Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.4% | — | Thinkfactory Ultimate Estate | 22/6/2006 | 16/6/2026 | SQL injection vulnerability in index.pl in Ultimate Estate 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.6) | 0.38% | — | Activestate Activeperl | 6/6/2006 | 16/6/2026 | ActiveState ActivePerl 5.8.8.817 for Windows configures the site/lib directory with "Users" group permissions for changing files, which allows local users to gain privileges by creating a malicious sitecustomize.pl file in that directory. NOTE: The provenance of this information is unknown; the details are obtained… | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Fusionzone Realestatezone | 29/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Webeveyn Whomp Real Estate Manager XP 2005 | 9/2/2006 | 16/6/2026 | SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Landshop Real Estate Commerce System | 5/12/2005 | 16/6/2026 | SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Relative Real Estate SystemsAI | 5/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Relative Real Estate Systems 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the mls parameter. | |
| Modificada | Alta (10) | 1.7% | — | Real Estate Management Software | 31/12/2004 | 16/6/2026 | Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors. | |
| Modificada | Alta (7.5) | 8.0% | 💥 Exploit | Activestate ActiveperlLarry Wall Perl | 31/12/2004 | 16/6/2026 | Integer overflow in the duplication operator in ActivePerl allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large multiplier, which may trigger a buffer overflow. | |
| Modificada | Baja (2.1) | 1.7% | 💥 Exploit | Activestate Activeperl | 31/12/2004 | 16/6/2026 | ActivePerl 5.8.x and others, and Larry Wall's Perl 5.6.1 and others, when running on Windows systems, allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long argument to the system command, which leads to a stack-based buffer overflow. NOTE: it is unclear whether this bug… | |
| Modificada | Alta (10) | 6.8% | — | Activestate ActiveperlLarry Wall Perl | 4/5/2004 | 16/6/2026 | Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character. | |
| Modificada | Media (5) | 6.6% | — | Activestate Activepython | 25/3/2002 | 16/6/2026 | ActivePython ActiveX control for Python in the AXScript package, when used in Internet Explorer, does not prevent a script from reading files from the client's filesystem, which allows remote attackers to read arbitrary files via a malicious web page containing Python script. | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Activestate Activeperl | 6/12/2001 | 16/6/2026 | Buffer overflow in PerlIS.dll in Activestate ActivePerl 5.6.1.629 and earlier allows remote attackers to execute arbitrary code via an HTTP request for a long filename that ends in a .pl extension. |