Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.51% | — | Code-projects Simple ChatboxAI | 13/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performing a manipulation results in file and directory information exposure. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Simple ChatboxAI | 13/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Simple ChatBox up to 1.0. Affected by this vulnerability is an unknown functionality of the file /chatbox/insert.php of the component Endpoint. Such manipulation of the argument msg leads to cross site scripting. The attack may be performed from remote. The exploit has… | |
| Aplazada | Media (5.5) | 2.1% | 💥 PoC | Getgist ChatboxAI | 12/4/2026 | 17/6/2026 | A flaw has been found in chatboxai chatbox up to 1.20.0. This impacts the function StdioClientTransport of the file src/main/mcp/ipc-stdio-transport.ts of the component Model Context Protocol Server Management System. Executing a manipulation of the argument args/env can lead to os command injection. The attack can be… | |
| Aplazada | Media (5.5) | 0.65% | — | Zhayujie Chatgpt-on-wechatAIZhayujie CowagentAI | 12/4/2026 | 17/6/2026 | A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed… | |
| Aplazada | Media (5.5) | 0.69% | — | Zhayujie Chatgpt-on-wechatAI | 12/4/2026 | 17/6/2026 | A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.3) | 0.32% | — | Rocket.chat | 10/4/2026 | 17/6/2026 | An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint. | |
| Aplazada | Media (5.5) | 0.70% | — | Zhayujie Chatgpt-on-wechatAI | 10/4/2026 | 17/6/2026 | A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of the component API Memory Content Endpoint. This manipulation of the argument filename causes path traversal. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (6.5) | 0.22% | — | Elfsight Whatsapp Chat CCAI | 8/4/2026 | 24/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Elfsight Elfsight WhatsApp Chat CC elfsight-whatsapp-chat allows DOM-Based XSS.This issue affects Elfsight WhatsApp Chat CC: from n/a through <= 1.2.0. | |
| Analizada | Media (6.3) | 0.34% | — | Librechat | 7/4/2026 | 24/7/2026 | LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the execute_code sandbox when persisting code-generated artifacts. On deployments using the default local file strategy, a malicious artifact filename containing traversal sequences (for example,… | |
| Aplazada | Baja (2.1) | 0.33% | — | Zhongyu09 OpenchatbiAI | 5/4/2026 | 24/7/2026 | A vulnerability was determined in zhongyu09 openchatbi up to 0.2.1. The impacted element is an unknown function of the component Multi-stage Text2SQL Workflow. Executing a manipulation of the argument keywords can lead to sql injection. The attack may be launched remotely. The exploit has been publicly disclosed and… | |
| Modificada | Alta (8.6) | 0.33% | — | FKA Prompts.chat | 3/4/2026 | 24/7/2026 | prompts.chat prior to commit 1464475, contains an identity confusion vulnerability due to inconsistent case-sensitive and case-insensitive handling of usernames across write and read paths, allowing attackers to create case-variant usernames that bypass uniqueness checks. Attackers can exploit non-deterministic… | |
| Modificada | Alta (7.1) | 0.30% | — | FKA Prompts.chat | 3/4/2026 | 24/7/2026 | prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in the Fal.ai media status polling feature that allows authenticated users to perform arbitrary outbound requests by supplying attacker-controlled URLs in the token parameter. Attackers can exploit the lack of URL validation to… | |
| Analizada | Alta (8.7) | 0.28% | — | FKA Prompts.chat | 3/4/2026 | 24/7/2026 | prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and page metadata generation that allow unauthorized users to access sensitive data associated with private prompts. Attackers can exploit these missing authorization checks… | |
| Analizada | Media (5.3) | 0.19% | — | FKA Prompts.chat | 3/4/2026 | 24/7/2026 | prompts.chat prior to commit 1464475 contains a blind server-side request forgery vulnerability in the Wiro media generator that allows authenticated users to perform server-side fetches of user-controlled inputImageUrl parameters. Attackers can exploit this vulnerability by sending POST requests to the… | |
| Modificada | Alta (8.6) | 0.36% | — | FKA Prompts.chat | 3/4/2026 | 24/7/2026 | prompts.chat prior to commit 0f8d4c3 contains a path traversal vulnerability in skill file handling that allows attackers to write arbitrary files to the client system by crafting malicious ZIP archives with unsanitized filenames containing path traversal sequences. Attackers can exploit missing server-side filename… | |
| Aplazada | Baja (2.1) | 0.44% | — | ChatwootAI | 31/3/2026 | 24/7/2026 | A vulnerability was identified in chatwoot up to 4.11.2. Affected by this vulnerability is the function Webhooks::Trigger in the library lib/webhooks/trigger.rb of the component Webhook API. Such manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit is… | |
| Analizada | Alta (7) | 0.33% | — | 1millionbot Millie Chatbot | 31/3/2026 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of other users being viewed by simply changing the conversation ID. The vulnerability is present in the endpoint 'api.1millionbot.com/api/public/conversations/' and, if exploited, could allow a remote… | |
| Analizada | Alta (8.7) | 0.45% | — | 1millionbot Millie Chatbot | 31/3/2026 | 17/6/2026 | Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions using Boolean prompt injection techniques (formulating a question in such a way that, upon receiving an affirmative response ('true'), the model executes the injected instruction), causing it to… | |
| Analizada | Crítica (9.3) | 0.82% | — | Echatserver Easy Chat Server | 28/3/2026 | 17/6/2026 | EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code… | |
| Aplazada | Media (5.5) | 0.46% | — | ChatwootAI | 27/3/2026 | 17/6/2026 | A security vulnerability has been detected in chatwoot up to 4.11.1. The affected element is an unknown function of the file /app/login of the component Signup Endpoint. Such manipulation of the argument signupEnabled with the input true leads to improper authorization. The attack can be executed remotely. The exploit… | |
| Analizada | Media (5.7) | 0.35% | — | Librechat | 27/3/2026 | 17/6/2026 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model Context Protocol) servers can include arbitrary HTTP headers that undergo credential placeholder substitution. An attacker can create a malicious MCP server with headers containing… | |
| Analizada | Media (5.3) | 0.28% | — | Librechat | 27/3/2026 | 17/6/2026 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoint `/api/agents/chat/stream/:streamId` does not verify that the requesting user owns the stream. Any authenticated user who obtains or guesses a valid stream ID can subscribe and read another user's… | |
| Analizada | Alta (7.7) | 0.35% | — | Librechat | 27/3/2026 | 17/6/2026 | LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side request forgery (SSRF) attack when using agent actions or MCP. Although a previous SSRF vulnerability (https://github.com/danny-avila/LibreChat/security/advisories/GHSA-rgjq-4q58-m3q8) was reported… | |
| Modificada | Alta (8.5) | 0.30% | — | Librechat | 27/3/2026 | 17/6/2026 | LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in their hex-normalized form, allowing any authenticated user to bypass SSRF protection and make the server issue HTTP requests to internal… | |
| Aplazada | Media (6.9) | 0.44% | — | Hijiffy ChatbotAI | 26/3/2026 | 17/6/2026 | Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'visitor' in '/api/v1/webchat/message'. |