Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
233 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 0.78% | — | Mintplexlabs Anythingllm | 16/4/2024 | 17/6/2026 | A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs/anything-llm repository, allowing unauthorized creation of high-privileged accounts. By intercepting and modifying the HTTP request during the account creation process via an invitation link, an attacker can add a `role`… | |
| Analizada | Media (5.4) | 0.31% | — | Mintplexlabs Anythingllm | 10/4/2024 | 17/6/2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in the chat functionality of the mintplex-labs/anything-llm repository, allowing attackers to execute arbitrary JavaScript in the context of a user's session. By manipulating the ChatBot responses, an attacker can inject malicious scripts to perform actions on… | |
| Analizada | Alta (7.5) | 0.78% | — | Mintplexlabs Anythingllm | 10/4/2024 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in the mintplex-labs/anything-llm repository when the application is running in 'just me' mode with a password. An attacker can exploit this vulnerability by making a request to the endpoint using the [validatedRequest] middleware with a specially crafted 'Authorization:'… | |
| Analizada | Alta (7.2) | 0.95% | — | Mintplexlabs Anythingllm | 10/4/2024 | 17/6/2026 | A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their privileges to admin roles through a mass assignment issue. The '/admin/system-preferences' API endpoint improperly authorizes manager-level users to modify the 'multi_user_mode' system variable, enabling them to access the… | |
| Analizada | Alta (7.2) | 0.78% | — | Mintplexlabs Anythingllm | 10/4/2024 | 17/6/2026 | In mintplex-labs/anything-llm, an improper input validation vulnerability allows attackers to escalate privileges by deactivating 'Multi-User Mode'. By sending a specially crafted curl request with the 'multi_user_mode' parameter set to false, an attacker can deactivate 'Multi-User Mode'. This action permits the… | |
| Analizada | Crítica (9.9) | 1.0% | — | Mintplexlabs Anythingllm | 10/4/2024 | 17/6/2026 | mintplex-labs/anything-llm is vulnerable to path traversal attacks due to insufficient validation of user-supplied input in the logo filename functionality. Attackers can exploit this vulnerability by manipulating the logo filename to reference files outside of the restricted directory. This can lead to unauthorized… | |
| Aplazada | Media (6.1) | 1.6% | 💥 PoC | Advancedformintegration Advanced Form IntegrationAI | 20/3/2024 | 17/6/2026 | The Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms plugin for WordPress is vulnerable to SQL Injection via the ‘integration_id’ parameter in all versions up to, and including, 1.82.0 due to insufficient escaping on the user supplied parameter and lack of… | |
| Analizada | Media (6.5) | 0.58% | — | Mintplexlabs Anythingllm | 3/3/2024 | 17/6/2026 | As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `/export-data` endpoint of the system and then unzip and read that export that would enable you do exfiltrate data of the system at that save state. This would require the attacked to be granted explicit access to the system,… | |
| Analizada | Alta (7.2) | 0.95% | — | Mintplexlabs Anythingllm | 2/3/2024 | 17/6/2026 | If an attacked was given access to an instance with the admin or manager role there is no backend authentication that would prevent the attacked from creating a new user with an `admin` role and then be able to use this new account to have elevated privileges on the instance | |
| Analizada | Media (6.5) | 0.72% | — | Mintplexlabs Anythingllm | 28/2/2024 | 17/6/2026 | A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files. The attacker would have to have been granted privileged permissions to the system before executing this attack. | |
| Modificada | Alta (8.1) | 0.90% | — | Mintplexlabs Anythingllm | 27/2/2024 | 17/6/2026 | Any user can delete an arbitrary folder (recursively) on a remote server due to bad input sanitization leading to path traversal. The attacker would need access to the server at some privilege level since this endpoint is protected and requires authorization. | |
| Analizada | Alta (7.1) | 0.56% | — | Mintplexlabs Anythingllm | 27/2/2024 | 17/6/2026 | Enable exports of the database and associated exported information of the system via the default user role. The attacked would have to have been granted access to the system prior to the attack. It is worth noting that the deterministic nature of the export name is lower risk as the UI for exporting would start the… | |
