Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.2% | — | Cool Video Gallery Project Cool Video Gallery | 17/12/2015 | 17/6/2026 | lib/core.php in the Cool Video Gallery plugin 1.9 for WordPress allows remote attackers to execute arbitrary code via shell metacharacters in the "Width of preview image" and possibly other input fields in the "Video Gallery Settings" page. | |
| Modificada | Alta (7.5) | 40% | 💥 Exploit | Apptha Wordpress Video Gallery | 24/2/2015 | 17/6/2026 | SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin before 2.8 for WordPress allows remote attackers to execute arbitrary SQL commands via the vid parameter in a rss action to wp-admin/admin-ajax.php. | |
| Modificada | Baja (3.5) | 2.9% | 💥 Exploit | Apptha Contus Video Gallery | 26/11/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly before 2014-07-23, for WordPress allow remote authenticated users to inject arbitrary web script or HTML via the videoadssearchQuery parameter to (1) videoads/videoads.php, (2)… | |
| Modificada | Alta (7.5) | 5.0% | 💥 Exploit | Apptha Contus Video Gallery | 26/11/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in the Apptha WordPress Video Gallery (contus-video-gallery) plugin 2.5, possibly as distributed before 2014-07-23, for WordPress allow (1) remote attackers to execute arbitrary SQL commands via the vid parameter in a myextract action to wp-admin/admin-ajax.php or (2) remote… | |
| Modificada | Media (4.3) | 8.8% | 💥 Exploit | Digitalzoomstudio Video Gallery | 26/11/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in deploy/designer/preview.php in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) swfloc or (2) designrand parameter. | |
| Modificada | Media (6.5) | 1.6% | — | ALL Video Gallery Plugin Project All-video-gallery | 6/8/2014 | 17/6/2026 | SQL injection vulnerability in the All Video Gallery (all-video-gallery) plugin 1.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in an edit action in the allvideogallery_videos page to wp-admin/admin.php. | |
| Modificada | Media (6.5) | 2.3% | 💥 Exploit | Hdwplayer Hdw-player-video-player-video-gallery | 6/8/2014 | 17/6/2026 | SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the edit action to wp-admin/admin.php. | |
| Modificada | Alta (7.5) | 6.5% | 💥 Exploit | ALL Video Gallery Plugin Project ALL Video Gallery Plugin | 6/8/2014 | 16/6/2026 | Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors. | |
| Modificada | Media (4.3) | 1.6% | — | Digitalzoomstudio Video Gallery | 30/5/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Digital Zoom Studio (DZS) Video Gallery plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the logoLink parameter to (1) preview.swf, (2) preview_skin_rouge.swf, (3) preview_allchars.swf, or (4) preview_skin_overlay.swf in… | |
| Modificada | Alta (7.5) | 2.1% | — | Apptha Video Gallery Plugin | 5/3/2014 | 16/6/2026 | SQL injection vulnerability in Apptha WordPress Video Gallery 2.0, 1.6, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the playid parameter to index.php. | |
| Modificada | Media (4.3) | 4.0% | 💥 Exploit | Xondie Vodpod Video Gallery | 7/10/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery Plugin 3.1.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the gid parameter. | |
| Modificada | Media (5) | 1.2% | — | Phpnuke Video Gallery ModuleAI | 26/4/2004 | 16/6/2026 | modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to gain sensitive information via an HTTP request with an invalid (1) catid or (2) clipid parameter, which reveals the full path in an error message. |