Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2780▲ 24 respecto a la semana anterior
Críticas / altas1288▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
–

1356 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.3%—Pensacola WEB Designs Xtreme ASP Photo Gallery15/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) catname and (2) total parameters in (a) displaypic.asp, and the (3) catname parameter in (b) displaythumbs.asp.
ModificadaMedia (4.3)1.8%—Uapplication Uphotogallery15/6/200616/6/2026
Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en thumbnails.asp en Uphotogallery Uapplication v1.1 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) s y (2) block.
ModificadaMedia (4.3)1.8%—Clicktech Clickgallery15/6/200616/6/2026
Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en ClickGallery v5.0 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) el parámetro gallery_id en gallery.asp y (2) el parámetro parentcurrentpage en view_gallery.asp.
ModificadaMedia (5.8)4.3%💥 ExploitAndy Mack 35mmslidegallery15/6/200616/6/2026
Múltiples vulnerabilidades cross-site scripting (XSS) en 35mmslidegallery 6.0 permite a atacantes remotos inyectar script web o HTML de forma arbitraria a través (1) del parámetro imgdir en (a) index.php, y los parámetros (2) w, (3) h y (4) t en (b) popup.php.
ModificadaMedia (6.8)2.0%—Fipsasp Fipsgallery15/6/200616/6/2026
Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en zoom.php en fipsGallery v1.5 y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro path.
ModificadaMedia (6.8)2.0%—Blue-collar Productions I-gallery15/6/200616/6/2026
Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en BlueCollar i-Gallery v4.1 PLUS y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámemtros (1) n y (2) d en (a) login.asp y el parámetro d en (b) igallery.asp.
ModificadaAlta (7.5)1.4%—Coppermine Photo Gallery12/6/200616/6/2026
Unspecified vulnerability in usermgr.php in Coppermine Photo Gallery before 1.4.7 has unknown impact and remote attack vectors, possibly related to authorization/authentication errors.
ModificadaAlta (7.5)1.2%—Particle Soft Particle Gallery6/6/200616/6/2026
SQL injection vulnerability in viewimage.php in Particle Gallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the imageid parameter.
ModificadaAlta (7.5)1.6%—Coppermine Photo Gallery22/5/200616/6/2026
Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
ModificadaAlta (7.5)1.3%—Duware Dugallery11/5/200616/6/2026
SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password field.
ModificadaMedia (5.8)2.1%💥 Exploit321soft Php-gallery5/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this issue might be resultant from the directory traversal vulnerability.
ModificadaMedia (5)3.2%💥 Exploit321soft Php-gallery5/5/200616/6/2026
Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path parameter.
ModificadaAlta (7.5)2.7%💥 Exploit4images Image Gallery Management System5/5/200616/6/2026
Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.
ModificadaMedia (6.4)1.6%—Invision Power Services Invision Gallery4/5/200616/6/2026
SQL injection vulnerability in post.php in Invision Gallery 2.0.6 allows remote attackers to execute arbitrary SQL commands via the album parameter.
ModificadaAlta (7.5)1.7%—JMK WEB Scripts JMK Picture Gallery1/5/200616/6/2026
JMK's Picture Gallery allows remote attackers to bypass authentication via a direct request to admin_gallery.php3, possibly related to the add action.
ModificadaAlta (7.5)2.7%💥 ExploitPlanet Concept Planetgallery1/5/200616/6/2026
planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php.
ModificadaMedia (4.3)1.9%💥 ExploitVerosky Media Instant Photo Gallery27/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.
ModificadaMedia (6.8)1.7%—Verosky Media Instant Photo Gallery27/4/200616/6/2026
SQL injection vulnerability in portfolio_photo_popup.php in Verosky Media Instant Photo Gallery 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, which is not cleansed before calling the count_click function in includes/functions/fns_std.php. NOTE: this issue could produce resultant…
ModificadaMedia (5.8)1.8%💥 ExploitVerosky Media Instant Photo Gallery26/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. NOTE: the original report may be inaccurate, since the "viewpro" string does not appear in the source code for…
ModificadaMedia (5)1.4%—Phpwebgallery26/4/200616/6/2026
PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
ModificadaMedia (5)4.4%💥 ExploitScry Gallery25/4/200616/6/2026
Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order.
ModificadaMedia (4.3)2.3%💥 ExploitScry Gallery25/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this is a different vulnerability than the directory traversal vector.
ModificadaMedia (5)1.6%—Scry Gallery25/4/200616/6/2026
Scry Gallery 1.1 allows remote attackers to obtain sensitive information via an invalid p parameter, which reveals the path in an error message.
ModificadaMedia (4.3)1.3%—Wingnut Easygallery21/4/200616/6/2026
Cross-site scripting (XSS) vulnerability in EasyGallery.php in Wingnut EasyGallery allows remote attackers to inject arbitrary web script or HTML via the ordner parameter.
ModificadaMedia (5)3.7%💥 ExploitCoppermine Photo Gallery20/4/200616/6/2026
Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard "../" sequences.