Vulnerabilities
Summary — last 7 days
New vulnerabilities2,738▼ 488 vs. last week
Critical / high1,301▼ 189 vs. last week
New active exploitation (KEV)4▼ 5 vs. last week
Unscored (no CVSS)229▼ 273 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.5) | 0.28% | — | AYS Gallery-photo-galleryAI | 9/22/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Photo Gallery by Ays gallery-photo-gallery allows DOM-Based XSS.This issue affects Photo Gallery by Ays: from n/a through <= 6.3.8. | |
| Deferred | Medium (6.5) | 0.45% | — | Realwebcare Awesome-responsive-photo-galleryAI | 2/3/2025 | 6/17/2026 | Missing Authorization vulnerability in Realwebcare Image Gallery – Responsive Photo Gallery awesome-responsive-photo-gallery allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Gallery – Responsive Photo Gallery: from n/a through <= 1.0.5. | |
| Modified | High (7.5) | 1.2% | — | Francisco Charrua Photo-gallery | 7/21/2006 | 6/16/2026 | SQL injection vulnerability in Room.php in Francisco Charrua Photo-Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. |