Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

220 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)8.7%💥 ExploitCoppermine-gallery Coppermine Photo Gallery4/9/201216/6/2026
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid (5) newer_than or (6) older_than…
ModificadaBaja (3.5)2.2%💥 ExploitCoppermine-gallery Coppermine Photo Gallery4/9/201216/6/2026
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote authenticated users with certain privileges to inject arbitrary web script or HTML via the keywords parameter.
ModificadaAlta (7.5)2.0%💥 ExploitPhpgalleryscript PHP Free Photo Gallery9/10/201116/6/2026
PHP remote file inclusion vulnerability in libs/adodb/adodb.inc.php in PHP Free Photo Gallery script allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.
ModificadaMedia (5)1.3%—Coppermine-gallery Coppermine Photo Gallery23/9/201116/6/2026
Coppermine Photo Gallery (CPG) 1.5.12 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/inspekt.php and certain other files.
ModificadaMedia (4.3)1.1%—Coppermine-gallery Coppermine Photo Gallery14/6/201116/6/2026
Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-4667.
ModificadaMedia (4.3)1.1%—Coppermine-gallery Coppermine Photo Gallery14/6/201116/6/2026
Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.4.27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)0.91%💥 ExploitGallarific PHP Photo Gallery Script20/1/201116/6/2026
SQL injection vulnerability in gallery.php in Gallarific PHP Photo Gallery script 2.1 and possibly other versions allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.8%💥 ExploitCoppermine-gallery Coppermine Photo Gallery11/1/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters to help.php, or (3) picfile_XXX parameter to searchnew.php.
ModificadaMedia (5)1.3%—Coppermine-gallery Coppermine Photo Gallery9/9/200916/6/2026
Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, which leaks the installation path in an error message.
ModificadaMedia (5)1.3%—Coppermine-gallery Coppermine Photo Gallery9/9/200916/6/2026
Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as the database table prefix via a direct request. NOTE: this might be leveraged for attacks against CVE-2008-0504.
ModificadaMedia (4.3)1.7%💥 ExploitCoppermine Photo Gallery11/5/200916/6/2026
Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via the css parameter, a different vector than CVE-2008-0505.
ModificadaMedia (5.1)2.0%💥 ExploitMinddezign Photo Gallery4/5/200916/6/2026
The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges via a modified username parameter in an edit account action to index.php.
ModificadaMedia (5.1)0.93%💥 ExploitMinddezign Photo Gallery4/5/200916/6/2026
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands via the username parameter in a login action to the admin module in index.php, a different vector than CVE-2008-6788.
ModificadaMedia (5.1)0.92%💥 ExploitMinddezign Photo Gallery4/5/200916/6/2026
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter in an info action to index.php.
ModificadaAlta (7.5)0.97%💥 ExploitDevelopiteasy Photo Gallery2/3/200916/6/2026
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter to gallery_category.php, (2) photo_id parameter to gallery_photo.php, and the (3) user_name and (4) user_pass parameters to admin/index.php. NOTE: some of…
ModificadaAlta (7.5)1.0%💥 ExploitOntarioabandonedplaces A Better Member-based ASP Photo Gallery11/2/200916/6/2026
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote attackers to execute arbitrary SQL commands via the entry parameter.
ModificadaAlta (7.5)1.0%💥 ExploitActivewebsoftwares Active Photo Gallery17/12/200816/6/2026
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaAlta (7.5)6.3%💥 ExploitCoppermine-gallery Coppermine Photo Gallery6/8/200816/6/2026
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.
ModificadaAlta (7.5)2.1%💥 ExploitCoppermine-gallery Coppermine Photo Gallery5/8/200816/6/2026
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
ModificadaAlta (7.5)0.97%💥 ExploitTerong Advanced WEB Photo Gallery17/4/200816/6/2026
SQL injection vulnerability in index.php in Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 allows remote attackers to execute arbitrary SQL commands via the photo_id parameter.
ModificadaMedia (6.5)1.8%—Coppermine Photo Gallery16/4/200816/6/2026
SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload.
ModificadaMedia (6.8)1.9%—Coppermine Photo Gallery16/4/200816/6/2026
SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input field associated with the session_id variable, as exploited in the wild in April 2008. NOTE: the fix…
ModificadaMedia (5)2.4%💥 ExploitTerong Advanced WEB Photo Gallery9/4/200816/6/2026
Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
ModificadaAlta (7.5)1.1%💥 ExploitPHP WEB Scripts Dynamic Photo Gallery5/3/200816/6/2026
SQL injection vulnerability in album.php in PHP WEB SCRIPT Dynamic Photo Gallery 1.02 allows remote attackers to execute arbitrary SQL commands via the albumID parameter.
ModificadaMedia (4.3)1.5%—Coppermine Photo Gallery31/1/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters.
Orbitaley — Vulnerabilidades