Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

111 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.97%💥 ExploitSoftcomplex PHP Image Gallery18/3/200916/6/2026
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the Admin field in a login action.
ModificadaAlta (7.5)0.97%💥 ExploitSoftcomplex PHP Image Gallery18/3/200916/6/2026
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary SQL commands via the ctg parameter.
ModificadaAlta (7.5)0.97%💥 ExploitAkirapowered Image Gallery13/3/200916/6/2026
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e107 allows remote attackers to execute arbitrary SQL commands via the image parameter in an image-detail action.
ModificadaMedia (4.3)5.8%💥 ExploitWordpress Page Flip Image Gallery Plugin30/12/200816/6/2026
Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the book_id parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.96%💥 ExploitElkagroup Image Gallery12/11/200816/6/2026
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
AnalizadaMedia (4.3)1.5%💥 ExploitSoftbizscripts Image Gallery Script7/8/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Image Gallery (Photo Gallery) allow remote attackers to inject arbitrary web script or HTML via the (1) latest parameter to (a) index.php, (b) images.php, (c) suggest_image.php, and (d) image_desc.php; and the (2) msg parameter to index.php, images.php,…
ModificadaMedia (6.8)1.9%💥 ExploitMinishowcase Image Gallery31/7/200816/6/2026
Directory traversal vulnerability in libraries/general.init.php in Minishowcase Image Gallery 09b136, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang parameter.
ModificadaAlta (7.5)1.2%—Xigla Absolute Image Gallery XE18/6/200816/6/2026
SQL injection vulnerability in gallery.asp in Xigla Absolute Image Gallery XE allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.
ModificadaMedia (4.3)1.1%—Xigla Absolute Image Gallery XE18/6/200816/6/2026
Cross-site scripting (XSS) vulnerability in Xigla Absolute Image Gallery XE allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in (1) admin/search.asp and (2) gallery.asp.
ModificadaMedia (4.3)1.0%—Softcomplex PHP Image Gallery12/6/200816/6/2026
Cross-site scripting (XSS) vulnerability in index.php in PHP Image Gallery allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.8)2.1%💥 ExploitJustjoomla Carousel Flash Image Gallery20/11/200716/6/2026
PHP remote file inclusion vulnerability in admin.jjgallery.php in the Carousel Flash Image Gallery (com_jjgallery) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
ModificadaMedia (6.8)5.8%💥 ExploitJoomlaWebmaster-tips.net Flash Image Gallery9/10/200716/6/2026
PHP remote file inclusion vulnerability in admin.wmtgallery.php in the webmaster-tips.net Flash Image Gallery (com_wmtgallery) 1.0 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.
ModificadaMedia (6.8)4.4%💥 ExploitJoomlaWebmaster-tips.net Flash Image Gallery9/10/200716/6/2026
PHP remote file inclusion vulnerability in admin.wmtportfolio.php in the webmaster-tips.net wmtportfolio 1.0 (com_wmtportfolio) component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
ModificadaMedia (4.3)1.0%—Splitside Directory Image Gallery9/10/200716/6/2026
Cross-site scripting (XSS) vulnerability in photos.cfm in Directory Image Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the backwardDirectory parameter.
ModificadaMedia (6.8)3.0%💥 ExploitLE Ralf Ralf Image Gallery1/8/200716/6/2026
PHP remote file inclusion vulnerability in check_entry.php in Ralf Image Gallery (RIG), aka Raphael Moll RIG Image Gallery, 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir_abs_src parameter. NOTE: this issue is disputed by multiple third parties, who report that the product exits if…
ModificadaAlta (7.5)1.1%💥 ExploitElkagroup Image Gallery27/6/200716/6/2026
SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
ModificadaMedia (6.8)1.2%—Singapore Image Gallery WEB Application14/6/200716/6/2026
index.php in Singapore Gallery allows remote attackers to obtain sensitive information via a request with a non-directory gallery parameter, which reveals the path in an error message.
ModificadaAlta (7.5)1.2%💥 ExploitXigla Absolute Image Gallery XE16/3/200716/6/2026
SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewimage action.
ModificadaAlta (7.5)1.0%💥 ExploitImage Gallery With Access Database16/1/200716/6/2026
Multiple SQL injection vulnerabilities in Image Gallery with Access Database allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to (a) dispimage.asp, or the (2) order or (3) page parameter to (b) default.asp.
ModificadaAlta (7.5)1.1%💥 ExploitFixit Knowledge Solutions Idms PRO Image Gallery1/12/200616/6/2026
Multiple SQL injection vulnerabilities in Fixit iDMS Pro Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) show_id or (2) parentid parameter to (a) filelist.asp, or the (3) fid parameter to (b) showfile.asp.
ModificadaMedia (6.8)1.6%—Fixit Knowledge Solutions Idms PRO Image Gallery1/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in the search functionality in Fixit iDMS Pro Image Gallery allows remote attackers to inject arbitrary web script or HTML via a search field (txtsearchtext parameter).
ModificadaMedia (5.1)14%💥 ExploitLE Ralf Ralf Image Gallery24/6/200616/6/2026
Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or ".." sequences in the (1) dir_abs_src parameter in (a) check_entry.php, (b) admin_album.php, (c) admin_image.php, and…
ModificadaAlta (7.5)2.7%💥 Exploit4images Image Gallery Management System5/5/200616/6/2026
Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.
AnalizadaMedia (6.4)2.2%💥 ExploitSoftbizscripts Image Gallery Script7/4/200616/6/2026
Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id parameter in insert_rating.php, and (5) cid parameter in…
ModificadaAlta (9)4.2%💥 ExploitCrafty Syntax Image Gallery7/4/200616/6/2026
newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullimage parameter and the ext parameter set to .php.
Orbitaley — Vulnerabilidades