Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2780▲ 24 respecto a la semana anterior
Críticas / altas1288▼ 240 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)242▲ 224 respecto a la semana anterior
1356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Pensacola WEB Designs Xtreme ASP Photo Gallery | 15/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Xtreme ASP Photo Gallery 1.05 and earlier, and possibly 2.0 (trial), allow remote attackers to inject arbitrary web script or HTML via the (1) catname and (2) total parameters in (a) displaypic.asp, and the (3) catname parameter in (b) displaythumbs.asp. | |
| Modificada | Media (4.3) | 1.8% | — | Uapplication Uphotogallery | 15/6/2006 | 16/6/2026 | Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en thumbnails.asp en Uphotogallery Uapplication v1.1 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro (1) s y (2) block. | |
| Modificada | Media (4.3) | 1.8% | — | Clicktech Clickgallery | 15/6/2006 | 16/6/2026 | Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en ClickGallery v5.0 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de (1) el parámetro gallery_id en gallery.asp y (2) el parámetro parentcurrentpage en view_gallery.asp. | |
| Modificada | Media (5.8) | 4.3% | 💥 Exploit | Andy Mack 35mmslidegallery | 15/6/2006 | 16/6/2026 | Múltiples vulnerabilidades cross-site scripting (XSS) en 35mmslidegallery 6.0 permite a atacantes remotos inyectar script web o HTML de forma arbitraria a través (1) del parámetro imgdir en (a) index.php, y los parámetros (2) w, (3) h y (4) t en (b) popup.php. | |
| Modificada | Media (6.8) | 2.0% | — | Fipsasp Fipsgallery | 15/6/2006 | 16/6/2026 | Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en zoom.php en fipsGallery v1.5 y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro path. | |
| Modificada | Media (6.8) | 2.0% | — | Blue-collar Productions I-gallery | 15/6/2006 | 16/6/2026 | Múltiples vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en BlueCollar i-Gallery v4.1 PLUS y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámemtros (1) n y (2) d en (a) login.asp y el parámetro d en (b) igallery.asp. | |
| Modificada | Alta (7.5) | 1.4% | — | Coppermine Photo Gallery | 12/6/2006 | 16/6/2026 | Unspecified vulnerability in usermgr.php in Coppermine Photo Gallery before 1.4.7 has unknown impact and remote attack vectors, possibly related to authorization/authentication errors. | |
| Modificada | Alta (7.5) | 1.2% | — | Particle Soft Particle Gallery | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in viewimage.php in Particle Gallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the imageid parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Coppermine Photo Gallery | 22/5/2006 | 16/6/2026 | Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions. | |
| Modificada | Alta (7.5) | 1.3% | — | Duware Dugallery | 11/5/2006 | 16/6/2026 | SQL injection vulnerability in admin_default.asp in DUGallery 2.x allows remote attackers to execute arbitrary SQL commands via the (1) Login or (2) password field. | |
| Modificada | Media (5.8) | 2.1% | 💥 Exploit | 321soft Php-gallery | 5/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this issue might be resultant from the directory traversal vulnerability. | |
| Modificada | Media (5) | 3.2% | 💥 Exploit | 321soft Php-gallery | 5/5/2006 | 16/6/2026 | Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path parameter. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | 4images Image Gallery Management System | 5/5/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2. | |
| Modificada | Media (6.4) | 1.6% | — | Invision Power Services Invision Gallery | 4/5/2006 | 16/6/2026 | SQL injection vulnerability in post.php in Invision Gallery 2.0.6 allows remote attackers to execute arbitrary SQL commands via the album parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | JMK WEB Scripts JMK Picture Gallery | 1/5/2006 | 16/6/2026 | JMK's Picture Gallery allows remote attackers to bypass authentication via a direct request to admin_gallery.php3, possibly related to the add action. | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Planet Concept Planetgallery | 1/5/2006 | 16/6/2026 | planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Verosky Media Instant Photo Gallery | 27/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. | |
| Modificada | Media (6.8) | 1.7% | — | Verosky Media Instant Photo Gallery | 27/4/2006 | 16/6/2026 | SQL injection vulnerability in portfolio_photo_popup.php in Verosky Media Instant Photo Gallery 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter, which is not cleansed before calling the count_click function in includes/functions/fns_std.php. NOTE: this issue could produce resultant… | |
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | Verosky Media Instant Photo Gallery | 26/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. NOTE: the original report may be inaccurate, since the "viewpro" string does not appear in the source code for… | |
| Modificada | Media (5) | 1.4% | — | Phpwebgallery | 26/4/2006 | 16/6/2026 | PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Media (5) | 4.4% | 💥 Exploit | Scry Gallery | 25/4/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Scry Gallery | 25/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this is a different vulnerability than the directory traversal vector. | |
| Modificada | Media (5) | 1.6% | — | Scry Gallery | 25/4/2006 | 16/6/2026 | Scry Gallery 1.1 allows remote attackers to obtain sensitive information via an invalid p parameter, which reveals the path in an error message. | |
| Modificada | Media (4.3) | 1.3% | — | Wingnut Easygallery | 21/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in EasyGallery.php in Wingnut EasyGallery allows remote attackers to inject arbitrary web script or HTML via the ordner parameter. | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | Coppermine Photo Gallery | 20/4/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard "../" sequences. |