Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.64%—Sigoden AichatAI2/9/202628/9/2026
A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. This manipulation causes uncontrolled memory allocation. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early…
AplazadaMedia (6.4)0.30%—Kiwichat NextclientAI2/5/202517/6/2026
The KiwiChat NextClient plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
ModificadaCrítica (9.8)1.9%—Matrix ElementMatrix Javascript SDKMatrix OLMSchildichat+214/12/202117/6/2026
The olm_session_describe function in Matrix libolm before 3.2.7 is vulnerable to a buffer overflow. The Olm session object represents a cryptographic channel between two parties. Therefore, its state is partially controllable by the remote party of the channel. Attackers can construct a crafted sequence of messages to…
ModificadaMedia (5.4)0.60%—Ichat Project Ichat27/8/202017/6/2026
Michael-design iChat Realtime PHP Live Support System 1.6 has persistent Cross-site Scripting via chat,text-filed tags.
ModificadaMedia (5)2.5%—Codelogic Freichat18/8/201517/6/2026
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to server/freichat.php.
ModificadaMedia (4.3)1.9%—Codologic COM Freichat19/3/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Freichat (com_freichat) component, possibly 9.4 and earlier, for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) xhash parameter to client/chat.php or (3) toname parameter to client/plugins/upload/upload.php.
ModificadaMedia (5.8)0.83%—Apple Ichat Server25/8/201216/6/2026
Apple iChat Server does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domains via responses for domains that were not asserted.
ModificadaMedia (4.3)1.7%—Evnix FreichatEvnix Freichatpure9/10/201116/6/2026
Cross-site scripting (XSS) vulnerability in the (1) FreiChat component before 2.1.2 for Joomla! and the (2) FreiChatPure component before 1.2.2 for Joomla! allows remote attackers to inject arbitrary web script or HTML by entering it in an unspecified window.
ModificadaMedia (6.8)3.4%—Apple Ichat3/8/200716/6/2026
The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not restrict object instantiation and manipulation to valid heap addresses, which allows remote attackers to execute arbitrary code via a crafted applet.
ModificadaMedia (5.4)2.1%—Apple Ichat3/8/200716/6/2026
Buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in iChat on Apple Mac OS X 10.3.9 and 10.4.10 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet.
ModificadaMedia (6.8)3.4%—Apple Ichat3/8/200716/6/2026
The Java interface to CoreAudio on Apple Mac OS X 10.3.9 and 10.4.10 does not properly check the bounds of heap read and write operations, which allows remote attackers to execute arbitrary code via a crafted applet.
ModificadaBaja (2.1)3.4%—Apple Ichat16/2/200716/6/2026
The Bonjour functionality in iChat in Apple Mac OS X 10.3.9 allows remote attackers to cause a denial of service (persistent application crash) via unspecified vectors, possibly related to CVE-2007-0614.
ModificadaMedia (5)7.4%—Apple IchatApple Instant Message FrameworkApple Mdnsresponder31/1/200716/6/2026
The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 does not check for duplicate entries when adding newly discovered available contacts, which allows remote attackers to cause a denial of service (disrupted communication) via a flood of duplicate…
ModificadaAlta (7.8)8.6%—Apple IchatApple Instant Message FrameworkApple MAC OS X31/1/200716/6/2026
The Bonjour functionality in mDNSResponder, iChat 3.1.6, and InstantMessage framework 428 in Apple Mac OS X 10.4.8 allows remote attackers to cause a denial of service (persistent application crash) via a crafted phsh hash attribute in a TXT key.
ModificadaAlta (7.5)23%—Apple Ichat23/1/200716/6/2026
Format string vulnerability in Apple iChat 3.1.6 allows remote attackers to cause a denial of service (null pointer dereference and application crash) and possibly execute arbitrary code via format string specifiers in an aim:// URI.
ModificadaAlta (7.5)2.9%—Minichat13/10/200616/6/2026
PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter.
ModificadaAlta (7.5)1.3%—Apple IchatApple Ichat AV23/12/200416/6/2026
Apple iChat AV 2.1, AV 2.0, and 1.0.1 allows remote attackers to execute arbitrary programs via a "link" that references the program.
ModificadaMedia (5)1.7%—Unichat2/11/200316/6/2026
Unichat allows remote attackers to cause a denial of service (crash) by adding extra chat characters (avatars) and logging in to a chat room, as demonstrated using duplicate ACTOR entries in u2res000.rit.
ModificadaMedia (5)1.1%—Digi-net Technologies Digichat31/12/200216/6/2026
Digi-Net Technologies DigiChat 3.5 allows chat users to obtain the IP addresses of other chat users via a "Showip" parameter in the chat applet.
ModificadaMedia (5)1.3%—Apple Ichat Server9/9/199816/6/2026
iChat ROOMS Webserver allows remote attackers to read arbitrary files via a .. (dot dot) attack.