Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
–

1355 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.41%—Fooplugins Foogallery2/10/202317/6/2026
Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento FooPlugins FooGallery en versiones <= 2.2.44.
ModificadaMedia (6.1)0.35%—I13websolution WEB Solution Photo Gallery Slideshow & Masonry Tiled Gallery29/9/202317/6/2026
Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento I Thirteen Web Solution Photo Gallery Slideshow & Masonry Tiled Gallery en versiones <= 1.0.13.
ModificadaMedia (5.5)0.17%—Samsung Gallery6/9/202317/6/2026
La autenticación incorrecta en LocalProvier of Gallery anterior a la versión 14.5.01.2 permite a un atacante acceder a los datos del proveedor de contenidos.
ModificadaBaja (3.3)0.17%—Samsung Gallery6/9/202317/6/2026
Una autenticación inadecuada en GallerySearchProvider de Gallery anterior a la versión 14.5.01.2 permite a los atacantes el acceso al historial de búsqueda.
ModificadaMedia (4.8)0.47%—Robogallery Robo Gallery4/9/202317/6/2026
El plugin The Photo Gallery, Images, Slider in Rbs Image Gallery para WordPress antes de la versión 3.2.16 no sanitiza ni escapa alguno de sus ajustes, lo que podría permitir a los usuarios de alto privilegio, tales como administradores, llevar a cabo ataques de Cross-Site Scripting (XSS) almacenado incluso cuando la…
ModificadaMedia (4.8)0.36%—Yotuwp Video Gallery1/9/202317/6/2026
Una vulnerabilidad de tipo Cross-Site Scripting (XSS) Autenticada Almacenada (admin+) en el plugin Yotuwp Video Gallery en las versiones anteriores e incluyendo a la v1.3.12.
ModificadaMedia (4.8)0.37%—Unitegallery Unite Gallery Lite30/8/202317/6/2026
Vulnerabilidad de Cross-Site Scripting (XSS) Almacenada en el plugin Unite Gallery Lite de Valiano que afecta a las versiones 1.7.61 e inferiores. Para explotar esta vulnerabilidad hace falta estar autenticado y tener permisos de administrador o superior.
ModificadaMedia (6.1)0.35%—I13websolution Video Gallery30/8/202317/6/2026
Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada en el plugin Video Gallery de I Thirteen Web Solution que afecta a las versiones 1.0.10 e inferiores. Para explotar esta vulnerabilidad no hace falta estar autenticado.
ModificadaMedia (6.1)0.40%—Ays-pro Photo Gallery18/8/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.1.3 versions.
ModificadaMedia (6.1)0.35%—Admiror-design-studio Admiror Gallery7/8/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.
ModificadaCrítica (9.8)0.60%—Creative-solutions Creative Gallery7/8/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
ModificadaCrítica (9.8)0.60%—Bestaddon Gallery7/8/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection.
ModificadaCrítica (9.8)1.5%💥 PoCPhpgurukul ART Gallery Management System31/7/202317/6/2026
Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php.
ModificadaMedia (6.1)0.46%—Wpsofts Portfolio Gallery, Product Catalog - Grid KIT Portfolio31/7/202317/6/2026
The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
ModificadaMedia (6.1)0.38%—Radiustheme Variation Images Gallery FOR Woocommerce27/7/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Images Gallery for WooCommerce plugin <= 2.3.3 versions.
ModificadaMedia (4.3)0.50%—Navz ACF Photo Gallery Field27/7/202317/6/2026
El plugin ACF Photo Gallery Field para WordPress es vulnerable a la modificación no autorizada de datos debido a una restricción insuficiente de la función "apg_profile_update" en las versiones hasta la 1.9 inclusive. Esto hace posible que atacantes autenticados, con permisos de nivel de suscriptor o superior…
ModificadaAlta (8.8)0.25%—Flickr Justified Gallery Project Flickr Justified Gallery18/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Miro Mannino Flickr Justified Gallery plugin <= 3.5 versions.
ModificadaAlta (8.8)0.27%—Awplife Album Gallery17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions.
ModificadaMedia (4.3)0.46%—Gallery-metabox Project Gallery-metabox12/7/202317/6/2026
The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to obtain a list of images attached to a post.
ModificadaMedia (4.3)0.41%—Gallery-metabox Project Gallery-metabox12/7/202317/6/2026
The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin.
ModificadaMedia (6.5)0.22%—Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview11/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
ModificadaCrítica (9.8)2.0%—Online ART Gallery Project Online ART Gallery10/7/202317/6/2026
Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability.
ModificadaMedia (5.4)0.36%—Simplephpscripts Photo Gallery PHP7/7/202317/6/2026
A vulnerability classified as problematic was found in SimplePHPscripts Photo Gallery PHP 2.0. This vulnerability affects unknown code of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. VDB-233290 is the identifier…
ModificadaMedia (6.1)0.38%—Contest-gallery Contest Gallery22/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 21.1.2 versions.
ModificadaMedia (6.1)0.39%—Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview20/6/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions.
Orbitaley — Vulnerabilidades