Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2) | 0.30% | — | Cym1102 Nginxwebui | 8/2/2026 | 17/6/2026 | A vulnerability was identified in cym1102 nginxWebUI up to 4.3.7. The impacted element is an unknown function of the file /adminPage/conf/check of the component Web Management Interface. Such manipulation of the argument nginxDir leads to cross site scripting. The attack can be executed remotely. The exploit is… | |
| Aplazada | Crítica (9.6) | 0.90% | — | Parisneo Lollms-webuiAI | 2/2/2026 | 17/6/2026 | A Local File Inclusion (LFI) vulnerability exists in the '/reinstall_extension' endpoint of the parisneo/lollms-webui application, specifically within the `name` parameter of the `@router.post("/reinstall_extension")` route. This vulnerability allows attackers to inject a malicious `name` parameter, leading to the… | |
| Rechazada | Sin puntuar | — | 💥 PoC | Openwebui Open WebuiAI | 23/1/2026 | 2/9/2026 | Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue.… | |
| Rechazada | Sin puntuar | — | — | Openwebui Open WebuiAI | 23/1/2026 | 2/9/2026 | Rejected reason: Open WebU's investigation further investigation showed that this is intended functionality of the Plugins extension system, in which users granted the relevant permission author Python that the server executes by design, and not a security issue.… | |
| Analizada | Media (5.4) | 0.24% | — | Openwebui Open Webui | 4/12/2025 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Stored XSS vulnerability was discovered in Open-WebUI's Notes PDF download functionality. An attacker can import a Markdown file containing malicious SVG tags into Notes, allowing them to execute… | |
| Analizada | Alta (7.1) | 4.4% | — | Openwebui Open Webui | 4/12/2025 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a Server-Side Request Forgery (SSRF) vulnerability in Open WebUI allows any authenticated user to force the server to make HTTP requests to arbitrary URLs. This can be exploited to access cloud metadata… | |
| Modificada | Media (4.3) | 0.28% | — | Openwebui Open Webui | 4/12/2025 | 17/6/2026 | open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks. | |
| Analizada | Alta (8) | 7.8% | — | Openwebui Open Webui | 8/11/2025 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerability in the Direct Connections feature that allows malicious external model servers to execute arbitrary JavaScript in victim browsers via Server-Sent Event… | |
| Analizada | Media (5.4) | 0.46% | 💥 PoC | Openwebui Open Webui | 8/11/2025 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. In versions 0.6.34 and below, the functionality that inserts custom prompts into the chat window is vulnerable to DOM XSS when 'Insert Prompt as Rich Text' is enabled, since the prompt body is assigned to the DOM sink… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Oobabooga Text-generation-webuiAI | 6/11/2025 | 17/6/2026 | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulnerability. The… | |
| Aplazada | Crítica (9.8) | 0.71% | — | Oobabooga Text-generation-webuiAI | 6/11/2025 | 17/6/2026 | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of oobabooga text-generation-webui. Authentication is not required to exploit this vulnerability. The… | |
| Aplazada | Media (6.2) | 0.57% | — | Text-generation-webuiAI | 13/10/2025 | 17/6/2026 | text-generation-webui is an open-source web interface for running Large Language Models. In versions through 3.13, a Local File Inclusion vulnerability exists in the character picture upload feature. An attacker can upload a text file containing a symbolic link to an arbitrary file path. When the application processes… | |
| Aplazada | Media (6.1) | 0.19% | — | IBM Bigfix WebuiAI | 10/10/2025 | 17/6/2026 | The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Header Poisoning Attacks. | |
| Modificada | Crítica (9.8) | 0.53% | — | X-D LAB Langchain-chatglm-webui | 1/8/2025 | 5/7/2026 | Insecure permissions in LangChain-ChatGLM-Webui commit ef829 allows attackers to arbitrarily view and download sensitive files via supplying a crafted request. | |
| Aplazada | Media (6.9) | 0.45% | — | Rucio-serverAIRucio-uiAIRucio-webuiAI | 17/7/2025 | 17/6/2026 | Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. The common Rucio helm-charts for the `rucio-server`, `rucio-ui`, and `rucio-webui` define the log format for the apache access log of these components. The… | |
| Analizada | Alta (8.9) | 0.70% | — | Rvc-boss Gpt-sovits-webui | 15/7/2025 | 17/6/2026 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in process_ckpt.py. The SoVITS_dropdown variable takes user input and passes it to the load_sovits_new function in process_ckpt.py. In load_sovits_new, the user input,… | |
| Analizada | Alta (8.9) | 0.70% | — | Rvc-boss Gpt-sovits-webui | 15/7/2025 | 17/6/2026 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in inference_webui.py. The GPT_dropdown variable takes user input and passes it to the change_gpt_weights function. In change_gpt_weights, the user input, here gpt_path is… | |
| Analizada | Alta (8.9) | 0.73% | — | Rvc-boss Gpt-sovits-webui | 15/7/2025 | 17/6/2026 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in bsroformer.py. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance of Roformer_Loader class is… | |
| Analizada | Alta (8.9) | 0.73% | — | Rvc-boss Gpt-sovits-webui | 15/7/2025 | 17/6/2026 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in vr.py AudioPreDeEcho. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance of AudioPreDeEcho… | |
| Analizada | Alta (8.9) | 0.73% | — | Rvc-boss Gpt-sovits-webui | 15/7/2025 | 17/6/2026 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is an unsafe deserialization vulnerability in vr.py AudioPre. The model_choose variable takes user input (e.g. a path to a model) and passes it to the uvr function. In uvr, a new instance of AudioPre class is… | |
| Analizada | Alta (8.9) | 3.3% | — | Rvc-boss Gpt-sovits-webui | 15/7/2025 | 17/6/2026 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py change_label function. path_list takes user input, which is passed to the change_label function, which concatenates the user input into a command and runs it on the… | |
| Analizada | Alta (8.9) | 3.4% | — | Rvc-boss Gpt-sovits-webui | 15/7/2025 | 17/6/2026 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py open_asr function. asr_inp_dir (and a number of other variables) takes user input, which is passed to the open_asr function, which concatenates the user input into a… | |
| Analizada | Alta (8.9) | 3.3% | — | Rvc-boss Gpt-sovits-webui | 15/7/2025 | 17/6/2026 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in webui.py open_denoise function. denoise_inp_dir and denoise_opt_dir take user input, which is passed to the open_denoise function, which concatenates the user input into a… | |
| Analizada | Alta (8.9) | 3.4% | — | Rvc-boss Gpt-sovits-webui | 15/7/2025 | 17/6/2026 | GPT-SoVITS-WebUI is a voice conversion and text-to-speech webUI. In versions 20250228v3 and prior, there is a command injection vulnerability in the webui.py open_slice function. slice_opt_root and slice-inp-path takes user input, which is passed to the open_slice function, which concatenates the user input into a… | |
| Analizada | Media (5.4) | 0.58% | — | Openwebui Open Webui | 5/5/2025 | 17/6/2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to version 0.6.6, a vulnerability in the way certain html tags in chat messages are rendered allows attackers to inject JavaScript code into a chat transcript. The JavaScript code will be executed in the user's… |