Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2723▼ 319 respecto a la semana anterior
Críticas / altas1277▼ 191 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)210▼ 117 respecto a la semana anterior
1355 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.41% | — | Fooplugins Foogallery | 2/10/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento FooPlugins FooGallery en versiones <= 2.2.44. | |
| Modificada | Media (6.1) | 0.35% | — | I13websolution WEB Solution Photo Gallery Slideshow & Masonry Tiled Gallery | 29/9/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada No Autenticada en el complemento I Thirteen Web Solution Photo Gallery Slideshow & Masonry Tiled Gallery en versiones <= 1.0.13. | |
| Modificada | Media (5.5) | 0.17% | — | Samsung Gallery | 6/9/2023 | 17/6/2026 | La autenticación incorrecta en LocalProvier of Gallery anterior a la versión 14.5.01.2 permite a un atacante acceder a los datos del proveedor de contenidos. | |
| Modificada | Baja (3.3) | 0.17% | — | Samsung Gallery | 6/9/2023 | 17/6/2026 | Una autenticación inadecuada en GallerySearchProvider de Gallery anterior a la versión 14.5.01.2 permite a los atacantes el acceso al historial de búsqueda. | |
| Modificada | Media (4.8) | 0.47% | — | Robogallery Robo Gallery | 4/9/2023 | 17/6/2026 | El plugin The Photo Gallery, Images, Slider in Rbs Image Gallery para WordPress antes de la versión 3.2.16 no sanitiza ni escapa alguno de sus ajustes, lo que podría permitir a los usuarios de alto privilegio, tales como administradores, llevar a cabo ataques de Cross-Site Scripting (XSS) almacenado incluso cuando la… | |
| Modificada | Media (4.8) | 0.36% | — | Yotuwp Video Gallery | 1/9/2023 | 17/6/2026 | Una vulnerabilidad de tipo Cross-Site Scripting (XSS) Autenticada Almacenada (admin+) en el plugin Yotuwp Video Gallery en las versiones anteriores e incluyendo a la v1.3.12. | |
| Modificada | Media (4.8) | 0.37% | — | Unitegallery Unite Gallery Lite | 30/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Almacenada en el plugin Unite Gallery Lite de Valiano que afecta a las versiones 1.7.61 e inferiores. Para explotar esta vulnerabilidad hace falta estar autenticado y tener permisos de administrador o superior. | |
| Modificada | Media (6.1) | 0.35% | — | I13websolution Video Gallery | 30/8/2023 | 17/6/2026 | Vulnerabilidad de Cross-Site Scripting (XSS) Reflejada en el plugin Video Gallery de I Thirteen Web Solution que afecta a las versiones 1.0.10 e inferiores. Para explotar esta vulnerabilidad no hace falta estar autenticado. | |
| Modificada | Media (6.1) | 0.40% | — | Ays-pro Photo Gallery | 18/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Photo Gallery Team Photo Gallery by Ays – Responsive Image Gallery plugin <= 5.1.3 versions. | |
| Modificada | Media (6.1) | 0.35% | — | Admiror-design-studio Admiror Gallery | 7/8/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements. | |
| Modificada | Crítica (9.8) | 0.60% | — | Creative-solutions Creative Gallery | 7/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | |
| Modificada | Crítica (9.8) | 0.60% | — | Bestaddon Gallery | 7/8/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability allows SQL Injection. | |
| Modificada | Crítica (9.8) | 1.5% | 💥 PoC | Phpgurukul ART Gallery Management System | 31/7/2023 | 17/6/2026 | Art Gallery Management System v1.0 contains a SQL injection vulnerability via the cid parameter at /agms/product.php. | |
| Modificada | Media (6.1) | 0.46% | — | Wpsofts Portfolio Gallery, Product Catalog - Grid KIT Portfolio | 31/7/2023 | 17/6/2026 | The grid-kit-premium WordPress plugin before 2.2.0 does not escape some parameters as well as generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.38% | — | Radiustheme Variation Images Gallery FOR Woocommerce | 27/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RadiusTheme Variation Images Gallery for WooCommerce plugin <= 2.3.3 versions. | |
| Modificada | Media (4.3) | 0.50% | — | Navz ACF Photo Gallery Field | 27/7/2023 | 17/6/2026 | El plugin ACF Photo Gallery Field para WordPress es vulnerable a la modificación no autorizada de datos debido a una restricción insuficiente de la función "apg_profile_update" en las versiones hasta la 1.9 inclusive. Esto hace posible que atacantes autenticados, con permisos de nivel de suscriptor o superior… | |
| Modificada | Alta (8.8) | 0.25% | — | Flickr Justified Gallery Project Flickr Justified Gallery | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Miro Mannino Flickr Justified Gallery plugin <= 3.5 versions. | |
| Modificada | Alta (8.8) | 0.27% | — | Awplife Album Gallery | 17/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in A WP Life Album Gallery – WordPress Gallery plugin <= 1.4.9 versions. | |
| Modificada | Media (4.3) | 0.46% | — | Gallery-metabox Project Gallery-metabox | 12/7/2023 | 17/6/2026 | The Gallery Metabox for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the refresh_metabox function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to obtain a list of images attached to a post. | |
| Modificada | Media (4.3) | 0.41% | — | Gallery-metabox Project Gallery-metabox | 12/7/2023 | 17/6/2026 | The Gallery Metabox for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the gallery_remove function in versions up to, and including, 1.5. This makes it possible for subscriber-level attackers to modify galleries attached to posts and pages with this plugin. | |
| Modificada | Media (6.5) | 0.22% | — | Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions. | |
| Modificada | Crítica (9.8) | 2.0% | — | Online ART Gallery Project Online ART Gallery | 10/7/2023 | 17/6/2026 | Projectworlds Online Art Gallery Project 1.0 allows unauthenticated users to perform arbitrary file uploads via the adminHome.php page. Note: This has been disputed as not a valid vulnerability. | |
| Modificada | Media (5.4) | 0.36% | — | Simplephpscripts Photo Gallery PHP | 7/7/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SimplePHPscripts Photo Gallery PHP 2.0. This vulnerability affects unknown code of the file /preview.php of the component URL Parameter Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. VDB-233290 is the identifier… | |
| Modificada | Media (6.1) | 0.38% | — | Contest-gallery Contest Gallery | 22/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contest Gallery plugin <= 21.1.2 versions. | |
| Modificada | Media (6.1) | 0.39% | — | Wordpress Nextgen Galleryview Project Wordpress Nextgen Galleryview | 20/6/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin <= 0.5.5 versions. |