Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
104 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.23% | — | FastgptAI | 8/5/2026 | 24/7/2026 | FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packages/service/common/system/utils.ts is vulnerable to DNS rebinding (TOCTOU — Time-of-Check to Time-of-Use). The function resolves the hostname via dns.resolve4()/dns.resolve6() and checks resolved IPs… | |
| Aplazada | Media (6.3) | 0.45% | — | FastgptAI | 8/5/2026 | 24/7/2026 | FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insufficient resource isolation and uncontrolled resource consumption. The service relies solely on an application-level soft limit (a 500ms polling interval) for memory management and lacks strict OS-level… | |
| Aplazada | Crítica (9.8) | 1.3% | — | FastgptAICoder Code-serverAI | 8/5/2026 | 24/7/2026 | FastGPT is an AI Agent building platform. From version 4.14.10 to before version 4.14.13, the agent-sandbox component of FastGPT is vulnerable to unauthenticated Remote Code Execution (RCE). The startup script entrypoint.sh initializes code-server with the --auth none flag and binds the service to all network… | |
| Aplazada | Media (5.5) | 2.1% | — | Toowiredd Chatgpt-mcp-serverAI | 26/4/2026 | 17/6/2026 | A weakness has been identified in Toowiredd chatgpt-mcp-server up to 0.1.0. Affected by this issue is some unknown functionality of the file src/services/docker.service.ts of the component MCP/HTTP. This manipulation causes os command injection. Remote exploitation of the attack is possible. The exploit has been made… | |
| Analizada | Alta (8.8) | 0.53% | — | Fastgpt | 17/4/2026 | 17/6/2026 | FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password change endpoint is vulnerable to NoSQL injection. An authenticated attacker can bypass the "old password" verification by injecting MongoDB query operators. This allows an attacker who has gained a low-privileged session to change… | |
| Analizada | Crítica (9.8) | 0.60% | — | Fastgpt | 17/4/2026 | 17/6/2026 | FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attacker to pass a MongoDB query operator object (e.g., {"$ne": ""}) as the password field. This NoSQL injection bypasses the… | |
| Aplazada | Media (5.5) | 0.65% | — | Zhayujie Chatgpt-on-wechatAIZhayujie CowagentAI | 12/4/2026 | 17/6/2026 | A vulnerability was detected in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects an unknown function of the component Agent Mode Service. Performing a manipulation results in missing authentication. The attack can be initiated remotely. The exploit is now public and may be used. The project was informed… | |
| Aplazada | Media (5.5) | 0.69% | — | Zhayujie Chatgpt-on-wechatAI | 12/4/2026 | 17/6/2026 | A weakness has been identified in zhayujie chatgpt-on-wechat CowAgent 2.0.4. The affected element is an unknown function of the component Administrative HTTP Endpoint. This manipulation causes missing authentication. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Media (5.3) | 0.44% | — | Fastgpt | 10/4/2026 | 17/6/2026 | FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access and execute applications belonging to other teams by supplying a foreign appId. While the API correctly validates the team token, it does not verify that the requested… | |
| Analizada | Media (5.3) | 0.40% | — | Fastgpt | 10/4/2026 | 17/6/2026 | FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool endpoint accepts arbitrary URLs without authentication. The internal IP check in isInternalAddress() only blocks private IPs when CHECK_INTERNAL_IP=true, which is not the default. This allows unauthenticated attackers to… | |
| Aplazada | Media (5.5) | 0.70% | — | Zhayujie Chatgpt-on-wechatAI | 10/4/2026 | 17/6/2026 | A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the function dispatch of the file agent/memory/service.py of the component API Memory Content Endpoint. This manipulation of the argument filename causes path traversal. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.7) | 0.42% | — | Fastgpt | 31/3/2026 | 24/7/2026 | FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, FastGPT's MCP (Model Context Protocol) tools endpoints (/api/core/app/mcpTools/getTools and /api/core/app/mcpTools/runTool) accept a user-supplied URL parameter and make server-side HTTP requests to it without validating whether the URL points to an… | |
