Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

262 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.98%💥 ExploitConkurent Real Estate22/10/200816/6/2026
SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in browse mode.
ModificadaAlta (7.5)1.0%💥 ExploitReal-estate-scripts15/10/200816/6/2026
SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.
ModificadaAlta (7.5)1.00%💥 ExploitBuilt2go Real Estate Listings9/10/200816/6/2026
SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects PRE Real Estate Listings23/9/200816/6/2026
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c parameter.
ModificadaMedia (6.8)1.1%💥 ExploitVclcomponents Relative Real Estate Systems15/7/200816/6/2026
SQL injection vulnerability in index.php in Relative Real Estate Systems 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.
ModificadaAlta (7.5)0.97%💥 ExploitMole Group Real Estate Script10/7/200816/6/2026
SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.
ModificadaMedia (5)2.1%💥 ExploitRelative Real Estate Systems26/6/200816/6/2026
Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
ModificadaAlta (7.5)1.0%💥 ExploitTherealestatescript THE Real Estate Script27/5/200816/6/2026
SQL injection vulnerability in dpage.php in The Real Estate Script allows remote attackers to execute arbitrary SQL commands via the docID parameter.
ModificadaAlta (7.5)1.1%—Site2nite Real Estate WEB14/2/200816/6/2026
Multiple SQL injection vulnerabilities in default.asp in Site2Nite allow remote attackers to execute arbitrary SQL commands via the (1) txtUserName and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.0%💥 ExploitDarko Selesi EstateagentJoomlaMambo31/1/200816/6/2026
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x and Joomla! allows remote attackers to execute arbitrary SQL commands via the objid parameter in a contact showObject action.
ModificadaAlta (7.5)1.0%💥 ExploitPHP Real Estate Classifieds Premium Plus20/12/200716/6/2026
SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)0.84%—PHP Real Estate Script Classifieds20/12/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in PHP Real Estate Classifieds allow remote attackers to inject arbitrary web script or HTML via unspecified "text areas/boxes."
ModificadaMedia (6.8)1.1%💥 ExploitCodewidgets Real Estate Listing Website Application Template31/7/200716/6/2026
SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaAlta (7.5)3.1%💥 ExploitPHP Real Estate Classifieds11/6/200716/6/2026
PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary PHP code via a URL in the loc parameter.
ModificadaMedia (6.8)0.34%—Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery30/4/200716/6/2026
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating…
ModificadaAlta (7.2)0.41%—Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery30/4/200716/6/2026
Buffer overflow in Ghost Service Manager, as used in Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, allows local users to gain privileges via a long string.
ModificadaMedia (4.9)0.34%—Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery30/4/200716/6/2026
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore points images are configured, uses weak permissions (world readable) for a configuration file with network share credentials, which allows local users to obtain the…
ModificadaAlta (7.5)1.2%💥 ExploitMotionborg WEB Real Estate11/1/200716/6/2026
SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters. NOTE: some details were obtained from third party information.
ModificadaAlta (7.5)1.1%💥 ExploitSoftwebs Nepal Ananda Real Estate28/12/200616/6/2026
SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the agent parameter.
ModificadaMedia (4.3)0.34%—Symantec Livestate Agent FOR Windows6/12/200616/6/2026
Symantec LiveState 7.1 Agent for Windows allows local users to gain privileges by stopping the shstart.exe process and open "Web Self-Service" from the system tray icon, which will open a browser window running with elevated privileges. NOTE: several third-party researchers have noted that administrator privileges may…
ModificadaAlta (7.5)1.3%💥 ExploitIexpress Estate Agent Manager16/11/200616/6/2026
SQL injection vulnerability in admin/default.asp in Estate Agent Manager 1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the UserName field.
ModificadaAlta (7.5)1.3%💥 ExploitDynamic Dataworx Nurealestate14/11/200616/6/2026
SQL injection vulnerability in propertysdetails.asp in Dynamic Dataworx NuRealestate (NuRems) 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the PropID parameter.
ModificadaAlta (7.5)2.6%💥 ExploitBits-dont-bite Estateagent24/8/200616/6/2026
PHP remote file inclusion vulnerability in estateagent.php in the EstateAgent component (com_estateagent) for Mambo, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
ModificadaMedia (4.3)1.3%—Thinkfactory Ultimate Estate22/6/200616/6/2026
Cross-site scripting (XSS) vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
ModificadaMedia (4.3)1.2%—Thinkfactory Ultimate Estate22/6/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in (a) emailtofriend.pl or (b) violation.pl, (2) seller parameter in (c) vsoa.pl, (3) user parameter in (d) userask.pl or (e) leavefeed.pl,…
Orbitaley — Vulnerabilidades