Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.20% | — | Navneil Naicker ACF GalerieAI | 23/4/2026 | 7/10/2026 | Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACF Galerie 4: from n/a through 1.4.2. | |
| Modificada | Media (6.1) | 0.41% | — | Igalerie | 25/1/2024 | 17/6/2026 | iGalerie v3.0.22 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Titre (Title) field in the editing interface. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Kwsphp Galerie Module | 20/2/2009 | 16/6/2026 | SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | RS Maxsoft Fotogalerie | 4/11/2008 | 16/6/2026 | SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Galerie | 9/10/2008 | 16/6/2026 | SQL injection vulnerability in galerie.php in Galerie 3.2 allows remote attackers to execute arbitrary SQL commands via the pic parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Exv2 BamagalerieExv2 | 17/3/2008 | 16/6/2026 | SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Alta (7.5) | 6.0% | 💥 Exploit | Matpo Bilder Galerie | 4/1/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Matpo Bilder Galerie Kontakt Formular | 4/1/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. | |
| Modificada | Media (6.8) | 6.5% | 💥 Exploit | Mapos Scripts Bilder Galerie | 14/8/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php, (2) galerie.php, or (3) anzagien.php. NOTE: A later report states that 1.1 is also affected, but that the filename for… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Noname Media Photo Galerie Standard | 6/2/2007 | 16/6/2026 | SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (5.1) | 4.5% | 💥 Exploit | Miraksgalerie | 9/6/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP code via a URL in the (1) g_pcltar_lib_dir parameter in (a) pcltar.lib.php when register_globals is enabled, and (2) listconfigfile[] parameter in (b) galsecurity.lib.php and (c) galimage.lib.php. | |
| Modificada | Media (6.4) | 1.6% | — | Power Place PHP Easy Galerie | 22/5/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in PHP Easy Galerie 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the includepath parameter. | |
| Modificada | Media (6.8) | 2.1% | 💥 Exploit | Timobraun Dynamic Galerie | 10/5/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter in (1) index.php and (2) galerie.php. NOTE: this issue might be resultant from directory traversal. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Timobraun Dynamic Galerie | 10/5/2006 | 16/6/2026 | Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Galerie | 6/11/2005 | 16/6/2026 | SQL injection vulnerability in showGallery.php in Gallery (Galerie) 2.4 allows remote attackers to execute arbitrary SQL commands via the galid parameter. | |
| Modificada | Media (5) | 0.90% | — | Truegalerie | 31/12/2003 | 16/6/2026 | upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery. | |
| Modificada | Media (6.4) | 2.1% | 💥 Exploit | Truelogik Truegalerie | 31/12/2003 | 16/6/2026 | The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1. |