| Analizada | Crítica (10) | 0.62% | — | Fastgpt | 31/3/2026 | 24/7/2026 | FastGPT is an AI Agent building platform. Prior to version 4.14.9.5, the FastGPT HTTP tools testing endpoint (/api/core/app/httpTools/runTool) is exposed without any authentication. This endpoint acts as a full HTTP proxy — it accepts a user-supplied baseUrl, toolPath, HTTP method, custom headers, and body, then makes… | |
| Analizada | Crítica (9.4) | 0.32% | 💥 PoC | Fastgpt | 20/3/2026 | 17/6/2026 | FastGPT is an AI Agent building platform. In versions 4.14.8.3 and below, the fastgpt-preview-image.yml workflow is vulnerable to arbitrary code execution and secret exfiltration by any external contributor. It uses pull_request_target (which runs with access to repository secrets) but checks out code from the pull… | |
| Analizada | Media (6.3) | 0.30% | 💥 PoC | Fastgpt | 11/3/2026 | 17/6/2026 | FastGPT is an AI Agent building platform. In 4.14.7 and earlier, FastGPT's Python Sandbox (fastgpt-sandbox) includes guardrails intended to prevent file writes (static detection + seccomp). These guardrails are bypassable by remapping stdout (fd 1) to an arbitrary writable file descriptor using fcntl. After remapping,… | |
| Aplazada | Media (5.3) | 0.32% | — | AYS AI Chatbot With Chatgpt AND Content GeneratorAI | 3/3/2026 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the store_data() and get_chatgpt_api_key() functions in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated… | |
| Aplazada | Media (5.3) | 0.22% | — | Ays-chatgpt-assistantAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.7.4. | |
| Analizada | Media (6.9) | 0.15% | — | Fastgpt | 12/2/2026 | 17/6/2026 | FastGPT is an AI Agent building platform. Due to the fact that FastGPT's web page acquisition nodes, HTTP nodes, etc. need to initiate data acquisition requests from the server, there are certain security issues. In addition to implementing internal network isolation in the deployment environment, this optimization… | |
| Analizada | Media (6.9) | 0.45% | — | Fastgpt | 10/2/2026 | 17/6/2026 | FastGPT is an AI Agent building platform. From 4.14.0 to 4.14.5, attackers can directly access the plugin system through FastGPT/api/plugin/xxx without authentication, thereby threatening the plugin system. This may cause the plugin system to crash and the loss of plugin installation status, but it will not result in… | |
| Aplazada | Media (5.3) | 0.28% | — | AYS Code AI Chatbot With Chatgpt AND Content GeneratorAI | 27/11/2025 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'ays_chatgpt_save_wp_media' function in all versions up to, and including, 2.7.0. This makes it possible for unauthenticated attackers to upload media files. | |
| Aplazada | Media (6.5) | 0.29% | — | AYS AI Chatbot With Chatgpt AND Content GeneratorAI | 27/11/2025 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.7.0 via the ays_chatgpt_pinecone_upsert function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations… | |
| Aplazada | Alta (7.5) | 1.3% | 💥 Exploit | Ays-chatgpt-assistantAI | 6/11/2025 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Retrieve Embedded Sensitive Data.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.6.6. | |
| Analizada | Media (6.9) | 0.24% | — | Fastgpt | 22/10/2025 | 17/6/2026 | FastGPT is an AI Agent building platform. Prior to version 4.11.1, in the workflow file reading node, the network link is not security-verified, posing a risk of SSRF attacks. This issue has been patched in version 4.11.1. | |
| Aplazada | Media (6.1) | 0.28% | 💥 PoC | Chatgpt UnliAI | 22/7/2025 | 17/6/2026 | Self Cross Site Scripting (XSS) vulnerability in ChatGPT Unli (ChatGPTUnli.com) thru 2025-05-26 allows attackers to execute arbitrary code via a crafted SVG file to the chat interface. | |
| Aplazada | Crítica (9.1) | 0.50% | 💥 PoC | Webfactory Aibuddy Openai ChatgptAI | 3/7/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Upload a Web Shell to a Web Server.This issue affects AiBud WP: from n/a through <= 1.9. |