Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

104 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)31%—Gaizhenbiao Chuanhuchatgpt29/10/202417/6/2026
A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including user upload, directory creation, and template loading. Specifically, the load_chat_history function in modules/models/base_model.py allows…
AnalizadaCrítica (9.1)0.55%—Gaizhenbiao Chuanhuchatgpt29/10/202417/6/2026
A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulnerability can lead to unauthorized changes in system behavior or security…
AplazadaAlta (7.5)0.42%—Butterfly Effect Limited Monica Chatgpt AI AssistantAI24/10/202417/6/2026
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
AnalizadaAlta (7.5)0.85%💥 ExploitAys-pro Chatgpt Assistant27/9/202417/6/2026
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 lacks sufficient access controls allowing an unauthenticated user to disconnect the AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 from OpenAI, thereby disabling the AI ChatBot with ChatGPT and…
ModificadaAlta (7.5)0.30%—Ays-pro Chatgpt Assistant27/9/202417/6/2026
The AI ChatBot with ChatGPT and Content Generator by AYS WordPress plugin before 2.1.0 discloses the Open AI API Key, allowing unauthenticated users to obtain it
AnalizadaMedia (5.3)1.1%💥 ExploitWebdigit Chatbot With Chatgpt25/9/202417/6/2026
The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key
AnalizadaMedia (5.3)1.3%💥 ExploitWebdigit Chatbot With Chatgpt5/9/202417/6/2026
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
AnalizadaCrítica (9.8)0.74%—Webdigit Chatbot With Chatgpt20/8/202417/6/2026
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.
AnalizadaMedia (6.1)0.41%—Webdigit Chatbot With Chatgpt19/8/202417/6/2026
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins
ModificadaCrítica (9.1)14%—Gaizhenbiao Chuanhuchatgpt31/7/202417/6/2026
A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration files such as `config.json` and `ds_config_chatbot.json`. This issue arises due to improper validation of file paths, enabling directory…
ModificadaMedia (6.1)0.37%—Gaizhenbiao Chuanhuchatgpt11/7/202417/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410. This vulnerability allows an attacker to inject malicious JavaScript code into the chat history file. When a victim uploads this file, the malicious script is executed in the victim's browser. This can lead to user…
ModificadaCrítica (9.1)11%—Gaizhenbiao Chuanhuchatgpt10/7/202417/6/2026
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir). This can lead to uncontrolled resource consumption, resulting in resource exhaustion, denial of service (DoS), server unavailability, and…
AnalizadaCrítica (9.1)11%—Gaizhenbiao Chuanhuchatgpt10/7/202417/6/2026
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn_index":66`. This unrestricted server restart capability can severely disrupt service availability, cause data loss or corruption, and…
AplazadaBaja (2.3)0.14%—Openai ChatgptAI6/7/202417/6/2026
The OpenAI ChatGPT app before 2024-07-05 for macOS opts out of the sandbox, and stores conversations in cleartext in a location accessible to other apps.
ModificadaAlta (7.5)0.86%—Gaizhenbiao Chuanhuchatgpt27/6/202417/6/2026
A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploited to delete any files ending in `.json` on the target system, leading to a denial of service as users are unable to authenticate.
ModificadaAlta (7.5)0.66%—Gaizhenbiao Chuanhuchatgpt27/6/202417/6/2026
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability is located in the filter_history function within the utils.py module. This function takes a user-provided keyword and attempts to match it against chat history filenames using a…
AnalizadaCrítica (9.8)0.53%—Gaizhenbiao Chuanhuchatgpt27/6/202417/6/2026
A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnerability allows attackers to send crafted requests from the vulnerable server to internal or external resources, potentially bypassing…
ModificadaMedia (6.1)0.59%—Gaizhenbiao Chuanhuchatgpt6/6/202417/6/2026
gaizhenbiao/chuanhuchatgpt is vulnerable to an unrestricted file upload vulnerability due to insufficient validation of uploaded file types in its `/upload` endpoint. Specifically, the `handle_file_upload` function does not sanitize or validate the file extension or content type of uploaded files, allowing attackers…
ModificadaAlta (7.5)1.4%💥 PoCGaizhenbiao Chuanhuchatgpt6/6/202417/6/2026
A timing attack vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, specifically within the password comparison logic. The vulnerability is present in version 20240310 of the software, where passwords are compared using the '=' operator in Python. This method of comparison allows an attacker to guess…
ModificadaMedia (6.5)0.50%—Gaizhenbiao Chuanhuchatgpt6/6/202417/6/2026
In gaizhenbiao/chuanhuchatgpt, specifically the version tagged as 20240121, there exists a vulnerability due to improper access control mechanisms. This flaw allows an authenticated attacker to bypass intended access restrictions and read the `history` files of other users, potentially leading to unauthorized access…
ModificadaMedia (5.4)0.46%—Gaizhenbiao Chuanhuchatgpt6/6/202417/6/2026
A stored Cross-Site Scripting (XSS) vulnerability existed in version (20240121) of gaizhenbiao/chuanhuchatgpt due to inadequate sanitization and validation of model output data. Despite user-input validation efforts, the application fails to properly sanitize or validate the output from the model, allowing for the…
ModificadaCrítica (9.8)3.8%💥 ExploitGaizhenbiao Chuanhuchatgpt6/6/202417/6/2026
The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict user access to resources within the `web_assets` folder. However, the outdated version of gradio it employs is susceptible to path traversal, as…
ModificadaAlta (7.5)0.52%—Gaizhenbiao Chuanhuchatgpt4/6/202417/6/2026
An improper access control vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically in version 20240410. This vulnerability allows any user on the server to access the chat history of any other user without requiring any form of interaction between the users. Exploitation of this vulnerability…
AnalizadaAlta (7.5)0.60%—Gaizhenbiao Chuanhuchatgpt16/5/202417/6/2026
A Local File Inclusion (LFI) vulnerability exists in the gaizhenbiao/chuanhuchatgpt application, specifically within the functionality for uploading chat history. The vulnerability arises due to improper input validation when handling file paths during the chat history upload process. An attacker can exploit this…
AnalizadaAlta (7.5)0.78%—Gaizhenbiao Chuanhuchatgpt10/4/202417/6/2026
gaizhenbiao/chuanhuchatgpt is vulnerable to improper access control, allowing unauthorized access to the `config.json` file. This vulnerability is present in both authenticated and unauthenticated versions of the application, enabling attackers to obtain sensitive information such as API keys (`openai_api_key`,…
Orbitaley — Vulnerabilidades