Vulnerabilities
Summary — last 7 days
New vulnerabilities2,774▼ 317 vs. last week
Critical / high1,288▼ 233 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
12 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Medium (6.5) | 0.15% | — | Pijey Simple Public Chat Room | 11/10/2025 | 6/17/2026 | The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery (CSRF). The application does not implement any CSRF-protection mechanisms such as tokens, nonces, or same-site cookie restrictions. An attacker can create a malicious HTML page that, when visited by… | |
| Analyzed | Low (2.1) | 0.42% | — | Fabian Public Chat Room | 7/25/2025 | 6/17/2026 | A vulnerability has been found in code-projects Public Chat Room 1.0 and classified as critical. This vulnerability affects unknown code of the file send_message.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Analyzed | Low (2) | 0.33% | — | Fabian Public Chat Room | 7/22/2025 | 6/17/2026 | A vulnerability classified as problematic has been found in code-projects Public Chat Room 1.0. This affects an unknown part of the file /send_message.php. The manipulation of the argument chat_msg/your_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed… | |
| Analyzed | Medium (5.5) | 0.55% | — | Fabian Public Chat Room | 7/22/2025 | 6/17/2026 | A vulnerability was found in code-projects Public Chat Room 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the… | |
| Modified | Medium (5) | 1.2% | — | Chat Room Project Chat Room | 12/17/2015 | 6/17/2026 | The Chat Room module 7.x-2.x before 7.x-2.2 for Drupal does not properly check permissions when setting up a websocket for chat messages, which allows remote attackers to bypass intended access restrictions and read messages from arbitrary Chat Rooms via unspecified vectors. | |
| Modified | Medium (4.3) | 0.97% | — | Ttfreeware Tigertoms Chat Room | 1/1/2015 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in TTChat 1.0.4 allow remote attackers to inject arbitrary web script or HTML via (1) the msg parameter to default.php or (2) the username parameter to chat_form.php. | |
| Modified | Low (3.5) | 2.6% | 💥 Exploit | PRO Chat Rooms Text Chat Rooms | 10/20/2014 | 6/17/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject arbitrary web script or HTML via (1) an uploaded profile picture or (2) the edit parameter to profiles/index.php. | |
| Modified | Medium (6.5) | 1.9% | 💥 Exploit | Prochatrooms Text Chat Rooms | 10/20/2014 | 6/17/2026 | Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) password, (2) email, or (3) id parameter. | |
| Modified | Medium (5.4) | 0.27% | — | Chatbox - Chat Rooms | 9/19/2014 | 6/17/2026 | The ChatBox - Chat Rooms (aka com.droidchatroom.messengerapp) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modified | Medium (4.6) | 1.5% | 💥 Exploit | Prochatrooms PRO Chat Rooms | 3/20/2009 | 6/16/2026 | Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local PHP script as an avatar via a .. (dot dot) in the avatar parameter, and cause other users to execute this script by using sendData.php to send a message to (1) an individual user or (2) a room,… | |
| Modified | Medium (4.3) | 1.5% | 💥 Exploit | Prochatrooms PRO Chat Rooms | 3/20/2009 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in profiles/index.php in Pro Chat Rooms 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the gud parameter. | |
| Modified | High (7.5) | 0.97% | 💥 Exploit | PRO Chat Rooms | 11/14/2008 | 6/16/2026 | SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the gud parameter to (1) profiles/index.php and (2) profiles/admin.php. |