Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

262 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.4%—Thinkfactory Ultimate Estate22/6/200616/6/2026
SQL injection vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.6)0.38%—Activestate Activeperl6/6/200616/6/2026
ActiveState ActivePerl 5.8.8.817 for Windows configures the site/lib directory with "Users" group permissions for changing files, which allows local users to gain privileges by creating a malicious sitecustomize.pl file in that directory. NOTE: The provenance of this information is unknown; the details are obtained…
ModificadaMedia (4.3)3.9%💥 ExploitFusionzone Realestatezone29/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters.
ModificadaAlta (7.5)1.3%💥 ExploitWebeveyn Whomp Real Estate Manager XP 20059/2/200616/6/2026
SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaAlta (7.5)1.1%💥 ExploitLandshop Real Estate Commerce System5/12/200516/6/2026
SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters.
ModificadaAlta (7.5)1.2%💥 ExploitRelative Real Estate SystemsAI5/12/200516/6/2026
SQL injection vulnerability in index.php in Relative Real Estate Systems 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the mls parameter.
ModificadaAlta (10)1.7%—Real Estate Management Software31/12/200416/6/2026
Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors.
ModificadaAlta (7.5)8.0%💥 ExploitActivestate ActiveperlLarry Wall Perl31/12/200416/6/2026
Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, which may trigger a buffer overflow.
ModificadaBaja (2.1)1.7%💥 ExploitActivestate Activeperl31/12/200416/6/2026
ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug…
ModificadaAlta (10)6.8%—Activestate ActiveperlLarry Wall Perl4/5/200416/6/2026
Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.
ModificadaMedia (5)6.6%—Activestate Activepython25/3/200216/6/2026
ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client's filesystem, which allows remote attackers to read arbitrary files via a malicious web page containing Python script.
ModificadaAlta (7.5)14%💥 ExploitActivestate Activeperl6/12/200116/6/2026
Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request for a long filename that ends in a .pl extension.