Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 304 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

28 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6)0.21%—Aotuman Grab Wechat ArticlesAI18/8/202620/8/2026
Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.
AplazadaCrítica (9.1)0.45%—Wechat Qrcode LoginAI27/7/202627/7/2026
The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem…
AplazadaBaja (2.1)0.37%—Zhayujie Chatgpt-on-wechatAI14/7/202614/7/2026
A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Performing a manipulation of the argument image results in server-side request forgery. It is…
AplazadaMedia (5.5)0.78%—Zhayujie Chatgpt-on-wechatAI5/7/20266/7/2026
A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.1.0. This issue affects the function verify_server of the file channel/wechatmp/common.py of the component wx Endpoint. This manipulation of the argument wechatmp_token causes missing authentication. The attack may be initiated remotely. The…
AplazadaMedia (5.5)1.3%—Zhayujie Chatgpt-on-wechatAI1/6/202622/7/2026
A weakness has been identified in zhayujie chatgpt-on-wechat up to 2.0.8. This issue affects the function _get_safety_warning of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to os command injection. The attack can be launched remotely. The exploit has been made…
AplazadaMedia (5.5)0.65%—Zhayujie Chatgpt-on-wechatAIZhayujie CowagentAI12/4/202617/6/2026
A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed…
AplazadaMedia (5.5)0.69%—Zhayujie Chatgpt-on-wechatAI12/4/202617/6/2026
A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been made available to the public and…
AplazadaMedia (5.5)0.70%—Zhayujie Chatgpt-on-wechatAI10/4/202617/6/2026
A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of the component API Memory Content Endpoint. This manipulation of the argument filename causes path traversal. The attack can be initiated remotely. The exploit has been…
AplazadaMedia (5.1)0.25%—Mikecen Wechat-face-recognitionAI25/9/202517/6/2026
A security flaw has been discovered in MikeCen WeChat-Face-Recognition up to 6e3f72bf8547d80b59e330f1137e4aa505f492c1. This vulnerability affects the function valid of the file wx.php. The manipulation of the argument echostr results in cross site scripting. The attack can be launched remotely. This product does not…
AplazadaAlta (7.1)0.41%—Redyyu Wechat-subscribers-liteAI19/11/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in redyyu WeChat Subscribers Lite wechat-subscribers-lite allows Reflected XSS.This issue affects WeChat Subscribers Lite : from n/a through <= 1.6.6.
AplazadaCrítica (9.8)0.85%—Wechat Social LoginAI1/10/202417/6/2026
The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's…
AplazadaCrítica (9.8)1.7%—Wechat Social LoginAI1/10/202417/6/2026
The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such…
AnalizadaAlta (8.8)1.2%—Tencent Wechat26/7/202417/6/2026
Insecure Permissions vulnerability in Tencent wechat v.8.0.37 allows an attacker to escalate privileges via the web-view component.
AnalizadaCrítica (9.8)0.66%—Dirk1983 Chatgpt-wechat-personal5/3/202417/6/2026
A Server-Side Request Forgery (SSRF) in weixin.php of ChatGPT-wechat-personal commit a0857f6 allows attackers to force the application to make arbitrary requests.
ModificadaAlta (7.5)0.81%—Linkwechat25/1/202417/6/2026
A vulnerability was found in qwdigital LinkWechat 5.1.0. It has been classified as problematic. This affects an unknown part of the file /linkwechat-api/common/download/resource of the component Universal Download Interface. The manipulation of the argument name with the input /profile/../../../../../etc/passwd leads…
ModificadaAlta (7.5)0.46%—Tencent Enterprise Wechat Privatization12/10/202317/6/2026
There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000.
ModificadaAlta (8.8)0.88%—Nbs&happysoftwechat18/8/202317/6/2026
A vulnerability, which was classified as critical, has been found in NBS&HappySoftWeChat 1.1.6. Affected by this issue is some unknown functionality. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this…
ModificadaMedia (6.1)0.41%—Wpjam Wechat Robot25/4/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in Denis 微信机器人高级版 plugin <= 6.0.1 versions.
ModificadaCrítica (9.8)0.78%—Wechat SDK Python Project Wechat SDK Python21/3/202317/6/2026
A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical. This issue affects the function validate/to_xml. The manipulation leads to xml external entity reference. The attack may be initiated remotely. Upgrading to version 0.5.5 is able to address this issue. The patch is named…
ModificadaAlta (7.5)1.4%—Tencent Wechat26/7/202217/6/2026
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
ModificadaMedia (6.1)0.78%—Wechat-php-sdk Project Wechat-php-sdk17/12/202117/6/2026
Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php.
ModificadaMedia (5.4)0.40%—Wechat Reward Project Wechat Reward18/10/202117/6/2026
The Wechat Reward WordPress plugin through 1.7 does not sanitise or escape its QR settings, nor has any CSRF check in place, allowing attackers to make a logged in admin change the settings and perform Cross-Site Scripting attacks.
ModificadaMedia (6.5)6.4%—Tencent Wechat14/4/202117/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tencent WeChat 2.9.5 desktop version. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the WXAM…
ModificadaAlta (8.8)2.1%—Tencent Wechat10/2/202117/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tencent WeChat 7.0.18. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the WXAM Decoder. The issue…
ModificadaMedia (5.4)1.4%—Tencent Wechat7/1/202017/6/2026
This vulnerability allows remote attackers redirect users to an external resource on affected installations of Tencent WeChat Prior to 7.0.9. User interaction is required to exploit this vulnerability in that the target must be within a chat session together with the attacker. The specific flaw exists within the…