Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

38 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.39%—Phpgurukul ART Gallery Management System6/3/202517/6/2026
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /search.php. The manipulation of the argument search leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed…
AnalizadaMedia (5.3)0.67%—Donbermoy Online ART Gallery Management System16/5/202417/6/2026
A vulnerability was found in SourceCodester Online Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file admin/adminHome.php. The manipulation of the argument sliderpic leads to unrestricted upload. The attack can be launched…
AnalizadaAlta (7.5)0.64%—Campcodes Online ART Gallery Management System27/3/202417/6/2026
A vulnerability classified as critical has been found in Campcodes Online Art Gallery Management System 1.0. This affects an unknown part of the file /admin/adminHome.php. The manipulation of the argument uname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
ModificadaMedia (6.5)0.54%—Phpgurukul ART Gallery Management System12/1/202417/6/2026
In PHPGurukul Art Gallery Management System v1.1, "Update Artist Image" functionality of "imageid" parameter is vulnerable to SQL Injection.
ModificadaCrítica (9.8)1.5%💥 PoCPhpgurukul ART Gallery Management System31/7/202317/6/2026
Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.
ModificadaCrítica (9.8)1.1%—Phpgurukul ART Gallery Management System15/3/202317/6/2026
Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page.
ModificadaMedia (5.4)0.56%—Phpgurukul ART Gallery Management System27/2/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the message parameter on the enquiry page.
ModificadaMedia (5.4)0.56%—Phpgurukul ART Gallery Management System27/2/202317/6/2026
A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fullname parameter on the enquiry page.
ModificadaCrítica (9.8)3.7%💥 ExploitPhpgurukul ART Gallery Management System27/2/202317/6/2026
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page.
ModificadaCrítica (9.8)1.1%—Phpgurukul ART Gallery Management System27/2/202317/6/2026
Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login.
ModificadaCrítica (9.8)4.4%💥 ExploitPhpgurukul ART Gallery Management System10/2/202317/6/2026
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
ModificadaCrítica (9.8)4.4%💥 ExploitPhpgurukul ART Gallery Management System10/2/202317/6/2026
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at product.php.
ModificadaMedia (6.1)5.9%💥 ExploitPhpgurukul ART Gallery Management System10/2/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the artname parameter under ART TYPE option in the navigation bar.
Orbitaley — Vulnerabilidades