Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 1.5% | — | Gallery Project GalleryGentoo Linux | 10/1/2005 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Gallery 1.4.4-pl3 y anteriores permite a atacantes remotos ejecutar script web o HTML de su elección mediante "URL s especialmente malformadas", posiblemente mediante un parámetro include en index.php | |
| Modificada | Media (5) | 1.8% | — | FsphpgalleryAI | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in index.php in FsPHPGallery before 1.2 allows remote attackers to list arbitrary directories via the dir parameter. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Pensacola WEB Designs Xtremeasp Photogallery | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Media (5) | 1.6% | — | Fsphpgallery | 31/12/2004 | 16/6/2026 | FsPHPGallery before 1.2 allows remote attackers to cause a denial of service via an image with a large size attribute, which causes a crash when the server attempts to resize the image. | |
| Modificada | Media (5) | 1.0% | — | Singapore Image Gallery WEB Application | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting vulnerabilities in Image Gallery Web Application 0.9.10 allow remote attackers to inject arbitrary web script or HTML. | |
| Modificada | Media (5) | 7.4% | 💥 Exploit | Gallery Project Gallery | 31/12/2004 | 16/6/2026 | The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. | |
| Modificada | Alta (7.5) | 1.5% | — | Singapore Image Gallery WEB ApplicationAI | 31/12/2004 | 16/6/2026 | The addImage method for admin.class.php in Image Gallery Web Application 0.9.10 does not properly check filenames, which allows remote attackers to upload and execute arbitrary files. | |
| Modificada | Alta (7.5) | 4.9% | 💥 Exploit | Invision Power Services Invision Gallery | 31/12/2004 | 16/6/2026 | Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters. | |
| Modificada | Alta (7.5) | 5.2% | 💥 Exploit | Gallery Project Gallery | 31/12/2004 | 16/6/2026 | The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded using save_photos.php, which allows remote attackers to upload and execute execute arbitrary scripts before they are deleted, if the temporary directory is under the… | |
| Modificada | Media (5) | 1.6% | — | Singapore Image Gallery WEB Application | 31/12/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities in singapore Image Gallery Web Application 0.9.10 allow remote attackers to (1) read arbitrary files via the showThumb method for thumb.php, or (2) delete arbitrary files via admin.class.php. | |
| Modificada | Alta (10) | 2.8% | — | Gallery Project GalleryDebian Linux | 6/8/2004 | 16/6/2026 | Gallery 1.4.3 y anteriores permite a atacantes remotos saltarse la autenticación y obtener privilegios de administrador de Gallery. | |
| Modificada | Media (5) | 2.6% | — | Coppermine Photo GalleryFrancisco Burzi Php-nuke | 2/5/2004 | 16/6/2026 | Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message. | |
| Modificada | Alta (7.5) | 9.3% | 💥 Exploit | Coppermine Photo GalleryFrancisco Burzi Php-nuke | 30/4/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php. | |
| Modificada | Alta (7.5) | 9.3% | 💥 Exploit | Coppermine Photo GalleryFrancisco Burzi Php-nuke | 30/4/2004 | 16/6/2026 | PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc. | |
| Modificada | Alta (7.5) | 10% | — | Coppermine Photo GalleryFrancisco Burzi Php-nuke | 30/4/2004 | 16/6/2026 | picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Coppermine Photo GalleryFrancisco Burzi Php-nuke | 30/4/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter. | |
| Modificada | Media (5) | 1.2% | — | Phpnuke Video Gallery ModuleAI | 26/4/2004 | 16/6/2026 | modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to gain sensitive information via an HTTP request with an invalid (1) catid or (2) clipid parameter, which reveals the full path in an error message. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Coppermine Photo GalleryFrancisco Burzi Php-nuke | 4/4/2004 | 16/6/2026 | Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter. | |
| Modificada | Media (4.8) | 0.51% | — | Bharat Mediratta Gallery | 31/12/2003 | 16/6/2026 | Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos. | |
| Modificada | Alta (10) | 1.4% | — | MY Photo Gallery | 31/12/2003 | 16/6/2026 | Unspecified vulnerability in My Photo Gallery 3.5, and possibly earlier versions, has unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | Gallery Project Gallery | 31/12/2003 | 16/6/2026 | PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. NOTE: this issue might be exploitable… | |
| Modificada | Media (4.6) | 0.43% | — | Apache Gallery | 22/9/2003 | 16/6/2026 | Gallery.pm en Apache::Gallery (también llamado A::G) usa nombres de ficheros temporales predecibles cuando ejecuta Inline::C, lo que permite a usuarios locales ejecutar código arbitrario creando y modificando los ficheros antes de que Apache::Gallery lo haga. | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Gallery Project Gallery | 27/8/2003 | 16/6/2026 | Vulnerabilidad en sitios cruzados en search.php de Gallery 1.1 a 1.3.4 permite a atacantes remotos insertar script web mediante el parámetro searchstring | |
| Modificada | Alta (7.5) | 39% | 💥 Exploit | Gallery Project Gallery | 11/4/2003 | 16/6/2026 | El paquete album de fotos Gallery anterior a 1.3.1permite a atacantes locales y posiblemente remotos ejecutar código arbitrario mediante una variable GALLERY_BASEDIR que apunta a un directorio o una URL que contiene un script php.ini que sea caballo de Troya. | |
| Modificada | Media (5) | 4.3% | — | Duma Photo Gallery System | 11/4/2003 | 16/6/2026 | Vulnerabilidad de cruce de directorio en update.dgps en Duma Photo Gallery System (DPGS) 0.99.4 permite que atacantes remotos lean cualquier fichero por medio de secuencias .. (punto punto) en el parámetro id. |