Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 127 respecto a la semana anterior
Críticas / altas1241▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 201 respecto a la semana anterior
–

1144 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.8%—EFS Software Easy Chat Server31/12/200416/6/2026
chat.ghp in Easy Chat Server 1.2 allows remote attackers to add a large number of fake users, then eventually cause a denial of service (server crash).
ModificadaAlta (7.1)1.7%—Lionmax Software Chat Anywhere31/12/200416/6/2026
LionMax Software Chat Anywhere 2.72a allows remote attackers to cause a denial of service (server crash and client CPU consumption) via a username beginning with percent (%) followed by a null character.
ModificadaMedia (5)1.6%—Ychat31/12/200416/6/2026
Multiple unknown vulnerabilities in yhttpd in yChat before 0.7 allow remote attackers to cause a denial of service (segmentation fault) via unknown vectors.
ModificadaBaja (2.6)2.4%💥 ExploitPHP Heaven Phpmychat31/12/200416/6/2026
Multiple directory traversal vulnerabilities in admin.php3 in PHPMyChat 0.14.5 allow remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the (1) sheet and (2) What parameters.
ModificadaMedia (5)1.5%—Chat AnywhereAI31/12/200416/6/2026
Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which causes the IP address to be displayed as $IP$ on the administration web page.
ModificadaMedia (5)3.5%💥 ExploitVirtual Projects Chatman31/12/200416/6/2026
Chatman 1.1.1 RC1 and earlier allows remote attackers to cause a denial of service (memory consumption or application crash) via a very large data size.
ModificadaMedia (4.3)0.99%—EFS Software Easy Chat Server31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in chat.ghp in Easy Chat Server 1.2 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
ModificadaMedia (5)3.6%💥 ExploitFree WEB ChatAI31/12/200416/6/2026
Free Web Chat 2.0 allows remote attackers to cause a denial of service (CPU consumption) via multiple connections from the same user.
ModificadaAlta (7.5)1.1%💥 ExploitPHP Heaven Phpmychat31/12/200416/6/2026
Multiple SQL injection vulnerabilities in usersL.php3 in PHPMyChat 0.14.5 allow remote attackers to execute arbitrary SQL commands via the (1) sortBy, (2) sortOrder, (3) startReg, (4) U, (5) LastCheck , and (6) R parameters.
ModificadaMedia (4.3)1.7%💥 ExploitLiveworld LivechatLiveworld LivefocusgroupLiveworld LiveforumLiveworld Liveq AND A31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa.
ModificadaAlta (7.5)4.6%💥 ExploitPHP Heaven Phpmychat31/12/200416/6/2026
edituser.php3 in PHPMyChat 0.14.5 allow remote attackers to bypass authentication and gain administrative privileges by setting the do_not_login parameter to false.
ModificadaAlta (7.5)1.3%—Natterchat31/12/200416/6/2026
SQL injection vulnerability in NatterChat 1.12 allows remote attackers to execute arbitrary SQL commands via unknown vectors.
ModificadaMedia (5)2.5%—Parachat Server31/12/200416/6/2026
Directory traversal vulnerability in ParaChat Server 5.5 allows remote attackers to read arbitrary files via a ..%5C (hex-encoded dot dot) in the URL.
ModificadaMedia (5)3.6%💥 ExploitFree WEB ChatAI31/12/200416/6/2026
The addUser function in UserManager.java in Free Web Chat 2.0 allows remote attackers to cause a denial of service (uncaught NullPointerException) via unknown attack vectors that cause the usrName variable to be null.
ModificadaAlta (7.5)1.3%—Apple IchatApple Ichat AV23/12/200416/6/2026
Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program.
ModificadaMedia (5)1.7%—Freechat23/11/200416/6/2026
FreeChat 1.1.1a allows remote attackers to cause a denial of service (crash) via certain unexpected strings, as demonstrated using "aaaaa".
ModificadaMedia (5)3.2%💥 ExploitBird Chat Internet Chat Server23/8/200416/6/2026
Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.
ModificadaMedia (4.3)1.7%💥 Exploit12planet Chat Server6/8/200416/6/2026
Vulnerabilidad de XSS en one2planet.infolet.InfoServlet en 12Planet Chat Server 2.9 permite a atacantes remotos ejecutar secuencias de comandos arbitrarias como otros usuarios a través del parámetro page.
ModificadaMedia (6.8)2.0%💥 ExploitSimm-comm SCI Photo Chat6/8/200416/6/2026
Cross-site scripting (XSS) vulnerability in SCI Photo Chat Server 3.4.9 allows remote attackers to execute arbitrary web script as other users via an invalid request that is echoed in the resulting error message.
ModificadaMedia (5)1.6%—Shawn Webb Webbsyte Chat2/8/200416/6/2026
Webbsyte Chat 0.9.0 allows remote attackers to cause a denial of service (crash) via a large number of connections.
ModificadaAlta (7.5)9.0%💥 ExploitXchat1/6/200416/6/2026
Stack-based buffer overflow in the Socks-5 proxy code for XChat 1.8.0 to 2.0.8, with socks5 traversal enabled, allows remote attackers to execute arbitrary code.
ModificadaAlta (7.5)2.6%—Xchat5/1/200416/6/2026
xchat 2.0.6 permite a atacantes remotos causar una denegación de servicio (caída) mediante una petición DCC pasiva con número ID inválido, lo que causa una desreferencia nula.
ModificadaMedia (5)3.2%💥 ExploitWfchat31/12/200316/6/2026
WF-Chat 1.0 Beta stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain authentication information via a direct request to (1) !pwds.txt and (2) !nicks.txt.
ModificadaMedia (5)1.7%—Unichat2/11/200316/6/2026
Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit.
ModificadaAlta (7.5)3.2%—Cgiscript Cschat-r-box31/12/200216/6/2026
csChatRBox.cgi in CGIScript.net csChat-R-Box allows remote attackers to execute arbitrary Perl code via the setup parameter, which is processed by the Perl eval function.