbiao Chuanhuchatgpt | 27/6/2024 | 17/6/2026 | A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as users are unable to authenticate. | |
| Modificada | Alta (7.5) | 0.66% | — | Gaizhenbiao Chuanhuchatgpt | 27/6/2024 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-provided keyword and attempts to match it against chat history filenames using a… | |
| Analizada | Crítica (9.8) | 0.53% | — | Gaizhenbiao Chuanhuchatgpt | 27/6/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests from the vulnerable server to internal or external resources, potentially bypassing… | |
| Modificada | Media (6.1) | 0.59% | — | Gaizhenbiao Chuanhuchatgpt | 6/6/2024 | 17/6/2026 | gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of uploaded file types in its `/upload` endpoint. Specifically, the `handle_file_upload` function does not sanitize or validate the file extension or content type of uploaded files, allowing attackers… | |
| Modificada | Alta (7.5) | 1.4% | 💥 PoC | Gaizhenbiao Chuanhuchatgpt | 6/6/2024 | 17/6/2026 | A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240310 of the software, where passwords are compared using the '=' operator in Python. This method of comparison allows an attacker to guess… | |
| Modificada | Media (6.5) | 0.50% | — | Gaizhenbiao Chuanhuchatgpt | 6/6/2024 | 17/6/2026 | In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to bypass intended access restrictions and read the `history` files of other users, potentially leading to unauthorized access… | |
| Modificada | Media (5.4) | 0.46% | — | Gaizhenbiao Chuanhuchatgpt | 6/6/2024 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. Despite user-input validation efforts, the application fails to properly sanitize or validate the output from the model, allowing for the… | |
| Modificada | Crítica (9.8) | 3.8% | 💥 Exploit | Gaizhenbiao Chuanhuchatgpt | 6/6/2024 | 17/6/2026 | The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict user access to resources within the `web_assets` folder. However, the outdated version of gradio it employs is susceptible to path traversal, as… | |
| Modificada | Alta (7.5) | 0.52% | — | Gaizhenbiao Chuanhuchatgpt | 4/6/2024 | 17/6/2026 | An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other user without requiring any form of interaction between the users. Exploitation of this vulnerability… | |
| Analizada | Alta (7.5) | 0.60% | — | Gaizhenbiao Chuanhuchatgpt | 16/5/2024 | 17/6/2026 | A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerability arises due to improper input validation when handling file paths during the chat history upload process. An attacker can exploit this… | |
| Analizada | Alta (7.5) | 0.78% | — | Gaizhenbiao Chuanhuchatgpt | 10/4/2024 | 17/6/2026 | gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling attackers to obtain sensitive information such as API keys (`openai_api_key`,… | |
| Analizada | Crítica (9.8) | 0.66% | — | Dirk1983 Chatgpt-wechat-personal | 5/3/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitrary requests. | |
| Modificada | Media (6.5) | 41% | 💥 Exploit | Dirk1983 Chatgpt | 5/3/2024 | 17/6/2026 | pictureproxy.php in the dirk1983 mm1.ltd source code f9f4bbc allows SSRF via the url parameter. NOTE: the references section has an archived copy of pictureproxy.php from its original GitHub location, but the repository name might later change because it is misleading. | |
| Modificada | Media (6.1) | 0.52% | — | Chanzhaoyu Chatgpt WEB | 8/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Chanzhaoyu chatgpt-web 2.11.1. This issue affects some unknown processing. The manipulation of the argument Description with the input <image src onerror=prompt(document.domain)> leads to cross site scripting. The attack may be initiated remotely.… | |
| Modificada | Media (5.3) | 0.62% | — | Chuanhuchatgpt Project Chuanhuchatgpt | 2/6/2023 | 17/6/2026 | ChuanhuChatGPT is a graphical user interface for ChatGPT and many large language models. A vulnerability in versions 20230526 and prior allows unauthorized access to the config.json file of the privately deployed ChuanghuChatGPT project, when authentication is not configured. The attacker can exploit this… |