Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1356 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)1.5%—Gallery Project GalleryGentoo Linux10/1/200516/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Gallery 1.4.4-pl3 y anteriores permite a atacantes remotos ejecutar script web o HTML de su elección mediante "URL s especialmente malformadas", posiblemente mediante un parámetro include en index.php
ModificadaMedia (5)1.8%—FsphpgalleryAI31/12/200416/6/2026
Directory traversal vulnerability in index.php in FsPHPGallery before 1.2 allows remote attackers to list arbitrary directories via the dir parameter.
ModificadaAlta (7.5)3.0%💥 ExploitPensacola WEB Designs Xtremeasp Photogallery31/12/200416/6/2026
SQL injection vulnerability in adminlogin.asp in XTREME ASP Photo Gallery 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaMedia (5)1.6%—Fsphpgallery31/12/200416/6/2026
FsPHPGallery before 1.2 allows remote attackers to cause a denial of service via an image with a large size attribute, which causes a crash when the server attempts to resize the image.
ModificadaMedia (5)1.0%—Singapore Image Gallery WEB Application31/12/200416/6/2026
Multiple cross-site scripting vulnerabilities in Image Gallery Web Application 0.9.10 allow remote attackers to inject arbitrary web script or HTML.
ModificadaMedia (5)7.4%💥 ExploitGallery Project Gallery31/12/200416/6/2026
The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POST_VARS variable and conduct a PHP remote file inclusion attack via the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412.
ModificadaAlta (7.5)1.5%—Singapore Image Gallery WEB ApplicationAI31/12/200416/6/2026
The addImage method for admin.class.php in Image Gallery Web Application 0.9.10 does not properly check filenames, which allows remote attackers to upload and execute arbitrary files.
ModificadaAlta (7.5)4.9%💥 ExploitInvision Power Services Invision Gallery31/12/200416/6/2026
Multiple SQL injection vulnerabilities in index.php in Invision Gallery 1.0.1 allow remote attackers to execute arbitrary SQL via the (1) img, (2) cat, (3) sort_key, (4) order_key, (5) user, or (6) album parameters.
ModificadaAlta (7.5)5.2%💥 ExploitGallery Project Gallery31/12/200416/6/2026
The set_time_limit function in Gallery before 1.4.4_p2 deletes non-image files in a temporary directory every 30 seconds after they have been uploaded using save_photos.php, which allows remote attackers to upload and execute execute arbitrary scripts before they are deleted, if the temporary directory is under the…
ModificadaMedia (5)1.6%—Singapore Image Gallery WEB Application31/12/200416/6/2026
Multiple directory traversal vulnerabilities in singapore Image Gallery Web Application 0.9.10 allow remote attackers to (1) read arbitrary files via the showThumb method for thumb.php, or (2) delete arbitrary files via admin.class.php.
ModificadaAlta (10)2.8%—Gallery Project GalleryDebian Linux6/8/200416/6/2026
Gallery 1.4.3 y anteriores permite a atacantes remotos saltarse la autenticación y obtener privilegios de administrador de Gallery.
ModificadaMedia (5)2.6%—Coppermine Photo GalleryFrancisco Burzi Php-nuke2/5/200416/6/2026
Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers to obtain sensitive information via a direct HTTP request to (1) phpinfo.php, (2) addpic.php, (3) config.php, (4) db_input.php, (5) displayecard.php, (6) ecard.php, (7) crop.inc.php, which reveal the full path in a PHP error message.
ModificadaAlta (7.5)9.3%💥 ExploitCoppermine Photo GalleryFrancisco Burzi Php-nuke30/4/200416/6/2026
PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to reference a URL on a remote web server that contains functions.inc.php.
ModificadaAlta (7.5)9.3%💥 ExploitCoppermine Photo GalleryFrancisco Burzi Php-nuke30/4/200416/6/2026
PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter to reference a URL on a remote web server that contains user_list_info_box.inc.
ModificadaAlta (7.5)10%—Coppermine Photo GalleryFrancisco Burzi Php-nuke30/4/200416/6/2026
picmgmtbatch.inc.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to execute arbitrary commands via shell metacharacters in the (1) $CONFIG['impath'] or (2) $CONFIG['jpeg_qual'] parameters.
ModificadaMedia (4.3)3.9%💥 ExploitCoppermine Photo GalleryFrancisco Burzi Php-nuke30/4/200416/6/2026
Cross-site scripting (XSS) vulnerability in menu.inc.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to inject arbitrary HTML or web script via the CPG_URL parameter.
ModificadaMedia (5)1.2%—Phpnuke Video Gallery ModuleAI26/4/200416/6/2026
modules.php in PHP-Nuke Video Gallery Module 0.1 Beta 5 allows remote attackers to gain sensitive information via an HTTP request with an invalid (1) catid or (2) clipid parameter, which reveals the full path in an error message.
ModificadaMedia (5)11%💥 ExploitCoppermine Photo GalleryFrancisco Burzi Php-nuke4/4/200416/6/2026
Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.
ModificadaMedia (4.8)0.51%—Bharat Mediratta Gallery31/12/200316/6/2026
Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos.
ModificadaAlta (10)1.4%—MY Photo Gallery31/12/200316/6/2026
Unspecified vulnerability in My Photo Gallery 3.5, and possibly earlier versions, has unknown impact and attack vectors.
ModificadaAlta (7.5)6.7%💥 ExploitGallery Project Gallery31/12/200316/6/2026
PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configuration mode on Unix, allows remote attackers to inject arbitrary PHP code via a URL in the GALLERY_BASEDIR parameter, a different vulnerability than CVE-2002-1412. NOTE: this issue might be exploitable…
ModificadaMedia (4.6)0.43%—Apache Gallery22/9/200316/6/2026
Gallery.pm en Apache::Gallery (también llamado A::G) usa nombres de ficheros temporales predecibles cuando ejecuta Inline::C, lo que permite a usuarios locales ejecutar código arbitrario creando y modificando los ficheros antes de que Apache::Gallery lo haga.
ModificadaMedia (4.3)3.9%💥 ExploitGallery Project Gallery27/8/200316/6/2026
Vulnerabilidad en sitios cruzados en search.php de Gallery 1.1 a 1.3.4 permite a atacantes remotos insertar script web mediante el parámetro searchstring
ModificadaAlta (7.5)39%💥 ExploitGallery Project Gallery11/4/200316/6/2026
El paquete album de fotos Gallery anterior a 1.3.1permite a atacantes locales y posiblemente remotos ejecutar código arbitrario mediante una variable GALLERY_BASEDIR que apunta a un directorio o una URL que contiene un script php.ini que sea caballo de Troya.
ModificadaMedia (5)4.3%—Duma Photo Gallery System11/4/200316/6/2026
Vulnerabilidad de cruce de directorio en update.dgps en Duma Photo Gallery System (DPGS) 0.99.4 permite que atacantes remotos lean cualquier fichero por medio de secuencias .. (punto punto) en el parámetro id.