Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 0.61% | — | Codefuture Image Hosting Script | 12/4/2026 | 17/6/2026 | CF Image Hosting Script 1.6.5 allows unauthenticated attackers to download and decode the application database by accessing the imgdb.db file in the upload/data directory. Attackers can extract delete IDs stored in plaintext from the deserialized database and use them to delete all pictures via the d parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Yabsoft Advanced Image Hosting Script | 26/11/2012 | 16/6/2026 | SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to execute arbitrary SQL commands via the gal parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Clixint Image Hosting Script DPI | 2/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Codefuture CF Image Hosting Script | 29/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this was originally reported as a file disclosure vulnerability, but this is… | |
| Modificada | Alta (7.5) | 6.4% | — | Scripteen Free Image Hosting Script | 25/8/2010 | 16/6/2026 | admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain administrative access by setting the cookgid cookie value to 1, a different vector than CVE-2008-3211. | |
| Modificada | Media (4.3) | 1.4% | — | Yabsoft Advanced Image Hosting Script | 10/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search.php in YABSoft Advanced Image Hosting (AIH) Script 2.2, and possibly 2.3, allows remote attackers to inject arbitrary web script or HTML via the text parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Clixint Image Hosting Script DPI | 10/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in images.php in Image Hosting Script DPI 1.1 Final (1.1F) allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | — | Scripteen Free Image Hosting Script | 20/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in header.php in Scripteen Free Image Hosting Script 2.3 allow remote attackers to execute arbitrary SQL commands via a (1) cookid or (2) cookgid cookie. | |
| Modificada | Alta (7.5) | 1.0% | — | Yabsoft Advanced Image Hosting Script | 20/3/2009 | 16/6/2026 | SQL injection vulnerability in gallery_list.php in YABSoft Advanced Image Hosting (AIH) Script 2.3 allows remote attackers to execute arbitrary SQL commands via the gal parameter. | |
| Modificada | Alta (7.5) | 0.95% | — | Scripteen Free Image Hosting Script | 18/7/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Scripteen Free Image Hosting Script 1.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameter to admin/login.php, or the (3) uname or (4) pass parameter to login.php. NOTE: the provenance of this information is unknown; the… | |
| Modificada | Alta (7.5) | 3.3% | — | Scripteen Free Image Hosting Script | 18/7/2008 | 16/6/2026 | Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrative access by setting the cookid cookie value to 1. | |
| Modificada | Alta (7.5) | 0.97% | — | Yabsoft Advanced Image Hosting Script | 3/6/2008 | 16/6/2026 | SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the t parameter. | |
| Modificada | Media (6.5) | 0.90% | — | ACE Image Hosting Script | 17/12/2007 | 16/6/2026 | SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbitrary SQL commands via the id parameter in editalbum mode. |