Vulnerabilities
Summary — last 7 days
New vulnerabilities2,751▲ 29 vs. last week
Critical / high1,468▲ 334 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)85▼ 441 vs. last week
4 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Modified | Medium (6.1) | 0.71% | — | Urlchatbox Chat Anywhere | 12/27/2018 | 6/17/2026 | The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP). | |
| Modified | Medium (4.6) | 0.56% | — | Lionmax Software Chat Anywhere | 5/2/2005 | 6/16/2026 | Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges. | |
| Modified | Medium (5) | 1.5% | — | Chat AnywhereAI | 12/31/2004 | 6/16/2026 | Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which causes the IP address to be displayed as $IP$ on the administration web page. | |
| Modified | High (7.1) | 1.7% | — | Lionmax Software Chat Anywhere | 12/31/2004 | 6/16/2026 | LionMax Software Chat Anywhere 2.72a allows remote attackers to cause a denial of service (server crash and client CPU consumption) via a username beginning with percent (%) followed by a null character. |