Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
1144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Sleeperchat | 25/1/2006 | 16/6/2026 | Vulnerabilidad XSS en index.php de SleeperChat 0.3f y anteriores permite a atacantes remotos inyectar 'script' web o HTML arbitrario mediante el parámetro "pseudo" | |
| Modificada | Alta (7.5) | 3.7% | 💥 Exploit | Topcmm Computing 123 Flash Chat Server | 25/1/2006 | 16/6/2026 | Vulnerabilidad de inyección de Eval en 123 Flash Chat Server 5.0 y 5.1 permite a atacantes ejecutar código mediante un "username" artesanal. | |
| Modificada | Media (5) | 1.5% | — | Sleeperchat | 25/1/2006 | 16/6/2026 | SleeperChat 0.3f y anteriores permite a atacantes remotos saltarse la autenticación y crear nuevas entradas mediante el parámetro "txt" de (1) chat_no.php y (2) chat_if.php. | |
| Modificada | Media (5) | 1.6% | — | Topcmm Computing 123 Flash Chat Server | 16/1/2006 | 16/6/2026 | Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via ".." (dot dot) sequences in the username field. | |
| Modificada | Alta (7.5) | 1.6% | — | Chatspot | 28/12/2005 | 16/6/2026 | The Chatspot 2.0.0a7 module for phpBB might allow remote attackers to impersonate other users via unknown vectors. | |
| Modificada | Alta (7.5) | 1.2% | — | Chatspot | 28/12/2005 | 16/6/2026 | SQL injection vulnerability in the Chatspot 2.0.0a7 module for phpBB allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Phpheaven Phpmychat | 4/12/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in phpMyChat 0.14.6 allow remote attackers to inject arbitrary web script or HTML via the medium parameter to (1) start_page.css.php and (2) style.css.php; or the From parameter to users_popupL.php. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Appindex Mwchat | 27/10/2005 | 16/6/2026 | SQL injection vulnerability in chat.php in MWChat 6.8 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Phpopenchat | 10/8/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHPOpenChat 3.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content parameter to profile.php and profile_misc.php, (3) the profile fields in userpage.php, (4) subject or (5) body in mail.php, or (8) disinvited_chatter… | |
| Modificada | Media (5) | 1.5% | — | Realchat | 27/7/2005 | 16/6/2026 | El protocolo de login en RealChat 3.5 no usa autentificación, lo que permite que atacantes remotos se logueen como otros usuarios (escuchando el inicio de una sesión de chat y repitiéndola con un nombre de usuario modificado). | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Jollybox.de TCP Chat | 5/7/2005 | 16/6/2026 | TCP Chat 1.0 allows remote attackers to cause a denial of service (crash) via a long string to the chat service, possibly triggering a buffer overflow. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Cool Cafe Chat | 16/6/2005 | 16/6/2026 | SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password. | |
| Modificada | Alta (7.5) | 1.7% | — | Cool Cafe Chat | 16/6/2005 | 16/6/2026 | modifyUser.asp in Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to obtain the administrator password and email address via a modified nickname value. | |
| Modificada | Alta (7.5) | 1.9% | — | Appindex Mwchat | 7/6/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in start_lobby.php in MWChat 6.x allows remote attackers to execute arbitrary PHP code via the CONFIG[MWCHAT_Libs] parameter. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Phpheaven Phpmychat | 16/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter. NOTE: it was later reported that 0.14.5 is also affected. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Phpopenchat | 2/5/2005 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4) phpnuke/ENGLISH_poc.php, (5) phpnuke/poc.php,… | |
| Modificada | Media (4.3) | 1.3% | — | Chatness | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in message.php in Chatness 2.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the user field or (2) the message parameter to message.php. | |
| Modificada | Media (5) | 1.7% | — | Lanchat PRO Revival | 2/5/2005 | 16/6/2026 | LANChat Pro Revival 1.666c allows remote attackers to cause a denial of service (application crash) via a malformed UDP packet. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Phpopenchat | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php. | |
| Modificada | Media (4.6) | 0.56% | 💥 Exploit | Lionmax Software Chat Anywhere | 2/5/2005 | 16/6/2026 | Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges. | |
| Modificada | Media (4.3) | 1.4% | — | Adventia ChatAdventia Server PRO | 29/3/2005 | 16/6/2026 | Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | PHP Heaven Phpmychat | 31/12/2004 | 16/6/2026 | PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request. | |
| Modificada | Media (5) | 75% | 💥 Exploit | EFS Software Easy Chat Server | 31/12/2004 | 16/6/2026 | chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected. | |
| Modificada | Media (5) | 1.9% | — | ChatterboxAI | 31/12/2004 | 16/6/2026 | ChatterBox 2.0 allows remote attackers to cause a denial of service (server crash) via a malformed request to the server, as demonstrated using "aaaaaa". | |
| Modificada | Alta (7.5) | 3.2% | — | Netchat Subnet Chat Application | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in the HTTP server in NetChat 7.3 and earlier allows remote attackers to execute arbitrary code via a long GET request. |