Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
111 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 1.1% | — | Softbizscripts Image Gallery Script | 7/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz Image Gallery allows remote attackers to inject arbitrary web script or HTML via msg parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Crafty Syntax Image Gallery | 7/4/2006 | 16/6/2026 | SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary SQL commands via the limitquery_s parameter when the $projectid variable is less than 1, which prevents the $limitquery_s… | |
| Modificada | Media (4.3) | 1.2% | — | Xigla Absolute Image Gallery XE | 28/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the shownew parameter in gallery.asp and (2) unspecified search module parameters. | |
| Modificada | Alta (7.5) | 10.0% | 💥 Exploit | 4images Image Gallery Management System | 27/2/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter. | |
| Modificada | Media (5) | 1.4% | — | Next Generation Image Gallery | 5/1/2006 | 16/6/2026 | Cross-site scripting vulnerability in index.php in Next Generation Image Gallery 0.0.1 Lite Edition allows remote attackers to inject arbitrary web script or HTML via the page parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Xigla Absolute Image Gallery XE | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | MY Image Gallery | 17/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) currDir or (2) image parameters. | |
| Modificada | Media (5) | 1.7% | — | MY Image Gallery | 17/8/2005 | 16/6/2026 | index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to obtain the web server path via certain currDir and image arguments, which leaks the path in an error message. | |
| Modificada | Alta (7.5) | 1.5% | — | Singapore Image Gallery WEB ApplicationAI | 31/12/2004 | 16/6/2026 | The addImage method for admin.class.php in Image Gallery Web Application 0.9.10 does not properly check filenames, which allows remote attackers to upload and execute arbitrary files. | |
| Modificada | Media (5) | 1.0% | — | Singapore Image Gallery WEB Application | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in Image Gallery Web Application 0.9.10 allow remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Media (5) | 1.6% | — | Singapore Image Gallery WEB Application | 31/12/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities in singapore Image Gallery Web Application 0.9.10 allow remote attackers to (1) read arbitrary files via the showThumb method for thumb.php, or (2) delete arbitrary files via admin.class.php. |