Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
111 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Softcomplex PHP Image Gallery | 18/3/2009 | 16/6/2026 | SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the Admin field in a login action. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Softcomplex PHP Image Gallery | 18/3/2009 | 16/6/2026 | SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the ctg parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Akirapowered Image Gallery | 13/3/2009 | 16/6/2026 | SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL commands via the image parameter in an image-detail action. | |
| Modificada | Media (4.3) | 5.8% | 💥 Exploit | Wordpress Page Flip Image Gallery Plugin | 30/12/2008 | 16/6/2026 | Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the book_id parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Elkagroup Image Gallery | 12/11/2008 | 16/6/2026 | SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Analizada | Media (4.3) | 1.5% | 💥 Exploit | Softbizscripts Image Gallery Script | 7/8/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php,… | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Minishowcase Image Gallery | 31/7/2008 | 16/6/2026 | Directory traversal vulnerability in libraries/general.init.php in Minishowcase Image Gallery 09b136, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Xigla Absolute Image Gallery XE | 18/6/2008 | 16/6/2026 | SQL injection vulnerability in gallery.asp in Xigla Absolute Image Gallery XE allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action. | |
| Modificada | Media (4.3) | 1.1% | — | Xigla Absolute Image Gallery XE | 18/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Xigla Absolute Image Gallery XE allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) admin/search.asp and (2) gallery.asp. | |
| Modificada | Media (4.3) | 1.0% | — | Softcomplex PHP Image Gallery | 12/6/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in PHP Image Gallery allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Justjoomla Carousel Flash Image Gallery | 20/11/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in admin.jjgallery.php in the Carousel Flash Image Gallery (com_jjgallery) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Media (6.8) | 5.8% | 💥 Exploit | JoomlaWebmaster-tips.net Flash Image Gallery | 9/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. | |
| Modificada | Media (6.8) | 4.4% | 💥 Exploit | JoomlaWebmaster-tips.net Flash Image Gallery | 9/10/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Media (4.3) | 1.0% | — | Splitside Directory Image Gallery | 9/10/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in photos.cfm in Directory Image Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the backwardDirectory parameter. | |
| Modificada | Media (6.8) | 3.0% | 💥 Exploit | LE Ralf Ralf Image Gallery | 1/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Gallery, 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir_abs_src parameter. NOTE: this issue is disputed by multiple third parties, who report that the product exits if… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Elkagroup Image Gallery | 27/6/2007 | 16/6/2026 | SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter. | |
| Modificada | Media (6.8) | 1.2% | — | Singapore Image Gallery WEB Application | 14/6/2007 | 16/6/2026 | index.php in Singapore Gallery allows remote attackers to obtain sensitive information via a request with a non-directory gallery parameter, which reveals the path in an error message. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Xigla Absolute Image Gallery XE | 16/3/2007 | 16/6/2026 | SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Image Gallery With Access Database | 16/1/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in Image Gallery with Access Database allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to (a) dispimage.asp, or the (2) order or (3) page parameter to (b) default.asp. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Fixit Knowledge Solutions Idms PRO Image Gallery | 1/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Fixit iDMS Pro Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) show_id or (2) parentid parameter to (a) filelist.asp, or the (3) fid parameter to (b) showfile.asp. | |
| Modificada | Media (6.8) | 1.6% | — | Fixit Knowledge Solutions Idms PRO Image Gallery | 1/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the search functionality in Fixit iDMS Pro Image Gallery allows remote attackers to inject arbitrary web script or HTML via a search field (txtsearchtext parameter). | |
| Modificada | Media (5.1) | 14% | 💥 Exploit | LE Ralf Ralf Image Gallery | 24/6/2006 | 16/6/2026 | Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or ".." sequences in the (1) dir_abs_src parameter in (a) check_entry.php, (b) admin_album.php, (c) admin_image.php, and… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | 4images Image Gallery Management System | 5/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2. | |
| Analizada | Media (6.4) | 2.2% | 💥 Exploit | Softbizscripts Image Gallery Script | 7/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id parameter in insert_rating.php, and (5) cid parameter in… | |
| Modificada | Alta (9) | 4.2% | 💥 Exploit | Crafty Syntax Image Gallery | 7/4/2006 | 16/6/2026 | newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullimage parameter and the ext parameter set to .php. |