Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.2% | — | EFS Software Easy Chat Server | 16/1/2007 | 16/6/2026 | Easy Chat Server 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download certain files via direct requests to files such as (1) ServerKey.pem and (2) AcceptIP.txt. NOTE: The provenance of this information is unknown; the details are obtained… | |
| Modificada | Alta (7.5) | 3.7% | — | Topcmm Computing 123 Flash Chat Server | 25/1/2006 | 16/6/2026 | Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username. | |
| Modificada | Media (5) | 1.6% | — | Topcmm Computing 123 Flash Chat Server | 16/1/2006 | 16/6/2026 | Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via ".." (dot dot) sequences in the username field. | |
| Modificada | Media (5) | 2.5% | — | Parachat Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL. | |
| Modificada | Media (5) | 2.8% | — | EFS Software Easy Chat Server | 31/12/2004 | 16/6/2026 | chat.ghp in Easy Chat Server 1.2 allows remote attackers to add a large number of fake users, then eventually cause a denial of service (server crash). | |
| Modificada | Media (5) | 75% | — | EFS Software Easy Chat Server | 31/12/2004 | 16/6/2026 | chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected. | |
| Modificada | Media (4.3) | 0.99% | — | EFS Software Easy Chat Server | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Media (5) | 3.2% | — | Bird Chat Internet Chat Server | 23/8/2004 | 16/6/2026 | Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users. | |
| Modificada | Media (4.3) | 1.7% | — | 12planet Chat Server | 6/8/2004 | 16/6/2026 | Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to execute arbitrary script as other users via the page parameter. | |
| Modificada | Media (5) | 2.5% | — | Parachat Server | 31/12/2002 | 16/6/2026 | ParaChat Server 4.0 does not log users off if the browser's back button is used, which allows remote attackers to cause a denial of service by repeatedly logging into a chat room, hitting the back button, then logging into the same chat room as a different user, which fills the chat room with invalid users. | |
| Modificada | Media (5) | 1.3% | — | Apple Ichat Server | 9/9/1998 | 16/6/2026 | iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack. |