Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.45% | — | Privoce Vocechat ServerAI | 28/9/2026 | 28/9/2026 | A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be… | |
| En análisis | Media (6.5) | 0.27% | — | Synology Chat ServerAI | 28/8/2026 | 1/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write restricted files and conduct limited denial-of-service attacks in DSM. | |
| En análisis | Media (4.3) | 0.36% | — | Synology Chat ServerAI | 28/8/2026 | 1/9/2026 | A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information. | |
| En análisis | Crítica (9) | 0.49% | — | Synology Chat ServerAI | 28/8/2026 | 1/9/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM. | |
| Aplazada | Alta (7.3) | 0.48% | — | Easy Chat ServerAI | 22/5/2026 | 23/7/2026 | Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the chat message functionality | |
| Aplazada | Media (6.5) | 1.1% | — | Easy Chat ServerAI | 22/5/2026 | 23/7/2026 | Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the UserName parameter | |
| Analizada | Crítica (9.3) | 0.82% | — | Echatserver Easy Chat Server | 28/3/2026 | 17/6/2026 | EChat Server 3.1 contains a buffer overflow vulnerability in the chat.ghp endpoint that allows remote attackers to execute arbitrary code by supplying an oversized username parameter. Attackers can send a GET request to chat.ghp with a malicious username value containing shellcode and ROP gadgets to achieve code… | |
| Analizada | Alta (8.7) | 0.52% | — | Echatserver Easy Chat Server | 22/3/2026 | 17/6/2026 | Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter… | |
| Modificada | Media (5.3) | 0.97% | — | Easy Chat Server Project Easy Chat Server | 18/1/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in EFS Easy Chat Server 3.1. Affected by this issue is some unknown functionality of the component HTTP GET Request Handler. The manipulation of the argument USERNAME leads to denial of service. The attack may be launched remotely. The exploit has… | |
| Modificada | Media (6.1) | 0.42% | — | Easy Chat Server Project Easy Chat Server | 4/10/2023 | 17/6/2026 | Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /registresult.htm (POST method), in the Icon parameter. The XSS is loaded from /users.ghp. | |
| Modificada | Media (6.1) | 0.42% | — | Easy Chat Server Project Easy Chat Server | 4/10/2023 | 17/6/2026 | Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /body2.ghp (POST method), in the mtowho parameter. | |
| Modificada | Media (6.1) | 0.42% | — | Easy Chat Server Project Easy Chat Server | 4/10/2023 | 17/6/2026 | Easy Chat Server, in its 3.1 version and before, does not sufficiently encrypt user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability stored via /registresult.htm (POST method), in the Resume parameter. The XSS is loaded from /register.ghp. | |
| Modificada | Crítica (9.8) | 0.98% | — | Easy Chat Server Project Easy Chat Server | 4/10/2023 | 17/6/2026 | Stack-based buffer overflow vulnerability in Easy Chat Server 3.1 version. An attacker could send an excessively long username string to the register.ghp file asking for the name via a GET request resulting in arbitrary code execution on the remote machine. | |
| Modificada | Alta (7.8) | 0.39% | — | Echatserver Easy Chat Server | 6/1/2023 | 17/6/2026 | Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability allows attackers to execute arbitrary code via a crafted DLL. | |
| Modificada | Crítica (9.8) | 1.5% | — | Chat Server Project Chat Server | 31/5/2022 | 17/6/2026 | Chat Server is the chat server for Vartalap, an open-source messaging application. Versions 2.3.2 until 2.6.0 suffer from a bug in validating the access token, resulting in authentication bypass. The function `this.authProvider.verifyAccessKey` is an async function, as the code is not using `await` to wait for the… | |
| Modificada | Alta (7.5) | 1.1% | — | Echatserver Easy Chat Server | 5/3/2020 | 17/6/2026 | An issue was discovered in EFS Easy Chat Server 3.1. There is a buffer overflow via a long body2.ghp message parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Microfocus Service ManagerMicrofocus Service Manager Chat ServerMicrofocus Service Manager Chat Service | 10/9/2019 | 17/6/2026 | HTTP cookie in Micro Focus Service manager, Versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Server, versions 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. And Micro Focus Service Manager Chat Service 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. | |
| Modificada | Alta (7.2) | 4.4% | — | Atlassian Hipchat Data CenterAtlassian Hipchat Server | 27/11/2017 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in version 2.2.0 of Hipchat Server and version 3.0.0 of Hipchat Data Center. Versions of Hipchat Server starting with 2.2.0 and before 2.2.6 are affected by this… | |
| Modificada | Alta (7.5) | 1.7% | — | Echatserver Easy Chat Server | 12/6/2017 | 17/6/2026 | register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response. | |
| Modificada | Crítica (9.8) | 24% | — | Echatserver Easy Chat Server | 12/6/2017 | 17/6/2026 | There is a remote stack-based buffer overflow (SEH) in register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1. By sending an overly long username string to registresult.htm for registering the user, an attacker may be able to execute arbitrary code. | |
| Modificada | Alta (7.5) | 1.3% | — | Echatserver Easy Chat Server | 12/6/2017 | 17/6/2026 | register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to reset arbitrary passwords via a crafted POST request to registresult.htm. | |
| Modificada | Alta (8.8) | 2.6% | — | Atlassian Hipchat Server | 5/5/2017 | 17/6/2026 | Atlassian Hipchat Server before 2.2.4 allows remote authenticated users with user level privileges to execute arbitrary code via vectors involving image uploads. | |
| Modificada | Crítica (9.1) | 2.6% | — | Atlassian Hipchat Server | 14/4/2017 | 17/6/2026 | Hipchat Server before 2.2.3 allows remote authenticated users with Server Administrator level privileges to execute arbitrary code by importing a file. | |
| Modificada | Media (5.8) | 0.83% | — | Apple Ichat Server | 25/8/2012 | 16/6/2026 | Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted. | |
| Modificada | Media (5.8) | 1.3% | — | Zeacom Chat Server | 20/5/2011 | 16/6/2026 | Zeacom Chat Server before 5.1 uses too short a random string for the JSESSIONID value, which makes it easier for remote attackers to hijack sessions or cause a denial of service (Chat Server crash or Tomcat daemon crash) via a brute-force attack. |