Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

22 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.1)0.57%—Monicahq Monica20/2/202617/6/2026
A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php, combined with the default misconfiguration where the "app.force_url" is not set and default is "false". The application generates absolute URLs (such as those used in…
AnalizadaMedia (5.4)0.50%—Monicahq Monica13/2/202517/6/2026
Monica 4.1.2 is vulnerable to Cross Site Scripting (XSS). A malicious user can create a malformed contact and use that contact in the "HOW YOU MET" customization options to trigger the XSS.
ModificadaMedia (6.5)0.40%—Monicahq Monica13/1/20255/7/2026
MonicaHQ v4.1.2 was discovered to contain a Client-Side Injection vulnerability via the last_name parameter the General Information module.
ModificadaMedia (5.4)0.37%—Monicahq Monica10/1/20255/7/2026
MonicaHQ v4.1.2 was discovered to contain an authenticated Client-Side Injection vulnerability via the Reason parameter at /people/h:[id]/debts/create.
ModificadaMedia (5.4)0.28%—Monicahq Monica10/1/20255/7/2026
MonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/ID/edit.
ModificadaAlta (8.8)0.80%—Monicahq Monica10/1/20255/7/2026
MonicaHQ v4.1.2 was discovered to contain multiple authenticated Client-Side Injection vulnerabilities via the title and description parameters at /people/ID/reminders/create.
ModificadaMedia (6.5)0.31%—Monicahq Monica10/1/20255/7/2026
MonicaHQ v4.1.2 was discovered to contain multiple Client-Side Injection vulnerabilities via the first_name and last_name parameters in the Add a new relationship feature.
AplazadaAlta (7.5)0.42%—Butterfly Effect Limited Monica Chatgpt AI AssistantAI24/10/202417/6/2026
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
AplazadaAlta (7.5)0.42%—Butterfly Effect Limited Monica Your AI CopilotAI24/10/202417/6/2026
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
ModificadaMedia (5.4)0.58%—Monicahq Monica11/12/202317/6/2026
A stored cross-site scripting (XSS) vulnerability exists in Monica (aka MonicaHQ) 4.0.0 via an SVG document uploaded by an authenticated user.
ModificadaMedia (5.4)0.64%—Monicahq Monica8/5/202317/6/2026
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter.
ModificadaMedia (5.4)0.67%—Monicahq Monica8/5/202317/6/2026
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/work` endpoint and job and company parameter.
ModificadaMedia (5.4)0.64%—Monicahq Monica8/5/202317/6/2026
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people/add` endpoint and nickName, description, lastName, middleName and firstName parameter.
ModificadaMedia (5.4)0.64%—Monicahq Monica8/5/202317/6/2026
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/introductions` endpoint and first_met_additional_info parameter.
ModificadaAlta (8.8)1.2%—Monicahq Monica8/5/202317/6/2026
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/food` endpoint and food parameter.
ModificadaAlta (8.8)1.4%—Monicahq Monica8/5/202317/6/2026
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `settings` endpoint and first_name parameter.
ModificadaMedia (5.4)0.89%—Monicahq Monica14/4/202117/6/2026
Cross Site Scripting (XSS) in Monica before 2.19.1 via the journal page.
ModificadaMedia (5.4)0.59%—Monicahq Monica22/2/202117/6/2026
The Contact page in Monica 2.19.1 allows stored XSS via the Nickname field.
ModificadaMedia (5.4)0.59%—Monicahq Monica22/2/202117/6/2026
The Contact page in Monica 2.19.1 allows stored XSS via the Description field.
ModificadaMedia (5.4)3.3%—Monicahq Monica22/2/202117/6/2026
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
ModificadaMedia (5.4)0.59%—Monicahq Monica22/2/202117/6/2026
The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.
ModificadaMedia (5.4)0.59%—Monicahq Monica22/2/202117/6/2026
The Contact page in Monica 2.19.1 allows stored XSS via the First Name field.