Vulnerabilities

Summary — last 7 days

New vulnerabilities2,774▼ 324 vs. last week
Critical / high1,284▼ 239 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
–

5 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (8.8)0.33%—ZechatAI5/29/20267/21/2026
Zechat 1.5 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the uname parameter. Attackers can send crafted requests to profile.php with UNION-based SQL injection payloads to retrieve table names, column names, and sensitive…
DeferredHigh (8.8)0.27%—ZechatAI5/17/20266/17/2026
Zechat 1.5 contains a SQL injection vulnerability in the v parameter that allows unauthenticated attackers to extract database information using time-based blind techniques. Attackers can exploit the v parameter with sleep-based blind injection to confirm vulnerability and extract data.
DeferredHigh (8.8)0.27%—ZechatAI5/17/20266/17/2026
Zechat 1.5 contains a SQL injection vulnerability in the hashtag parameter that allows unauthenticated attackers to extract database information using union-based techniques. Attackers can exploit the hashtag parameter with union-based payloads to retrieve table and column names.
DeferredMedium (5.3)0.14%—ZechatAI5/17/20266/17/2026
Zechat 1.5 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows an attacker to change a user's information by bypassing anti-CSRF protections. The application uses a CSRF token, but an attacker can use the hashtag parameter to inject an encoded payload and bypass the CSRF protection, allowing for…
ModifiedCritical (9.8)2.7%💥 ExploitZechat Project Zechat1/24/20186/17/2026
SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.
Orbitaley — Vulnerabilities