Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
1144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.8% | — | EFS Software Easy Chat Server | 31/12/2004 | 16/6/2026 | chat.ghp in Easy Chat Server 1.2 allows remote attackers to add a large number of fake users, then eventually cause a denial of service (server crash). | |
| Modificada | Alta (7.1) | 1.7% | — | Lionmax Software Chat Anywhere | 31/12/2004 | 16/6/2026 | LionMax Software Chat Anywhere 2.72a allows remote attackers to cause a denial of service (server crash and client CPU consumption) via a username beginning with percent (%) followed by a null character. | |
| Modificada | Media (5) | 1.6% | — | Ychat | 31/12/2004 | 16/6/2026 | Multiple unknown vulnerabilities in yhttpd in yChat before 0.7 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors. | |
| Modificada | Baja (2.6) | 2.4% | 💥 Exploit | PHP Heaven Phpmychat | 31/12/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the (1) sheet and (2) What parameters. | |
| Modificada | Media (5) | 1.5% | — | Chat AnywhereAI | 31/12/2004 | 16/6/2026 | Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which causes the IP address to be displayed as $IP$ on the administration web page. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Virtual Projects Chatman | 31/12/2004 | 16/6/2026 | Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data size. | |
| Modificada | Media (4.3) | 0.99% | — | EFS Software Easy Chat Server | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Free WEB ChatAI | 31/12/2004 | 16/6/2026 | Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | PHP Heaven Phpmychat | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Liveworld LivechatLiveworld LivefocusgroupLiveworld LiveforumLiveworld Liveq AND A | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa. | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | PHP Heaven Phpmychat | 31/12/2004 | 16/6/2026 | edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login parameter to false. | |
| Modificada | Alta (7.5) | 1.3% | — | Natterchat | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in NatterChat 1.12 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | |
| Modificada | Media (5) | 2.5% | — | Parachat Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Free WEB ChatAI | 31/12/2004 | 16/6/2026 | The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught NullPointerException) via unknown attack vectors that cause the usrName variable to be null. | |
| Modificada | Alta (7.5) | 1.3% | — | Apple IchatApple Ichat AV | 23/12/2004 | 16/6/2026 | Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program. | |
| Modificada | Media (5) | 1.7% | — | Freechat | 23/11/2004 | 16/6/2026 | FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using "aaaaa". | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Bird Chat Internet Chat Server | 23/8/2004 | 16/6/2026 | Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | 12planet Chat Server | 6/8/2004 | 16/6/2026 | Vulnerabilidad de XSS en one2planet.infolet.InfoServlet en 12Planet Chat Server 2.9 permite a atacantes remotos ejecutar secuencias de comandos arbitrarias como otros usuarios a través del parámetro page. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Simm-comm SCI Photo Chat | 6/8/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message. | |
| Modificada | Media (5) | 1.6% | — | Shawn Webb Webbsyte Chat | 2/8/2004 | 16/6/2026 | Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections. | |
| Modificada | Alta (7.5) | 9.0% | 💥 Exploit | Xchat | 1/6/2004 | 16/6/2026 | Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 2.6% | — | Xchat | 5/1/2004 | 16/6/2026 | xchat 2.0.6 permite a atacantes remotos causar una denegación de servicio (caída) mediante una petición DCC pasiva con número ID inválido, lo que causa una desreferencia nula. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | Wfchat | 31/12/2003 | 16/6/2026 | WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt. | |
| Modificada | Media (5) | 1.7% | — | Unichat | 2/11/2003 | 16/6/2026 | Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit. | |
| Modificada | Alta (7.5) | 3.2% | — | Cgiscript Cschat-r-box | 31/12/2002 | 16/6/2026 | csChatRBox.cgi in CGIScript.net csChat-R-Box allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function. |