Vulnerabilities

Summary — last 7 days

New vulnerabilities2,738▼ 488 vs. last week
Critical / high1,301▼ 189 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)229▼ 273 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.5)0.28%—AYS Gallery-photo-galleryAI9/22/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Photo Gallery by Ays gallery-photo-gallery allows DOM-Based XSS.This issue affects Photo Gallery by Ays: from n/a through <= 6.3.8.
DeferredMedium (6.5)0.45%—Realwebcare Awesome-responsive-photo-galleryAI2/3/20256/17/2026
Missing Authorization vulnerability in Realwebcare Image Gallery – Responsive Photo Gallery awesome-responsive-photo-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Gallery – Responsive Photo Gallery: from n/a through <= 1.0.5.
ModifiedHigh (7.5)1.2%—Francisco Charrua Photo-gallery7/21/20066/16/2026
SQL injection vulnerability in Room.php in Francisco Charrua Photo-Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.