Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.37% | — | Zhayujie Chatgpt-on-wechatAI | 14/7/2026 | 14/7/2026 | A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Performing a manipulation of the argument image results in server-side request forgery. It is… | |
| Aplazada | Media (5.5) | 0.78% | — | Zhayujie Chatgpt-on-wechatAI | 5/7/2026 | 6/7/2026 | A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. This manipulation of the argument wechatmp_token causes missing authentication. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 1.3% | — | Zhayujie Chatgpt-on-wechatAI | 1/6/2026 | 22/7/2026 | A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to os command injection. The attack can be launched remotely. The exploit has been made… | |
| Aplazada | Media (5.5) | 2.1% | — | Toowiredd Chatgpt-mcp-serverAI | 26/4/2026 | 17/6/2026 | A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been made… | |
| Aplazada | Media (5.5) | 0.65% | — | Zhayujie Chatgpt-on-wechatAIZhayujie CowagentAI | 12/4/2026 | 17/6/2026 | A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed… | |
| Aplazada | Media (5.5) | 0.69% | — | Zhayujie Chatgpt-on-wechatAI | 12/4/2026 | 17/6/2026 | A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Aplazada | Media (5.5) | 0.70% | — | Zhayujie Chatgpt-on-wechatAI | 10/4/2026 | 17/6/2026 | A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of the component API Memory Content Endpoint. This manipulation of the argument filename causes path traversal. The attack can be initiated remotely. The exploit has been… | |
| Aplazada | Media (5.3) | 0.32% | — | AYS AI Chatbot With Chatgpt AND Content GeneratorAI | 3/3/2026 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the store_data() and get_chatgpt_api_key() functions in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.22% | — | Ays-chatgpt-assistantAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.7.4. | |
| Aplazada | Media (5.3) | 0.28% | — | AYS Code AI Chatbot With Chatgpt AND Content GeneratorAI | 27/11/2025 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files. | |
| Aplazada | Media (6.5) | 0.29% | — | AYS AI Chatbot With Chatgpt AND Content GeneratorAI | 27/11/2025 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.0 via the ays_chatgpt_pinecone_upsert function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations… | |
| Aplazada | Alta (7.5) | 1.3% | — | Ays-chatgpt-assistantAI | 6/11/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Retrieve Embedded Sensitive Data.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.6.6. | |
| Aplazada | Media (6.1) | 0.28% | — | Chatgpt UnliAI | 22/7/2025 | 17/6/2026 | Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to execute arbitrary code via a crafted SVG file to the chat interface. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Webfactory Aibuddy Openai ChatgptAI | 3/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server.This issue affects AiBud WP: from n/a through <= 1.9. | |
| Analizada | Media (6.5) | 0.65% | — | Openai Chatgpt | 19/5/2025 | 17/6/2026 | The ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a code block), which enables HTML injection within most modern graphical web browsers. | |
| Analizada | Media (6.5) | 0.59% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in the file upload feature of gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability is due to improper handling of form-data with a large filename in the file upload request. By sending a payload with an excessively large filename, the server becomes overwhelmed… | |
| Analizada | Media (6.5) | 0.48% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A Server-Side Request Forgery (SSRF) vulnerability was discovered in gaizhenbiao/chuanhuchatgpt version 20240914. The vulnerability allows an attacker to construct a response link by saving the response in a folder named after the SHA-1 hash of the target URL. This enables the attacker to access the response directly,… | |
| Analizada | Alta (8.1) | 0.62% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete other users' chat history. The vulnerability arises because the username is provided via an HTTP request from the client side, rather than being read from a secure source like a… | |
| Analizada | Media (6.5) | 0.64% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | An incorrect authorization vulnerability exists in gaizhenbiao/chuanhuchatgpt version git c91dbfc. The vulnerability allows any user to restart the server at will, leading to a complete loss of availability. The issue arises because the function responsible for restarting the server is not properly guarded by an admin… | |
| Analizada | Media (5.4) | 0.57% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the gaizhenbiao/chuanhuchatgpt repository, affecting version git 20b2e02. The vulnerability arises from improper sanitization of HTML tags in chat history uploads. Specifically, the sanitization logic fails to handle HTML tags within code blocks correctly,… | |
| Modificada | Alta (8.8) | 0.59% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling of session data and lack of access control mechanisms, enabling attackers to view and manipulate chat histories of other users. | |
| Analizada | Media (5.4) | 0.42% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability allows an attacker to upload a malicious HTML file containing JavaScript code, which is then executed when the file is accessed. This can lead to the execution of arbitrary JavaScript in the… | |
| Modificada | Media (6.5) | 0.73% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | A Regular Expression Denial of Service (ReDoS) vulnerability exists in gaizhenbiao/chuanhuchatgpt, as of commit 20b2e02. The server uses the regex pattern `r'<[^>]+>'` to parse user input. In Python's default regex engine, this pattern can take polynomial time to match certain crafted inputs. An attacker can exploit… | |
| Modificada | Media (6.5) | 0.73% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | gaizhenbiao/chuanhuchatgpt version git d4ec6a3 is affected by a local file inclusion vulnerability due to the use of the gradio component gr.JSON, which has a known issue (CVE-2024-4941). This vulnerability allows unauthenticated users to access arbitrary files on the server by uploading a specially crafted JSON file… | |
| Modificada | Alta (7.5) | 0.71% | — | Gaizhenbiao Chuanhuchatgpt | 20/3/2025 | 17/6/2026 | An unauthenticated Denial of Service (DoS) vulnerability was identified in ChuanhuChatGPT version 20240918, which could be exploited by sending large data payloads using a multipart boundary. Although a patch was applied for CVE-2024-7807, the issue can still be exploited by sending data in groups with 10 characters… |