Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.98% | 💥 Exploit | Conkurent Real Estate | 22/10/2008 | 16/6/2026 | SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in browse mode. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Real-estate-scripts | 15/10/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Built2go Real Estate Listings | 9/10/2008 | 16/6/2026 | SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects PRE Real Estate Listings | 23/9/2008 | 16/6/2026 | SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c parameter. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Vclcomponents Relative Real Estate Systems | 15/7/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Relative Real Estate Systems 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Mole Group Real Estate Script | 10/7/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action. | |
| Modificada | Media (5) | 2.1% | 💥 Exploit | Relative Real Estate Systems | 26/6/2008 | 16/6/2026 | Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Therealestatescript THE Real Estate Script | 27/5/2008 | 16/6/2026 | SQL injection vulnerability in dpage.php in The Real Estate Script allows remote attackers to execute arbitrary SQL commands via the docID parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Site2nite Real Estate WEB | 14/2/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in default.asp in Site2Nite allow remote attackers to execute arbitrary SQL commands via the (1) txtUserName and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Darko Selesi EstateagentJoomlaMambo | 31/1/2008 | 16/6/2026 | SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | PHP Real Estate Classifieds Premium Plus | 20/12/2007 | 16/6/2026 | SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 0.84% | — | PHP Real Estate Script Classifieds | 20/12/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in PHP Real Estate Classifieds allow remote attackers to inject arbitrary web script or HTML via unspecified "text areas/boxes." | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Codewidgets Real Estate Listing Website Application Template | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | PHP Real Estate Classifieds | 11/6/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary PHP code via a URL in the loc parameter. | |
| Modificada | Media (6.8) | 0.34% | — | Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery | 30/4/2007 | 16/6/2026 | Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating… | |
| Modificada | Alta (7.2) | 0.41% | — | Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery | 30/4/2007 | 16/6/2026 | Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string. | |
| Modificada | Media (4.9) | 0.34% | — | Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery | 30/4/2007 | 16/6/2026 | Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Motionborg WEB Real Estate | 11/1/2007 | 16/6/2026 | SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters. NOTE: some details were obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Softwebs Nepal Ananda Real Estate | 28/12/2006 | 16/6/2026 | SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the agent parameter. | |
| Modificada | Media (4.3) | 0.34% | — | Symantec Livestate Agent FOR Windows | 6/12/2006 | 16/6/2026 | Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open "Web Self-Service" from the system tray icon, which will open a browser window running with elevated privileges. NOTE: several third-party researchers have noted that administrator privileges may… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Iexpress Estate Agent Manager | 16/11/2006 | 16/6/2026 | SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Dynamic Dataworx Nurealestate | 14/11/2006 | 16/6/2026 | SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the PropID parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Bits-dont-bite Estateagent | 24/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in estateagent.php in the EstateAgent component (com_estateagent) for Mambo, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Thinkfactory Ultimate Estate | 22/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Thinkfactory Ultimate Estate | 22/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in (a) emailtofriend.pl or (b) violation.pl, (2) seller parameter in (c) vsoa.pl, (3) user parameter in (d) userask.pl or (e) leavefeed.pl,… |