Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.0%—Simple Image Gallery WEB APP Project Simple Image Gallery WEB APP16/3/202317/6/2026
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the username parameter.
ModificadaAlta (8.8)0.97%—Simple Image Gallery WEB APP Project Simple Image Gallery WEB APP17/11/202217/6/2026
A SQL injection vulnerability exits on the Simple Image Gallery System 1.0 application through "id" parameter on the album page.
ModificadaMedia (6.1)0.76%—Duogeek Simple Image Gallery14/12/202117/6/2026
The Simple Image Gallery WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the msg parameter found in the ~/simple-image-gallery.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.0.6.
ModificadaCrítica (9.8)1.5%—Simple Image Gallery WEB APP Project Simple Image Gallery WEB APP16/8/202117/6/2026
An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app.
ModificadaMedia (6.1)0.65%—Kubik-rubik Simple Image Gallery Extended5/3/201817/6/2026
The htmlImageAddTitleAttribute function in sige.php in the Kubik-Rubik Simple Image Gallery Extended (SIGE) extension 3.2.3 for Joomla! has XSS via a crafted image header, as demonstrated by the Caption-Abstract header object in a JPEG file. This is fixed in 3.3.1.
ModificadaMedia (6.1)2.2%—Kubik-rubik Simple Image Gallery Extended20/2/201817/6/2026
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter.