Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 9 respecto a la semana anterior
Críticas / altas1289▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
1356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.6) | 0.90% | — | Animegenesis Gallery | 20/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in AnimeGenesis Gallery allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Tinywebgallery | 18/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Snipegallery Snipe Gallery | 18/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Snipe Gallery 3.1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) gallery_id parameter in view.php, (2) keyword parameter in search.php, and (3) image_id parameter in image.php. NOTE: it is possible that vectors 1 and 3 are… | |
| Modificada | Baja (2.6) | 1.3% | — | JMB Software Autogallery | 12/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Autogallery 0.41 allow remote attackers to inject arbitrary web script or HTML via the (1) pic or (2) show parameters. | |
| Modificada | Media (4.3) | 1.3% | — | Gallery Project Gallery | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Gallery before 1.5.3 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |
| Modificada | Baja (2.6) | 0.91% | — | Phpwebgallery | 10/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in PHPWebGallery 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, a different vulnerability than CVE-2006-1675. | |
| Modificada | Baja (2.6) | 1.9% | 💥 Exploit | Phpwebgallery | 10/4/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PHPWebGallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) num, and (3) search parameters to (a) category.php, and the (4) slideshow, (5) show_metadata, and (6) start parameters to (b) picture.php, a different… | |
| Analizada | Media (6.8) | 1.1% | — | Softbizscripts Image Gallery Script | 7/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in image_desc.php in Softbiz Image Gallery allows remote attackers to inject arbitrary web script or HTML via msg parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Crafty Syntax Image Gallery | 7/4/2006 | 16/6/2026 | SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to execute arbitrary SQL commands via the limitquery_s parameter when the $projectid variable is less than 1, which prevents the $limitquery_s… | |
| Analizada | Media (6.4) | 2.2% | 💥 Exploit | Softbizscripts Image Gallery Script | 7/4/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Softbiz Image Gallery allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in image_desc.php, (2) provided parameter in template.php, (3) cid parameter in suggest_image.php, (4) img_id parameter in insert_rating.php, and (5) cid parameter in… | |
| Modificada | Alta (9) | 4.2% | 💥 Exploit | Crafty Syntax Image Gallery | 7/4/2006 | 16/6/2026 | newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows remote authenticated users to upload and execute arbitrary PHP code via a multipart/form-data POST with a .jpg filename in the fullimage parameter and the ext parameter set to .php. | |
| Modificada | Alta (7.5) | 1.1% | — | Phpwebgallery | 3/4/2006 | 16/6/2026 | SQL injection vulnerability in category.php in PhpWebGallery 1.4.1 allows remote attackers to execute arbitrary SQL commands via the search parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Mediaslash.com Mediaslash Gallery | 1/4/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable). | |
| Modificada | Media (4.3) | 1.2% | — | Xigla Absolute Image Gallery XE | 28/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) the shownew parameter in gallery.asp and (2) unspecified search module parameters. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | TFT Gallery | 28/3/2006 | 16/6/2026 | TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the admin password file and obtain password hashes via a direct request to admin/passwd. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Gallery Project Gallery | 14/3/2006 | 16/6/2026 | Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".." (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2) install/index.php. | |
| Modificada | Media (6.4) | 1.6% | — | Gallery Project Gallery | 9/3/2006 | 16/6/2026 | Gallery 2 up to 2.0.2 allows remote attackers to spoof their IP address via a modified X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is checked by Gallery before other more reliable sources of IP address information, such as REMOTE_ADDR. | |
| Modificada | Media (6.4) | 4.0% | 💥 Exploit | Gallery Project Gallery | 9/3/2006 | 16/6/2026 | Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Gallery Project Gallery | 9/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is not properly handled when adding a comment to an album. | |
| Modificada | Baja (2.6) | 2.1% | 💥 Exploit | Jgs-xa Jgs-gallery AddonWoltlab Burning Board | 28/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid… | |
| Modificada | Alta (7.5) | 10.0% | 💥 Exploit | 4images Image Gallery Management System | 27/2/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter. | |
| Modificada | Media (5) | 1.7% | — | Coppermine Photo Gallery | 24/2/2006 | 16/6/2026 | Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames. | |
| Modificada | Media (5) | 2.4% | — | Coppermine Photo Gallery | 24/2/2006 | 16/6/2026 | Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang parameter. | |
| Modificada | Media (6.5) | 2.7% | — | Gallery Project Gallery | 8/2/2006 | 16/6/2026 | Vulnerabilidad no especificada en util.php de Gallery anteriores a 1.5.2-pl12 permite a usuarios remotos autenticados engañar a un propietario para modificar datos de álbumes almacenados y posiblemente ejecutar código de su elección mediante vectores no especificados que conllevan un enlace artesanal a un fichero… | |
| Modificada | Media (4.3) | 1.8% | — | Gallery Project Gallery | 21/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the user name (fullname). |