Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
233 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.58% | — | Mintplexlabs Anythingllm | 25/6/2024 | 17/6/2026 | A vulnerability in mintplex-labs/anything-llm allows for a Denial of Service (DoS) condition due to uncontrolled resource consumption. Specifically, the issue arises from the application's failure to limit the size of usernames, enabling attackers to create users with excessively bulky texts in the username field.… | |
| Modificada | Media (6.5) | 0.46% | — | Mintplexlabs Anythingllm | 20/6/2024 | 17/6/2026 | In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the response after login (`POST /api/request-token`) and after account creations (`POST /api/admin/users/new`). This exposure occurs because the entire User object, including the… | |
| Modificada | Media (6.5) | 0.62% | — | Mintplexlabs Anythingllm | 19/6/2024 | 17/6/2026 | An uncontrolled resource consumption vulnerability exists in the `upload-link` endpoint of mintplex-labs/anything-llm. This vulnerability allows attackers to cause a denial of service (DOS) by shutting down the server through sending invalid upload requests. Specifically, the server can be made to shut down by sending… | |
| Analizada | Media (6.1) | 0.30% | — | Minthcm | 14/6/2024 | 17/6/2026 | In MintHCM 4.0.3, a registered user can execute arbitrary JavaScript code and achieve a reflected Cross-site Scripting (XSS) attack. | |
| Analizada | Alta (7.2) | 1.0% | — | Mintplexlabs Anythingllm | 12/6/2024 | 17/6/2026 | A path traversal vulnerability in mintplex-labs/anything-llm allowed a manager to bypass the `normalizePath()` function, intended to defend against path traversal attacks. This vulnerability enables the manager to read, delete, or overwrite the 'anythingllm.db' database file and other files stored in the 'storage'… | |
| Analizada | Crítica (9.6) | 0.97% | — | Mintplexlabs Anythingllm DesktopMintplexlabs Anythingllm Docker | 6/6/2024 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability exists in mintplex-labs/anything-llm, affecting both the desktop application version 1.2.0 and the latest version of the web application. The vulnerability arises from the application's feature to fetch and embed content from websites into workspaces, which can be exploited… | |
| Modificada | Media (6.5) | 0.66% | — | Mintplexlabs Anythingllm | 6/6/2024 | 17/6/2026 | mintplex-labs/anything-llm is affected by an uncontrolled resource consumption vulnerability in its upload file endpoint, leading to a denial of service (DOS) condition. Specifically, the server can be shut down by sending an invalid upload request. An attacker with the ability to upload documents can exploit this… | |
| Modificada | Alta (8.8) | 0.79% | — | Mintplexlabs Anythingllm | 6/6/2024 | 17/6/2026 | In mintplex-labs/anything-llm, a vulnerability exists in the thread update process that allows users with Default or Manager roles to escalate their privileges to Administrator. The issue arises from improper input validation when handling HTTP POST requests to the endpoint… | |
| Modificada | Alta (8.8) | 0.52% | — | Mintplexlabs Anythingllm | 6/6/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the upload link feature of mintplex-labs/anything-llm. This feature, intended for users with manager or admin roles, processes uploaded links through an internal Collector API using a headless browser. An attacker can exploit this by hosting a malicious… | |
| Modificada | Alta (8.7) | 0.67% | — | Mintplexlabs Anythingllm | 6/6/2024 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in the mintplex-labs/anything-llm application, affecting versions up to and including the latest before 1.0.0. The vulnerability arises from the application's failure to properly sanitize and validate user-supplied URLs before embedding them into the application… | |
| Modificada | Media (5.3) | 0.45% | — | Mintplexlabs Anythingllm | 6/6/2024 | 17/6/2026 | A JSON Injection vulnerability exists in the `mintplex-labs/anything-llm` application, specifically within the username parameter during the login process at the `/api/request-token` endpoint. The vulnerability arises from improper handling of values, allowing attackers to perform brute force attacks without prior… | |
| Modificada | Alta (8.8) | 0.57% | — | Mintplexlabs Anythingllm | 6/6/2024 | 17/6/2026 | mintplex-labs/anything-llm is vulnerable to multiple security issues due to improper input validation in several endpoints. An attacker can exploit these vulnerabilities to escalate privileges from a default user role to an admin role, read and delete arbitrary files on the system, and perform Server-Side Request… | |
