Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
–

1144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.7%💥 ExploitSleeperchat25/1/200616/6/2026
Vulnerabilidad XSS en index.php de SleeperChat 0.3f y anteriores permite a atacantes remotos inyectar 'script' web o HTML arbitrario mediante el parámetro "pseudo"
ModificadaAlta (7.5)3.7%💥 ExploitTopcmm Computing 123 Flash Chat Server25/1/200616/6/2026
Vulnerabilidad de inyección de Eval en 123 Flash Chat Server 5.0 y 5.1 permite a atacantes ejecutar código mediante un "username" artesanal.
ModificadaMedia (5)1.5%—Sleeperchat25/1/200616/6/2026
SleeperChat 0.3f y anteriores permite a atacantes remotos saltarse la autenticación y crear nuevas entradas mediante el parámetro "txt" de (1) chat_no.php y (2) chat_if.php.
ModificadaMedia (5)1.6%—Topcmm Computing 123 Flash Chat Server16/1/200616/6/2026
Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via ".." (dot dot) sequences in the username field.
ModificadaAlta (7.5)1.6%—Chatspot28/12/200516/6/2026
The Chatspot 2.0.0a7 module for phpBB might allow remote attackers to impersonate other users via unknown vectors.
ModificadaAlta (7.5)1.2%—Chatspot28/12/200516/6/2026
SQL injection vulnerability in the Chatspot 2.0.0a7 module for phpBB allows remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaMedia (4.3)1.8%💥 ExploitPhpheaven Phpmychat4/12/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in phpMyChat 0.14.6 allow remote attackers to inject arbitrary web script or HTML via the medium parameter to (1) start_page.css.php and (2) style.css.php; or the From parameter to users_popupL.php.
ModificadaAlta (7.5)2.0%💥 ExploitAppindex Mwchat27/10/200516/6/2026
SQL injection vulnerability in chat.php in MWChat 6.8 allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaMedia (4.3)1.7%—Phpopenchat10/8/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PHPOpenChat 3.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) content parameter to profile.php and profile_misc.php, (3) the profile fields in userpage.php, (4) subject or (5) body in mail.php, or (8) disinvited_chatter…
ModificadaMedia (5)1.5%—Realchat27/7/200516/6/2026
El protocolo de login en RealChat 3.5 no usa autentificación, lo que permite que atacantes remotos se logueen como otros usuarios (escuchando el inicio de una sesión de chat y repitiéndola con un nombre de usuario modificado).
ModificadaMedia (5)3.4%💥 ExploitJollybox.de TCP Chat5/7/200516/6/2026
TCP Chat 1.0 allows remote attackers to cause a denial of service (crash) via a long string to the chat service, possibly triggering a buffer overflow.
ModificadaAlta (7.5)1.1%💥 ExploitCool Cafe Chat16/6/200516/6/2026
SQL injection vulnerability in login.asp for Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to execute arbitrary SQL commands via the password.
ModificadaAlta (7.5)1.7%—Cool Cafe Chat16/6/200516/6/2026
modifyUser.asp in Cool Cafe (Cool Café) Chat 1.2.1 allows remote attackers to obtain the administrator password and email address via a modified nickname value.
ModificadaAlta (7.5)1.9%—Appindex Mwchat7/6/200516/6/2026
PHP remote file inclusion vulnerability in start_lobby.php in MWChat 6.x allows remote attackers to execute arbitrary PHP code via the CONFIG[MWCHAT_Libs] parameter.
ModificadaMedia (4.3)1.7%💥 ExploitPhpheaven Phpmychat16/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (1) start_page.css.php3 (aka start-page.css.php3) or (2) style.css.php3 in PHPMyChat 0.14.5 allow remote attackers to inject arbitrary web script or HTML commands via the FontName parameter. NOTE: it was later reported that 0.14.5 is also affected.
ModificadaAlta (7.5)11%💥 ExploitPhpopenchat2/5/200516/6/2026
Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter to (1) poc_loginform.php or (2) phpbb/poc.php, the poc_root_path parameter to (3) phpbb/poc.php, (4) phpnuke/ENGLISH_poc.php, (5) phpnuke/poc.php,…
ModificadaMedia (4.3)1.3%—Chatness2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in message.php in Chatness 2.5.1 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the user field or (2) the message parameter to message.php.
ModificadaMedia (5)1.7%—Lanchat PRO Revival2/5/200516/6/2026
LANChat Pro Revival 1.666c allows remote attackers to cause a denial of service (application crash) via a malformed UDP packet.
ModificadaMedia (4.3)1.7%💥 ExploitPhpopenchat2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or HTML via (1) the chatter parameter to regulars.php or (2) the chatter, chatter1, chatter2, chatter3, or chatter4 parameters to register.php.
ModificadaMedia (4.6)0.56%💥 ExploitLionmax Software Chat Anywhere2/5/200516/6/2026
Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges.
ModificadaMedia (4.3)1.4%—Adventia ChatAdventia Server PRO29/3/200516/6/2026
Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.
ModificadaMedia (4.3)1.7%💥 ExploitPHP Heaven Phpmychat31/12/200416/6/2026
PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.
ModificadaMedia (5)75%💥 ExploitEFS Software Easy Chat Server31/12/200416/6/2026
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username parameter, possibly due to a buffer overflow. NOTE: it was later reported that 2.2 is also affected.
ModificadaMedia (5)1.9%—ChatterboxAI31/12/200416/6/2026
ChatterBox 2.0 allows remote attackers to cause a denial of service (server crash) via a malformed request to the server, as demonstrated using "aaaaaa".
ModificadaAlta (7.5)3.2%—Netchat Subnet Chat Application31/12/200416/6/2026
Stack-based buffer overflow in the HTTP server in NetChat 7.3 and earlier allows remote attackers to execute arbitrary code via a long GET request.