Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.9% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter. | |
| Modificada | Crítica (9.8) | 2.9% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter. | |
| Modificada | Crítica (9.8) | 2.9% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php. | |
| Modificada | Crítica (9.8) | 3.4% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement. | |
| Modificada | Media (5.4) | 0.98% | — | Anblik Image-gallery-with-slideshow | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database. | |
| Modificada | Alta (7.5) | 2.3% | — | Wptf-image-gallery Project Wptf-image-gallery | 6/10/2016 | 17/6/2026 | Remote file download vulnerability in wptf-image-gallery v1.03 | |
| Modificada | Media (4.3) | 1.1% | — | Obsession-design Image-gallery | 16/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter. |