Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

171 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.22%—Wp-property-hive PropertyhiveAI17/9/202617/9/2026
Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions.
AplazadaMedia (6.9)0.50%—Joomshaper SP PropertyAI10/9/202610/9/2026
Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks.
AplazadaMedia (6.9)0.43%—Joomshaper SP PropertyAI10/9/202610/9/2026
Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potential email manipulation.
AplazadaAlta (8.6)0.44%—Joomshaper SP PropertyAI10/9/202610/9/2026
Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping.
AplazadaMedia (6.9)0.33%—Joomshaper SP PropertyAI10/9/202610/9/2026
Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file removal actions with arbitrary path strings or upload unverified file types.
AplazadaAlta (7.1)0.21%—Joomshaper SP PropertyAI10/9/202610/9/2026
Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) endpoints processed POST requests without verifying Joomla session anti-CSRF tokens.
AplazadaCrítica (9.3)0.51%—Joomshaper SP PropertyAI10/9/202610/9/2026
Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and psize_range_dropdown) by directly concatenating raw…
AnalizadaAlta (8.8)0.42%—Oracle Hospitality Opera 5 Property Services18/8/20264/9/2026
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.28.0-5.6.28.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle…
Pendiente de análisisMedia (6.7)0.47%—Otalio Ship Property Management SystemAI18/8/202629/9/2026
Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting
Pendiente de análisisAlta (8.1)0.26%—Otalio Ship Property Management SystemAI18/8/202629/9/2026
Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs
AplazadaAlta (7.1)0.25%—Houzez Property FeedAI6/8/202612/8/2026
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
AplazadaMedia (6.4)0.33%—Realestateconnected Easy Property ListingsAI1/8/202612/8/2026
The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to, and including, 3.5.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and…
AnalizadaBaja (1.9)0.14%—Oracle Property Manager21/7/202611/8/2026
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Property Manager executes to…
AnalizadaMedia (5.4)0.23%—Oracle Property Manager21/7/202611/8/2026
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful…
AnalizadaMedia (5.4)0.12%—Oracle Property Manager21/7/202611/8/2026
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful…
AnalizadaAlta (7.2)0.49%—Oracle Property Manager21/7/202611/8/2026
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful…
AplazadaAlta (7.1)0.25%—Wp-property-hive PropertyhiveAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3.
AplazadaMedia (4.9)0.48%—Wp-property-hive Houzez Property FeedAI2/7/20262/7/2026
The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the prepare_items() method of the…
AnalizadaAlta (8.8)0.43%—Faboba Ultimate Property Listing19/6/202619/8/2026
Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_selectuser_id parameter. Attackers can send GET requests to index.php with the option=com_upl and view=propertylisting…
AnalizadaAlta (7.2)0.49%—Oracle Property Manager17/6/202618/6/2026
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful…
AnalizadaCrítica (9.8)0.55%—Oracle Hospitality Opera 5 Property Services28/5/202617/6/2026
Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6 and 5.6.28. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to…
AplazadaAlta (7.1)0.25%—Wp-property-hive PropertyhiveAI27/5/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows DOM-Based XSS.This issue affects PropertyHive: from n/a through <= 2.2.2.
AplazadaMedia (5.1)0.22%—Jproperty Iproperty Real EstateAI9/4/202626/9/2026
Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter of the all-properties-with-map endpoint…
AplazadaBaja (1.9)0.15%—Propertyguru AgentnetAI3/4/202624/7/2026
A security flaw has been discovered in PropertyGuru AgentNet Singapore App up to 23.7.10 on Android. This affects an unknown function of the file com/allproperty/android/agentnet/BuildConfig.java of the component com.allproperty.android.agentnet. The manipulation of the argument…
ModificadaCrítica (9.8)0.52%—Jon-remus-sevellejo Personnel Property Equipment System2/3/202617/6/2026
sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php.
Orbitaley — Vulnerabilidades