Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Enhanced Simple PHP Gallery | 7/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Enhanced Simple PHP Gallery 1.7 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. | |
| Modificada | Media (5) | 1.5% | — | Enhanced Simple PHP Gallery | 7/1/2006 | 16/6/2026 | Enhanced Simple PHP Gallery 1.7 allows remote attackers to obtain the full path of the application via a direct request to sp_helper_functions.php, which leaks the pathname in an error message. | |
| Modificada | Media (5) | 1.4% | — | Next Generation Image Gallery | 5/1/2006 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en index.php de Next Generation Image Gallery 0.0.1 Lite Edition permite a atacantes remotos inyectar 'script' web o HTML de su elección mediante el parámetro "page". | |
| Modificada | Media (4.3) | 1.2% | — | Xigla Absolute Image Gallery XE | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Absolute Image Gallery XE 2.x allows remote attackers to inject arbitrary web script or HTML via the text parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Mcgallery PRO | 14/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in mcGallery PRO 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id, (2) start, and (3) rand parameters to show.php, and the (4) album parameter to index.php. | |
| Modificada | Media (4.3) | 3.7% | 💥 Exploit | Snipegallery Snipe Gallery | 14/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in Snipe Gallery 3.1.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the keyword parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Phpwebgallery | 14/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_number parameters to comments.php, (4) the search parameter to category.php, and (5) image_id parameter to picture.php. NOTE: it was later… | |
| Modificada | Media (4.3) | 1.2% | — | Mcgallery PROAI | 14/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified search module parameters. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Snipegallery Snipe Gallery | 14/12/2005 | 16/6/2026 | SQL injection vulnerability in Snipe Gallery 3.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) gallery_id parameter to view.php and (2) image_id parameter to image.php. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Mcgallery PRO | 14/12/2005 | 16/6/2026 | Directory traversal vulnerability in mcGallery PRO 2.2 and earlier allows remote attackers to read arbitrary files via the language parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Powerdev Encapsgallery | 14/12/2005 | 16/6/2026 | SQL injection vulnerability in gallery.php in EncapsGallery 1.0.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.2% | — | GalleryAI | 5/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the "Add Image From Web" feature in Gallery 2.0 before 2.0.2 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. | |
| Modificada | Media (5) | 1.4% | — | Gallery Project Gallery | 5/12/2005 | 16/6/2026 | The installer for Gallery 2.0 before 2.0.2 stores the install log under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information. | |
| Modificada | Media (5) | 1.4% | — | Gallery Project Gallery | 5/12/2005 | 16/6/2026 | Unspecified vulnerability in the zipcart module in Gallery 2.0 before 2.0.2 allows remote attackers to read arbitrary files via unknown vectors. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Verosky Media Instant Photo Gallery | 4/12/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Instant Photo Gallery 1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter in portfolio.php and (2) cid parameter in content.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+7 | 3/12/2005 | 16/6/2026 | SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote… | |
| Modificada | Media (5) | 1.6% | — | Coppermine-gallery Coppermine Photo Gallery | 3/12/2005 | 16/6/2026 | relocate_server.php en Coppermine Photo Gallery (CPG) 1.4.2 y 1.4 beta no se elimina después de la instalación y no usa autenticación, lo que permite a atacantes remotos obtener información sensible, como la configuración de la base de datos, a través de una petición directa. | |
| Modificada | Media (4.3) | 1.2% | — | Invision Power Services Invision Gallery | 3/11/2005 | 16/6/2026 | Multiple interpretation error in the image upload handling code in Invision Gallery 2.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML or script in an image whose type does not match its extension, which is rendered by Internet Explorer due to CVE-2005-3312. NOTE: it could be argued… | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Invision Power Services Invision Gallery | 1/11/2005 | 16/6/2026 | SQL injection vulnerability in Invision Gallery 2.0.3 allows remote attackers to execute arbitrary SQL commands via the st parameter. | |
| Modificada | Media (6.4) | 1.9% | — | Gallery Project Gallery | 17/10/2005 | 16/6/2026 | Directory traversal vulnerability in the gallery script in Gallery 2.0 (G2) allows remote attackers to read or include arbitrary files via ".." sequences in the g2_itemId parameter. | |
| Modificada | Media (4.3) | 1.7% | — | Gallery Project Gallery | 30/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Gallery 1.5.1-RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag. | |
| Modificada | Media (4.3) | 1.2% | — | Coppermine Photo Gallery | 23/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in displayimage.php in Coppermine Photo Gallery before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via EXIF data. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | MY Image Gallery | 17/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the (1) currDir or (2) image parameters. | |
| Modificada | Media (4.6) | 0.38% | — | Gallery Project Gallery | 17/8/2005 | 16/6/2026 | User.php in Gallery, as used in Postnuke, allows users with any Admin privileges to gain access to all galleries. | |
| Modificada | Media (5) | 1.7% | — | MY Image Gallery | 17/8/2005 | 16/6/2026 | index.php for My Image Gallery (Mig ) 1.4.1 allows remote attackers to obtain the web server path via certain currDir and image arguments, which leaks the path in an error message. |