Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2746▼ 296 respecto a la semana anterior
Críticas / altas1284▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)213▼ 109 respecto a la semana anterior
1355 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.44% | — | Pluginus Inpost Gallery | 22/3/2023 | 17/6/2026 | The InPost Gallery WordPress plugin, in versions < 2.2.2, is affected by a reflected cross-site scripting vulnerability in the 'imgurl' parameter to the add_inpost_gallery_slide_item action, which can only be triggered by an authenticated user. | |
| Modificada | Media (5.4) | 0.38% | — | Galaxyweblinks Gallery With Thumbnail Slider | 21/3/2023 | 17/6/2026 | Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Galaxy Weblinks Gallery with thumbnail slider plugin <= 6.0 versions. | |
| Modificada | Media (5.4) | 0.38% | — | Robogallery Gallery Images APE | 21/3/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting vulnerability in Galleryape Gallery Images Ape plugin <= 2.2.8 versions. | |
| Modificada | Media (6.1) | 0.52% | — | Code-projects Simple ART Gallery | 19/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in code-projects Simple Art Gallery 1.0. Affected by this issue is some unknown functionality of the file adminHome.php. The manipulation of the argument about_info leads to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.73% | — | Code-projects Simple ART Gallery | 19/3/2023 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Simple Art Gallery 1.0. Affected by this vulnerability is an unknown functionality of the file adminHome.php. The manipulation of the argument reach_city leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Modificada | Crítica (9.8) | 2.0% | — | Simple Image Gallery WEB APP Project Simple Image Gallery WEB APP | 16/3/2023 | 17/6/2026 | Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter. | |
| Modificada | Crítica (9.8) | 0.76% | — | Code-projects Simple ART Gallery | 15/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Simple Art Gallery 1.0. Affected is an unknown function of the file adminHome.php. The manipulation of the argument social_facebook leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (8.8) | 1.0% | — | Code-projects Simple ART Gallery | 15/3/2023 | 17/6/2026 | A vulnerability was found in Simple Art Gallery 1.0. It has been declared as critical. This vulnerability affects the function sliderPicSubmit of the file adminHome.php. The manipulation leads to unrestricted upload. The attack can be initiated remotely. VDB-223126 is the identifier assigned to this vulnerability. | |
| Modificada | Crítica (9.8) | 1.1% | — | Phpgurukul ART Gallery Management System | 15/3/2023 | 17/6/2026 | Art Gallery Management System v1.0 was discovered to contain a SQL injection vulnerability via the viewid parameter on the enquiry page. | |
| Modificada | Media (5.4) | 0.23% | — | Robogallery Robo Gallery | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RoboSoft Photo Gallery, Images, Slider in Rbs Image Gallery plugin <= 3.2.9 leading to galleries hierarchy change, included plugin deactivate & activate. | |
| Modificada | Media (4.3) | 0.23% | — | Imagely Nextgen Gallery | 1/3/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Imagely WordPress Gallery Plugin – NextGEN Gallery plugin <= 3.28 leading to thumbnail alteration. | |
| Modificada | Media (5.4) | 0.56% | — | Phpgurukul ART Gallery Management System | 27/2/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the message parameter on the enquiry page. | |
| Modificada | Media (5.4) | 0.56% | — | Phpgurukul ART Gallery Management System | 27/2/2023 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Art Gallery Management System Project v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fullname parameter on the enquiry page. | |
| Modificada | Crítica (9.8) | 3.7% | 💥 Exploit | Phpgurukul ART Gallery Management System | 27/2/2023 | 17/6/2026 | Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the pid parameter in the single-product page. | |
| Modificada | Crítica (9.8) | 1.1% | — | Phpgurukul ART Gallery Management System | 27/2/2023 | 17/6/2026 | Art Gallery Management System Project in PHP 1.0 was discovered to contain a SQL injection vulnerability via the username parameter in the Admin Login. | |
| Modificada | Crítica (9.8) | 0.46% | — | Music Gallery Site Project Music Gallery Site | 27/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=user/manage. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is… | |
| Modificada | Crítica (9.8) | 0.46% | — | Music Gallery Site Project Music Gallery Site | 27/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Music Gallery Site 1.0 and classified as critical. This issue affects some unknown processing of the file view_category.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is… | |
| Modificada | Crítica (9.8) | 4.7% | 💥 Exploit | Music Gallery Site Project Music Gallery Site | 22/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Alta (8.8) | 1.7% | 💥 Exploit | Music Gallery Site Project Music Gallery Site | 22/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. This vulnerability affects unknown code of the file Master.php of the component GET Request Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 1.9% | 💥 Exploit | Music Gallery Site Project Music Gallery Site | 22/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been classified as critical. This affects an unknown part of the file view_music_details.php of the component GET Request Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The… | |
| Modificada | Crítica (9.8) | 1.8% | 💥 Exploit | Music Gallery Site Project Music Gallery Site | 21/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file music_list.php of the component GET Request Handler. The manipulation of the argument cid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (5.4) | 0.48% | — | Utubevideo Gallery Project Utubevideo Gallery | 13/2/2023 | 17/6/2026 | The uTubeVideo Gallery WordPress plugin before 2.0.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.48% | — | Responsive Gallery Grid Project Responsive Gallery Grid | 13/2/2023 | 17/6/2026 | The Responsive Gallery Grid WordPress plugin before 2.3.9 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.47% | — | Youtube Channel Gallery Project Youtube Channel Gallery | 13/2/2023 | 17/6/2026 | The Youtube Channel Gallery WordPress plugin through 2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.71% | — | Wpgogo Lightbox-gallery | 13/2/2023 | 17/6/2026 | The Lightbox Gallery WordPress plugin before 0.9.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks |