Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.9%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.
ModificadaCrítica (9.8)2.9%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.
ModificadaCrítica (9.8)2.9%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.
ModificadaCrítica (9.8)3.4%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.
ModificadaMedia (5.4)0.98%—Anblik Image-gallery-with-slideshow14/9/201717/6/2026
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database.
ModificadaAlta (7.5)2.3%—Wptf-image-gallery Project Wptf-image-gallery6/10/201617/6/2026
Remote file download vulnerability in wptf-image-gallery v1.03
ModificadaMedia (4.3)1.1%—Obsession-design Image-gallery16/3/201016/6/2026
Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.
Orbitaley — Vulnerabilidades