Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
220 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 8.7% | 💥 Exploit | Coppermine-gallery Coppermine Photo Gallery | 4/9/2012 | 16/6/2026 | Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid (5) newer_than or (6) older_than… | |
| Modificada | Baja (3.5) | 2.2% | 💥 Exploit | Coppermine-gallery Coppermine Photo Gallery | 4/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote authenticated users with certain privileges to inject arbitrary web script or HTML via the keywords parameter. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Phpgalleryscript PHP Free Photo Gallery | 9/10/2011 | 16/6/2026 | PHP remote file inclusion vulnerability in libs/adodb/adodb.inc.php in PHP Free Photo Gallery script allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | |
| Modificada | Media (5) | 1.3% | — | Coppermine-gallery Coppermine Photo Gallery | 23/9/2011 | 16/6/2026 | Coppermine Photo Gallery (CPG) 1.5.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/inspekt.php and certain other files. | |
| Modificada | Media (4.3) | 1.1% | — | Coppermine-gallery Coppermine Photo Gallery | 14/6/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-4667. | |
| Modificada | Media (4.3) | 1.1% | — | Coppermine-gallery Coppermine Photo Gallery | 14/6/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.4.27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Gallarific PHP Photo Gallery Script | 20/1/2011 | 16/6/2026 | SQL injection vulnerability in gallery.php in Gallarific PHP Photo Gallery script 2.1 and possibly other versions allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | Coppermine-gallery Coppermine Photo Gallery | 11/1/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters to help.php, or (3) picfile_XXX parameter to searchnew.php. | |
| Modificada | Media (5) | 1.3% | — | Coppermine-gallery Coppermine Photo Gallery | 9/9/2009 | 16/6/2026 | Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, which leaks the installation path in an error message. | |
| Modificada | Media (5) | 1.3% | — | Coppermine-gallery Coppermine Photo Gallery | 9/9/2009 | 16/6/2026 | Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as the database table prefix via a direct request. NOTE: this might be leveraged for attacks against CVE-2008-0504. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Coppermine Photo Gallery | 11/5/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via the css parameter, a different vector than CVE-2008-0505. | |
| Modificada | Media (5.1) | 2.0% | 💥 Exploit | Minddezign Photo Gallery | 4/5/2009 | 16/6/2026 | The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username parameter in an edit account action to index.php. | |
| Modificada | Media (5.1) | 0.93% | 💥 Exploit | Minddezign Photo Gallery | 4/5/2009 | 16/6/2026 | SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a different vector than CVE-2008-6788. | |
| Modificada | Media (5.1) | 0.92% | 💥 Exploit | Minddezign Photo Gallery | 4/5/2009 | 16/6/2026 | SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Developiteasy Photo Gallery | 2/3/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id parameter to gallery_photo.php, and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Ontarioabandonedplaces A Better Member-based ASP Photo Gallery | 11/2/2009 | 16/6/2026 | SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Activewebsoftwares Active Photo Gallery | 17/12/2008 | 16/6/2026 | SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Coppermine-gallery Coppermine Photo Gallery | 6/8/2008 | 16/6/2026 | Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Coppermine-gallery Coppermine Photo Gallery | 5/8/2008 | 16/6/2026 | themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Terong Advanced WEB Photo Gallery | 17/4/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 allows remote attackers to execute arbitrary SQL commands via the photo_id parameter. | |
| Modificada | Media (6.5) | 1.8% | — | Coppermine Photo Gallery | 16/4/2008 | 16/6/2026 | SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload. | |
| Modificada | Media (6.8) | 1.9% | — | Coppermine Photo Gallery | 16/4/2008 | 16/6/2026 | SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input field associated with the session_id variable, as exploited in the wild in April 2008. NOTE: the fix… | |
| Modificada | Media (5) | 2.4% | 💥 Exploit | Terong Advanced WEB Photo Gallery | 9/4/2008 | 16/6/2026 | Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | PHP WEB Scripts Dynamic Photo Gallery | 5/3/2008 | 16/6/2026 | SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Coppermine Photo Gallery | 31/1/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters. |