Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
47 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.1) | 1.7% | — | Lollms WEB UI | 24/3/2026 | 17/6/2026 | LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of `lollms-webui`. The `@router.post("/api/proxy")` endpoint allows unauthenticated attackers to force the… | |
| Modificada | Alta (7.5) | 0.63% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server does not limit or validate the length of the boundary or the characters appended to it, allowing an attacker to craft requests with excessively long boundaries, leading to resource… | |
| Analizada | Alta (8.8) | 1.4% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangerous ones like .py, .sh, .bat, and more. Attackers can exploit this by uploading files with malicious content and then using the '/open_file' API endpoint to execute these… | |
| Modificada | Alta (8.4) | 0.31% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access() function to verify the client_id, enabling attackers to delete directories without proper… | |
| Analizada | Crítica (9.8) | 0.80% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary paths on the system. The issue arises due to insufficient sanitization of user-supplied input, which… | |
| Modificada | Media (6.5) | 0.24% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability can be exploited remotely via Cross-Site Request Forgery (CSRF). Despite CSRF protection preventing file uploads, the application still processes multipart boundaries,… | |
| Modificada | Crítica (9.1) | 0.95% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the `filename` value, causing a Path Traversal error. | |
| Analizada | Media (4.4) | 0.33% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. This can lead to unauthorized access to directories within the personality_folder on the victim's computer. | |
| Analizada | Media (5.4) | 0.30% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' directive, which inserts the content of the 'full_template' variable directly as HTML. This allows an attacker to execute malicious JavaScript code… | |
| Analizada | Alta (7.5) | 0.75% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/proxy` REST API. Attackers can exploit this vulnerability to abuse the victim server's credentials to access unauthorized web resources by specifying the JSON parameter… | |
| Analizada | Media (5.3) | 1.0% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the /open_file endpoint. | |
| Modificada | Media (6.7) | 0.82% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The function does not properly sanitize the `app_name` parameter, enabling an attacker to upload a malicious `server.py` file and execute arbitrary code by exploiting the… | |
| Analizada | Alta (7.1) | 0.24% | — | Lollms WEB UI | 29/10/2024 | 17/6/2026 | A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a… | |
| Analizada | Media (6.5) | 0.17% | — | Lollms WEB UI | 29/10/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim into installing… | |
| Modificada | Alta (7.1) | 0.22% | — | Lollms WEB UI | 13/10/2024 | 17/6/2026 | A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is… | |
| Analizada | Alta (7.5) | 0.60% | — | Lollms WEB UI | 30/9/2024 | 17/6/2026 | A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation in the `serve_js` function in `app.py`, which allows attackers to perform path traversal attacks. This can lead to unauthorized access to arbitrary files on the server,… | |
| Modificada | Alta (8.8) | 0.17% | — | Lollms WEB UI | 1/8/2024 | 17/6/2026 | In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities. Specifically, the endpoints /reload_binding, /install_binding, /reinstall_binding, /unInstall_binding, /set_active_binding_settings, and /update_binding_settings are… | |
| Analizada | Alta (8.4) | 0.45% | — | Lollms WEB UI | 2/7/2024 | 17/6/2026 | parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp311-cp311-manylinux_2_31_x86_64. The vulnerability arises from the application's 'binding_zoo' feature, which allows attackers to upload and… | |
| Analizada | Alta (7.5) | 1.9% | — | Lollms WEB UI | 27/6/2024 | 17/6/2026 | An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with `allow_absolute_path=True` allows an attacker to access arbitrary files and directories on a Windows system. This vulnerability can be… | |
| Analizada | Media (5.4) | 0.35% | — | Lollms WEB UI | 27/6/2024 | 17/6/2026 | A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows an attacker to inject malicious scripts via chat messages, which are then executed in the context of the user's browser. | |
| Analizada | Alta (7.7) | 0.49% | — | Lollms WEB UI | 25/6/2024 | 17/6/2026 | A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest. The vulnerability arises from insufficient input validation in the `/apply_settings` function, allowing an attacker to manipulate the `discussion_db_name` parameter to… | |
| Modificada | Alta (8.1) | 0.18% | — | Parisneo Lollms WEB UI | 10/6/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the clear_personality_files_list function of the parisneo/lollms-webui v9.6. The vulnerability arises from the use of a GET request to clear personality files list, which lacks proper CSRF protection. This flaw allows attackers to trick users into performing… | |
| Modificada | Crítica (9.8) | 34% | — | Lollms WEB UI | 6/6/2024 | 17/6/2026 | A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. The vulnerability arises due to improper handling of the `name` parameter in the… | |
| Modificada | Crítica (9.8) | 0.73% | — | Lollms WEB UI | 6/6/2024 | 17/6/2026 | A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5. The vulnerability arises from the improper limitation of a pathname to a restricted directory in the 'process_folder' function within… | |
| Modificada | Crítica (9.8) | 1.4% | — | Lollms WEB UI | 6/6/2024 | 17/6/2026 | A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/switch_personal_path")` endpoint in `./lollms-webui/lollms_core/lollms/server/endpoints/lollms_user.py`. The vulnerability arises due to insufficient sanitization of… |