| Analizada | Alta (7.5) | 0.92% | — | Mintplexlabs Anythingllm | 27/2/2024 | 17/6/2026 | Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly granted a permission level of manager or admin, they could link-scrape internally resolving IPs of other services that are on the same network as AnythingLLM. This would require the attacker also be able to guess these… | |
| Analizada | Media (6.5) | 0.57% | — | Mintplexlabs Anythingllm | 26/2/2024 | 17/6/2026 | A privilege escalation vulnerability exists in mintplex-labs/anything-llm, allowing users with 'default' role to delete documents uploaded by 'admin'. Despite the intended restriction that prevents 'default' role users from deleting admin-uploaded documents, an attacker can exploit this vulnerability by sending a… | |
| Analizada | Alta (7.5) | 0.81% | — | Mintplexlabs Anythingllm | 26/2/2024 | 17/6/2026 | The inclusion of the web scraper for AnythingLLM means that any user with the proper authorization level (manager, admin, and when in single user) could put in the URL ``` http://169.254.169.254/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance ``` which is a special IP and URL that resolves… | |
| Analizada | Media (6.5) | 0.64% | — | Mintplexlabs Anythingllm | 26/2/2024 | 17/6/2026 | Attacker, with permission to submit a link or submits a link via POST to be collected that is using the file:// protocol can then introspect host files and other relatively stored files. | |
| Analizada | Alta (8.8) | 0.64% | — | Mintplexlabs Anythingllm | 26/2/2024 | 17/6/2026 | As a manager, you should not be able to modify a series of settings. In the UI this is indeed hidden as a convenience for the role since most managers would not be savvy enough to modify these settings. They can use their token to still modify those settings though through a standard HTTP request While this is not a… | |
| Modificada | Media (5.9) | 0.48% | — | Mintplexlabs Anythingllm | 26/2/2024 | 17/6/2026 | Theoretically, it would be possible for an attacker to brute-force the password for an instance in single-user password protection mode via a timing attack given the linear nature of the `!==` used for comparison. The risk is minified by the additional overhead of the request, which varies in a non-constant nature… | |
| Analizada | Media (5.4) | 0.47% | — | Mintplexlabs Anythingllm | 26/2/2024 | 17/6/2026 | User can send a chat that contains an XSS opportunity that will then run when the chat is sent and on subsequent page loads. Given the minimum requirement for a user to send a chat is to be given access to a workspace via an admin the risk is low. Additionally, the location in which the XSS renders is only limited to… | |
| Modificada | Alta (7.5) | 1.4% | — | Kmint21 Golden FTP Server | 25/1/2024 | 17/6/2026 | A vulnerability was found in Kmint21 Golden FTP Server 2.02b and classified as problematic. This issue affects some unknown processing of the component PASV Command Handler. The manipulation leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (4.3) | 0.38% | — | Mintplexlabs Vector Admin | 25/1/2024 | 17/6/2026 | Authentication bypass in vector-admin allows a user to register to a vector-admin server while “domain restriction” is active, even when not owning an authorized email address. | |
| Modificada | Alta (7.5) | 1.0% | — | Mintplexlabs Anythingllm | 19/1/2024 | 17/6/2026 | AnythingLLM is an application that turns any document, resource, or piece of content into context that any LLM can use as references during chatting. In versions prior to commit `08d33cfd8` an unauthenticated API route (file export) can allow attacker to crash the server resulting in a denial of service attack. The… | |
| Modificada | Alta (7.2) | 0.54% | — | Advancedformintegration Advanced Form Integration | 28/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nasirahmed Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms.This issue affects Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets… | |
| Modificada | Alta (8.8) | 0.63% | — | Mintplexlabs Anythingllm | 30/10/2023 | 17/6/2026 | Improper Access Control in GitHub repository mintplex-labs/anything-llm prior to 0.1.0. | |
| Modificada | Crítica (9.1) | 0.74% | — | Mintplexlabs Anythingllm | 30/10/2023 | 17/6/2026 | Improper Input Validation in GitHub repository mintplex-labs/anything-llm prior to 0.1.0. |