| Modificada | Crítica (9.8) | 0.98% | — | Mintplexlabs Anythingllm | 6/6/2024 | 17/6/2026 | A remote code execution vulnerability exists in mintplex-labs/anything-llm due to improper handling of environment variables. Attackers can exploit this vulnerability by injecting arbitrary environment variables via the `POST /api/system/update-env` endpoint, which allows for the execution of arbitrary code on the… | |
| Modificada | Crítica (9.4) | 0.55% | — | Mintplexlabs Anythingllm | 6/6/2024 | 17/6/2026 | An improper authorization vulnerability exists in the mintplex-labs/anything-llm application, specifically within the '/api/v/' endpoint and its sub-routes. This flaw allows unauthenticated users to perform destructive actions on the VectorDB, including resetting the database and deleting specific namespaces, without… | |
| Modificada | Alta (7.5) | 0.49% | — | Mintplexlabs Anythingllm | 5/6/2024 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of mintplex-labs/anything-llm, allowing attackers to bypass the official fix intended to restrict access to intranet IP addresses and protocols. Despite efforts to filter out intranet IP addresses starting with 192, 172, 10, and 127… | |
| Aplazada | Media (4.9) | 0.36% | — | Mintplexlabs Anything-llmAI | 26/5/2024 | 17/6/2026 | Mintplex-Labs' anything-llm application is vulnerable to improper neutralization of special elements used in an expression language statement, identified in the commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. The vulnerability arises from the application's handling of user modifications by managers or admins,… | |
| Analizada | Alta (7.2) | 0.61% | — | Mintplexlabs Anythingllm | 20/5/2024 | 17/6/2026 | In mintplex-labs/anything-llm, a vulnerability exists due to improper input validation in the workspace update process. Specifically, the application fails to validate or format JSON data sent in an HTTP POST request to `/api/workspace/:workspace-slug/update`, allowing it to be executed as part of a database query… | |
| Analizada | Media (4.9) | 0.56% | — | Mintplexlabs Anythingllm | 19/5/2024 | 17/6/2026 | A vulnerability in mintplex-labs/anything-llm allows for a denial of service (DoS) condition through the modification of a user's `id` attribute to a value of 0. This issue affects the current version of the software, with the latest commit id `57984fa85c31988b2eff429adfc654c46e0c342a`. By exploiting this… | |
| Aplazada | Crítica (9) | 1.0% | — | Linuxmint MintuploadAI | 19/5/2024 | 17/6/2026 | In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connection, drop_data_received_cb, and Service.remove. A user can modify a service name in a ~/.linuxmint/mintUpload/services/service file. | |
| Analizada | Media (6.5) | 0.33% | — | Mintplexlabs Anythingllm | 7/5/2024 | 17/6/2026 | A race condition vulnerability exists in the mintplex-labs/anything-llm repository, specifically within the user invite acceptance process. Attackers can exploit this vulnerability by sending multiple concurrent requests to accept a single user invite, allowing the creation of multiple user accounts from a single… | |
| Analizada | Alta (7.8) | 1.3% | 💥 PoC | Linuxmint Xreader | 3/5/2024 | 17/6/2026 | Linux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Analizada | Alta (7.8) | 1.8% | 💥 PoC | Linuxmint Xreader | 3/5/2024 | 17/6/2026 | Linux Mint Xreader EPUB File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page… | |
| Analizada | Alta (8) | 0.73% | — | Mintplexlabs Anythingllm | 16/4/2024 | 17/6/2026 | In mintplex-labs/anything-llm, an attacker can exploit improper input validation by sending a malformed JSON payload to the '/system/enable-multi-user' endpoint. This triggers an error that is caught by a catch block, which in turn deletes all users and disables the 'multi_user_mode'. The vulnerability allows an… | |
| Analizada | Alta (7.2) | 0.83% | — | Mintplexlabs Anythingllm | 16/4/2024 | 17/6/2026 | mintplex-labs/anything-llm is vulnerable to improper input validation, allowing attackers to read and delete arbitrary files on the server. By manipulating the 'logo_filename' parameter in the 'system-preferences' API endpoint, an attacker can construct requests to read sensitive files or the application's '.env'… | |
| Analizada | Alta (8.1) | 0.82% | — | Mintplexlabs Anythingllm | 16/4/2024 | 17/6/2026 | mintplex-labs/anything-llm is vulnerable to a relative path traversal attack, allowing unauthorized attackers with a default role account to delete files and folders within the filesystem, including critical database files such as 'anythingllm.db'. The vulnerability stems from insufficient input validation and… |