Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▲ 75 respecto a la semana anterior
Críticas / altas1288▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1356 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.4%—Moosegallery20/7/200516/6/2026
Vulnerabilidad de inclusión de fichero PHP remoto en display.php en MooseGallery permite que atacantes remotos ejecuten código PHP arbitrario mediante el parámetro "type".
ModificadaAlta (7.5)3.2%—Squitosoft Squito Gallery13/7/200516/6/2026
Vulnerabilidad de inclusión de fichero PHP remoto en photolist.inc.php en Squito Gallery 1.33 permite que atacantes remotos ejecuten código arbitrario mediante el parámetro "photoroot".
ModificadaAlta (7.5)2.6%—Photogal Photo Gallery12/7/200516/6/2026
PHP remote file inclusion vulnerability in gals.php in PhotoGal Photo Gallery 1.5 and earlier allows remote attackers to execute arbitrary code via the news_file parameter.
ModificadaAlta (7.5)10%💥 ExploitSkrypty PPA Gallery11/7/200516/6/2026
PHP remote file inclusion vulnerability in inc/functions.inc.php in PPA web photo gallery 0.5.6 allows remote attackers to execute arbitrary code via the config[ppa_root_path] variable.
ModificadaMedia (4.3)0.94%—Blue-collar Productions I-gallery20/6/200516/6/2026
Cross-site scripting (XSS) vulnerability in folderview.asp for BlueCollar iGallery 3.3 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.
ModificadaMedia (5)7.5%💥 ExploitBlue-collar Productions I-gallery20/6/200516/6/2026
Directory traversal vulnerability in folderview.asp for Blue-Collar Productions i-Gallery 3.3 allows remote attackers to read arbitrary files and directories via the folder parameter.
ModificadaMedia (5)3.1%💥 ExploitMcgallery15/6/200516/6/2026
Directory traversal vulnerability in admin.php in McGallery 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.
ModificadaMedia (5)1.4%—Mcgallery15/6/200516/6/2026
show.php in McGallery 1.1 allows remote attackers to connect to arbitrary databases, or gain sensitive information by triggering an error, via a modified host parameter.
ModificadaMedia (4.3)0.46%—Invisioncommunity Gallery9/6/200516/6/2026
Cross-site request forgery (CSRF) vulnerability in Invision Gallery before 1.3.1 allows remote attackers to delete albums and images as another user via a link or IMG tag to the (1) albums or (2) delimg actions.
ModificadaAlta (7.5)1.2%💥 ExploitInvision Power Services Invision Gallery9/6/200516/6/2026
Multiple SQL injection vulnerabilities in Invision Gallery before 1.3.1 allow remote attackers to execute arbitrary SQL commands via (1) the comment parameter in an editcomment action or (2) the rating parameter when voting on a photo.
ModificadaMedia (5)2.9%💥 ExploitKeyvan1 Imagegallery18/5/200516/6/2026
Keyvan1 ImageGallery stores the image.mdb database under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information.
ModificadaAlta (7.5)1.5%—Uapplication UphotogalleryAI3/5/200516/6/2026
edit_image.asp in Uapplication Uphotogallery allows remote attackers to upload arbitrary files.
ModificadaAlta (7.5)1.7%—Uapplication Uphotogallery3/5/200516/6/2026
Uapplication Uphotogallery stores the database under the web document root, which allows remote attackers to obtain sensitive information via a direct request to uphotogallery.mdb.
ModificadaMedia (5)1.4%—Gallery Project Gallery2/5/200516/6/2026
main.php in Gallery 2.0 Alpha allows remote attackers to gain sensitive information by changing the value of g2_subView parameter, which reveals the path in an error message.
ModificadaMedia (4.3)1.2%—Coppermine Photo Gallery2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.
ModificadaAlta (7.5)1.2%💥 ExploitZoom Media GalleryAI2/5/200516/6/2026
SQL injection vulnerability in index.php for zOOm Media Gallery 2.1.2 allows remote attackers to execute arbitrary SQL commands via the catid parameter.
ModificadaAlta (7.5)1.7%—Coppermine Photo Gallery2/5/200516/6/2026
Coppermine Photo Gallery 1.3.2 stores passwords in plaintext, which allows remote attackers to obtain sensitive information.
ModificadaMedia (5)1.6%—Gallery Project Gallery2/5/200516/6/2026
Cross-site scripting vulnerability in login.php in Gallery 1.4.4-pl2 allows remote attackers to inject arbitrary web script or HTML via the username field.
ModificadaMedia (4.3)1.4%—Gallery Project Gallery2/5/200516/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 1.3.4-pl1 allow remote attackers to inject arbitrary web script or HTML via (1) the index field in add_comment.php, (2) set_albumName, (3) slide_index, (4) slide_full, (5) slide_loop, (6) slide_pause, (7) slide_dir fields in slideshow_low.php, or (8)…
ModificadaAlta (7.5)1.2%—Coppermine Photo Gallery2/5/200516/6/2026
SQL injection vulnerability in Coppermine Photo Gallery 1.3.2 allows remote attackers to execute arbitrary SQL commands via the favs parameter to (1) init.inc.php or (2) zipdownload.php.
ModificadaAlta (7.5)1.5%—Sergey Kiselev Sgallery2/5/200516/6/2026
SQL injection vulnerability in imageview.php for SGallery 1.01 allows remote attackers to execute arbitrary SQL commands via the (1) idalbum or (2) idimage parameters.
ModificadaMedia (5)1.6%—Sergey Kiselev Sgallery2/5/200516/6/2026
imageview.php in SGallery 1.01 allows remote attackers to obtain sensitive information via an HTTP request with (1) idalbum and (2) idimage unset, which reveals the installation path in an error message for the sql_fetch_row function.
ModificadaAlta (7.5)2.3%—Twiki Imagegalleryplugin23/2/200516/6/2026
The ImageGalleryPlugin (ImageGalleryPlugin.pm) in Twiki allows remote attackers to execute arbitrary commands via certain commands that generate thumbnails.
ModificadaMedia (4.3)1.4%—Gallery Project Gallery17/1/200516/6/2026
Cross-site scripting (XSS) vulnerability in login.php in Gallery 2.0 Alpha allows remote attackers to inject arbitrary web script or HTML via the g2_form[subject] field.
ModificadaAlta (7.5)2.0%—Sergey Kiselev Sgallery12/1/200516/6/2026
PHP remote file inclusion vulnerability in SGallery 1.01 allows local and possibly remote attackers to execute arbitrary PHP code by modifying the DOCUMENT_ROOT parameter to reference a URL on a remote web server that contains (1) config.php or (2) sql_layer.php.