Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.4% | — | Moosegallery | 20/7/2005 | 16/6/2026 | Vulnerabilidad de inclusión de fichero PHP remoto en display.php en MooseGallery permite que atacantes remotos ejecuten código PHP arbitrario mediante el parámetro "type". | |
| Modificada | Alta (7.5) | 3.2% | — | Squitosoft Squito Gallery | 13/7/2005 | 16/6/2026 | Vulnerabilidad de inclusión de fichero PHP remoto en photolist.inc.php en Squito Gallery 1.33 permite que atacantes remotos ejecuten código arbitrario mediante el parámetro "photoroot". | |
| Modificada | Alta (7.5) | 2.6% | — | Photogal Photo Gallery | 12/7/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Skrypty PPA Gallery | 11/7/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable. | |
| Modificada | Media (4.3) | 0.94% | — | Blue-collar Productions I-gallery | 20/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary web script or HTML via the folder parameter. | |
| Modificada | Media (5) | 7.5% | 💥 Exploit | Blue-collar Productions I-gallery | 20/6/2005 | 16/6/2026 | Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Mcgallery | 15/6/2005 | 16/6/2026 | Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. | |
| Modificada | Media (5) | 1.4% | — | Mcgallery | 15/6/2005 | 16/6/2026 | show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter. | |
| Modificada | Media (4.3) | 0.46% | — | Invisioncommunity Gallery | 9/6/2005 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Invision Power Services Invision Gallery | 9/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo. | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | Keyvan1 Imagegallery | 18/5/2005 | 16/6/2026 | Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.5% | — | Uapplication UphotogalleryAI | 3/5/2005 | 16/6/2026 | edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files. | |
| Modificada | Alta (7.5) | 1.7% | — | Uapplication Uphotogallery | 3/5/2005 | 16/6/2026 | Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to uphotogallery.mdb. | |
| Modificada | Media (5) | 1.4% | — | Gallery Project Gallery | 2/5/2005 | 16/6/2026 | main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message. | |
| Modificada | Media (4.3) | 1.2% | — | Coppermine Photo Gallery | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Zoom Media GalleryAI | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Coppermine Photo Gallery | 2/5/2005 | 16/6/2026 | Coppermine Photo Gallery 1.3.2 stores passwords in plaintext, which allows remote attackers to obtain sensitive information. | |
| Modificada | Media (5) | 1.6% | — | Gallery Project Gallery | 2/5/2005 | 16/6/2026 | Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field. | |
| Modificada | Media (4.3) | 1.4% | — | Gallery Project Gallery | 2/5/2005 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7) slide_dir fields in slideshow_low.php, or (8)… | |
| Modificada | Alta (7.5) | 1.2% | — | Coppermine Photo Gallery | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in Coppermine Photo Gallery 1.3.2 allows remote attackers to execute arbitrary SQL commands via the favs parameter to (1) init.inc.php or (2) zipdownload.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Sergey Kiselev Sgallery | 2/5/2005 | 16/6/2026 | SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters. | |
| Modificada | Media (5) | 1.6% | — | Sergey Kiselev Sgallery | 2/5/2005 | 16/6/2026 | imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function. | |
| Modificada | Alta (7.5) | 2.3% | — | Twiki Imagegalleryplugin | 23/2/2005 | 16/6/2026 | The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails. | |
| Modificada | Media (4.3) | 1.4% | — | Gallery Project Gallery | 17/1/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field. | |
| Modificada | Alta (7.5) | 2.0% | — | Sergey Kiselev Sgallery | 12/1/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php. |