Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.64% | — | Sigoden AichatAI | 2/9/2026 | 28/9/2026 | A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. This manipulation causes uncontrolled memory allocation. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early… | |
| Aplazada | Media (6.4) | 0.30% | — | Kiwichat NextclientAI | 2/5/2025 | 17/6/2026 | The KiwiChat NextClient plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Modificada | Crítica (9.8) | 1.9% | — | Matrix ElementMatrix Javascript SDKMatrix OLMSchildichat+2 | 14/12/2021 | 17/6/2026 | The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to… | |
| Modificada | Media (5.4) | 0.60% | — | Ichat Project Ichat | 27/8/2020 | 17/6/2026 | Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags. | |
| Modificada | Media (5) | 2.5% | — | Codelogic Freichat | 18/8/2015 | 17/6/2026 | SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to server/freichat.php. | |
| Modificada | Media (4.3) | 1.9% | — | Codologic COM Freichat | 19/3/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) xhash parameter to client/chat.php or (3) toname parameter to client/plugins/upload/upload.php. | |
| Modificada | Media (5.8) | 0.83% | — | Apple Ichat Server | 25/8/2012 | 16/6/2026 | Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted. | |
| Modificada | Media (4.3) | 1.7% | — | Evnix FreichatEvnix Freichatpure | 9/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure component before 1.2.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML by entering it in an unspecified window. | |
| Modificada | Media (6.8) | 3.4% | — | Apple Ichat | 3/8/2007 | 16/6/2026 | The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not restrict object instantiation and manipulation to valid heap addresses, which allows remote attackers to execute arbitrary code via a crafted applet. | |
| Modificada | Media (5.4) | 2.1% | — | Apple Ichat | 3/8/2007 | 16/6/2026 | Buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in iChat on Apple Mac OS X 10.3.9 and 10.4.10 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet. | |
| Modificada | Media (6.8) | 3.4% | — | Apple Ichat | 3/8/2007 | 16/6/2026 | The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not properly check the bounds of heap read and write operations, which allows remote attackers to execute arbitrary code via a crafted applet. | |
| Modificada | Baja (2.1) | 3.4% | — | Apple Ichat | 16/2/2007 | 16/6/2026 | The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614. | |
| Modificada | Media (5) | 7.4% | — | Apple IchatApple Instant Message FrameworkApple Mdnsresponder | 31/1/2007 | 16/6/2026 | The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of service (disrupted communication) via a flood of duplicate… | |
| Modificada | Alta (7.8) | 8.6% | — | Apple IchatApple Instant Message FrameworkApple MAC OS X | 31/1/2007 | 16/6/2026 | The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key. | |
| Modificada | Alta (7.5) | 23% | — | Apple Ichat | 23/1/2007 | 16/6/2026 | Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI. | |
| Modificada | Alta (7.5) | 2.9% | — | Minichat | 13/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Apple IchatApple Ichat AV | 23/12/2004 | 16/6/2026 | Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program. | |
| Modificada | Media (5) | 1.7% | — | Unichat | 2/11/2003 | 16/6/2026 | Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit. | |
| Modificada | Media (5) | 1.1% | — | Digi-net Technologies Digichat | 31/12/2002 | 16/6/2026 | Digi-Net Technologies DigiChat 3.5 allows chat users to obtain the IP addresses of other chat users via a "Showip" parameter in the chat applet. | |
| Modificada | Media (5) | 1.3% | — | Apple Ichat Server | 9/9/1998 | 16/6/2026 | iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack. |