Vulnerabilities

Summary — last 7 days

New vulnerabilities2,751▲ 29 vs. last week
Critical / high1,468▲ 334 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)85▼ 441 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
ModifiedMedium (6.1)0.71%—Urlchatbox Chat Anywhere12/27/20186/17/2026
The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP).
ModifiedMedium (4.6)0.56%—Lionmax Software Chat Anywhere5/2/20056/16/2026
Chat Anywhere 2.72a stores sensitive information such as passwords in plaintext in the .INI file for a chatroom, which allows local users to gain privileges.
ModifiedMedium (5)1.5%—Chat AnywhereAI12/31/20046/16/2026
Chat Anywhere 2.72 and earlier allows remote attackers to hide their IP address by using %00 before the nickname, which causes the IP address to be displayed as $IP$ on the administration web page.
ModifiedHigh (7.1)1.7%—Lionmax Software Chat Anywhere12/31/20046/16/2026
LionMax Software Chat Anywhere 2.72a allows remote attackers to cause a denial of service (server crash and client CPU consumption) via a username beginning with percent (%) followed by a null character.