Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.20%—Navneil Naicker ACF GalerieAI23/4/20267/10/2026
Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACF Galerie 4: from n/a through 1.4.2.
ModificadaMedia (6.1)0.41%—Igalerie25/1/202417/6/2026
iGalerie v3.0.22 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the Titre (Title) field in the editing interface.
ModificadaAlta (7.5)0.97%💥 ExploitKwsphp Galerie Module20/2/200916/6/2026
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action.
ModificadaAlta (7.5)0.97%💥 ExploitRS Maxsoft Fotogalerie4/11/200816/6/2026
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute arbitrary SQL commands via the fotoID parameter. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.
ModificadaAlta (7.5)0.97%💥 ExploitGalerie9/10/200816/6/2026
SQL injection vulnerability in galerie.php in Galerie 3.2 allows remote attackers to execute arbitrary SQL commands via the pic parameter.
ModificadaAlta (7.5)1.2%💥 ExploitExv2 BamagalerieExv217/3/200816/6/2026
SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
ModificadaAlta (7.5)6.0%💥 ExploitMatpo Bilder Galerie4/1/200816/6/2026
PHP remote file inclusion vulnerability in includes/tumbnail.php in MatPo Bilder Galerie 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter.
ModificadaAlta (7.5)2.8%💥 ExploitMatpo Bilder Galerie Kontakt Formular4/1/200816/6/2026
PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.
ModificadaMedia (6.8)6.5%💥 ExploitMapos Scripts Bilder Galerie14/8/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php, (2) galerie.php, or (3) anzagien.php. NOTE: A later report states that 1.1 is also affected, but that the filename for…
ModificadaAlta (7.5)1.3%💥 ExploitNoname Media Photo Galerie Standard6/2/200716/6/2026
SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (5.1)4.5%💥 ExploitMiraksgalerie9/6/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP code via a URL in the (1) g_pcltar_lib_dir parameter in (a) pcltar.lib.php when register_globals is enabled, and (2) listconfigfile[] parameter in (b) galsecurity.lib.php and (c) galimage.lib.php.
ModificadaMedia (6.4)1.6%—Power Place PHP Easy Galerie22/5/200616/6/2026
PHP remote file inclusion vulnerability in index.php in PHP Easy Galerie 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the includepath parameter.
ModificadaMedia (6.8)2.1%💥 ExploitTimobraun Dynamic Galerie10/5/200616/6/2026
Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter in (1) index.php and (2) galerie.php. NOTE: this issue might be resultant from directory traversal.
ModificadaAlta (7.5)3.0%💥 ExploitTimobraun Dynamic Galerie10/5/200616/6/2026
Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php.
ModificadaAlta (7.5)1.3%💥 ExploitGalerie6/11/200516/6/2026
SQL injection vulnerability in showGallery.php in Gallery (Galerie) 2.4 allows remote attackers to execute arbitrary SQL commands via the galid parameter.
ModificadaMedia (5)0.90%—Truegalerie31/12/200316/6/2026
upload.php in Truegalerie 1.0 allows remote attackers to read arbitrary files by specifying the target filename in the file cookie in form.php, then downloading the file from the image gallery.
ModificadaMedia (6.4)2.1%💥 ExploitTruelogik Truegalerie31/12/200316/6/2026
The (1) verif_admin.php and (2) check_admin.php scripts in Truegalerie 1.0 allow remote attackers to gain administrator access via a request to admin.php without the connect parameter and with the loggedin parameter set to any value, such as 1.
Orbitaley — Vulnerabilidades