Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.24% | — | Thesamur Embedai | 30/1/2025 | 17/6/2026 | A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attacker to inject a malicious JavaScript code into a message that will be executed when a user opens the chat. | |
| Analizada | Media (5.4) | 0.22% | — | Thesamur Embedai | 30/1/2025 | 17/6/2026 | A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging the"/embedai/users/show/<SCRIPT>" endpoint to inject the malicious JavaScript code. This JavaScript code will be executed when a user opens the… | |
| Analizada | Media (6.5) | 0.32% | — | Thesamur Embedai | 30/1/2025 | 17/6/2026 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the backups of the database by requesting the "/embedai/app/uploads/database/<SQL_FILE>" endpoint. | |
| Analizada | Media (6.5) | 0.27% | — | Thesamur Embedai | 30/1/2025 | 17/6/2026 | an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying by making a POST request changing the parameters of the "/demos/embedai/pmt_cash_on_delivery/pay" endpoint. | |
| Analizada | Media (4.3) | 0.34% | — | Thesamur Embedai | 30/1/2025 | 17/6/2026 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/<VISIT_ID>" to obtain information about the visits made by other users. The information provided by this endpoint includes IP address,… | |
| Analizada | Media (6.5) | 0.28% | — | Thesamur Embedai | 30/1/2025 | 17/6/2026 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain files stored by others users by changing the "FILE_ID" of the endpoint "/embedai/files/show/<FILE_ID>". | |
| Analizada | Media (4.3) | 0.24% | — | Thesamur Embedai | 30/1/2025 | 17/6/2026 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the parameter "chat_id" of the POST request "/embedai/chats/send_message". | |
| Analizada | Media (6.5) | 0.34% | — | Thesamur Embedai | 30/1/2025 | 17/6/2026 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to other users by changing the “CHAT_ID” of the endpoint "/embedai/chats/load_messages?chat_id=<CHAT_ID>". | |
| Analizada | Media (6.5) | 0.34% | — | Thesamur Embedai | 30/1/2025 | 17/6/2026 | An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to show subscription's information of others users by changing the "SUSCBRIPTION_ID" param of the endpoint "/demos/embedai/subscriptions/show/<SUSCBRIPTION_ID>". | |
| Aplazada | Alta (8.3) | 0.16% | — | Thesamur EmbedaiAI | 29/5/2024 | 17/6/2026 | The EmbedAI application is susceptible to security issues that enable Data Poisoning attacks. This weakness could result in the application becoming compromised, leading to unauthorized entries or data poisoning attacks, which are delivered by a CSRF vulnerability due to the absence of a secure session management… |