Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.17% | — | Real EstateAI | 26/6/2026 | 26/6/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in Real Estate 7 <= 3.5.9 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Real EstateAI | 26/6/2026 | 26/6/2026 | Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. | |
| Aplazada | Media (5.1) | 0.17% | — | Zoner Real EstateAI | 4/6/2026 | 22/7/2026 | WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when creating properties. Attackers can inject JavaScript payloads in the property creation form that execute when administrators… | |
| Aplazada | Media (5.5) | 0.24% | — | E-plugins Real Estate PROAI | 22/4/2026 | 17/6/2026 | The Real Estate Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Media (5.1) | 0.22% | — | Jproperty Iproperty Real EstateAI | 9/4/2026 | 26/9/2026 | Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter of the all-properties-with-map endpoint… | |
| Aplazada | Media (6.1) | 0.26% | 💥 PoC | Ingestate ServerAI | 30/3/2026 | 5/7/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Edit feature of the Software Package List page of IngEstate Server v11.14.0 allow attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the About application, What's news, or Release note parameters. | |
| Analizada | Alta (8.8) | 0.46% | — | Netartmedia Real Estate Portal | 12/3/2026 | 17/6/2026 | Netartmedia Real Estate Portal 5.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can submit POST requests to index.php with malicious SQL payloads in the page field to bypass authentication,… | |
| Analizada | Alta (8.8) | 0.46% | — | Netartmedia Real Estate Portal | 12/3/2026 | 17/6/2026 | Netartmedia Real Estate Portal 5.0 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user_email parameter. Attackers can send POST requests to index.php with malicious payloads in the user_email field to bypass authentication,… | |
| Analizada | Alta (8.8) | 0.32% | — | Netartmedia Real Estate Portal | 12/3/2026 | 17/6/2026 | Netartmedia PHP Real Estate Agency 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can send POST requests to index.php with crafted SQL payloads in the features[] parameter to… | |
| Aplazada | Alta (8.8) | 0.38% | — | Inout RealestateAI | 12/3/2026 | 17/6/2026 | Inout RealEstate contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the city parameter. Attackers can send POST requests to the agents/agentlistdetails endpoint with malicious SQL payloads in the city parameter to extract sensitive… | |
| Aplazada | Crítica (9.8) | 0.40% | — | Axiomthemes EstateAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in axiomthemes Estate estate allows Object Injection.This issue affects Estate: from n/a through <= 1.3.4. | |
| Aplazada | Media (6.5) | 0.23% | — | Wpestate Wpresidence CoreAI | 19/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpEstate Wpresidence Core wpresidence-core allows Stored XSS.This issue affects Wpresidence Core: from n/a through <= 5.4.0. | |
| Aplazada | Media (6.5) | 0.32% | — | EKA Software Computer Information Advertising Services LTD Real Estate ScriptAI | 17/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS). This issue affects Real Estate… | |
| Aplazada | Alta (7.6) | 0.32% | — | Firestormplugins Firestorm Professional Real EstateAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FireStorm Plugins FireStorm Professional Real Estate fs-real-estate-plugin allows Blind SQL Injection.This issue affects FireStorm Professional Real Estate: from n/a through <= 2.7.11. | |
| Aplazada | Alta (7.3) | 0.25% | — | E-plugins Real Estate PROAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in e-plugins Real Estate Pro real-estate-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real Estate Pro: from n/a through <= 2.1.5. | |
| Aplazada | Media (6.5) | 0.32% | — | Realestateconnected Easy Property ListingsAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.20. | |
| Aplazada | Alta (7.1) | 0.26% | — | E-plugins Real Estate PROAI | 8/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e-plugins Real Estate Pro real-estate-pro allows Reflected XSS.This issue affects Real Estate Pro: from n/a through <= 2.1.4. | |
| Analizada | Baja (2) | 0.40% | — | Codeastro Real Estate Management System | 19/12/2025 | 17/6/2026 | A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /admin/userdelete.php of the component Administrator Endpoint. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Baja (2) | 0.36% | — | Codeastro Real Estate Management System | 19/12/2025 | 17/6/2026 | A weakness has been identified in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /admin/stateadd.php of the component Administrator Endpoint. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been made available to the public and… | |
| Modificada | Baja (2) | 0.36% | — | Codeastro Real Estate Management System | 19/12/2025 | 17/6/2026 | A security flaw has been discovered in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /admin/userbuilderdelete.php of the component Administrator Endpoint. The manipulation results in sql injection. The attack can be launched remotely. The exploit has been released to the… | |
| Analizada | Baja (2) | 0.36% | — | Codeastro Real Estate Management System | 19/12/2025 | 17/6/2026 | A vulnerability was identified in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /admin/useragentdelete.php of the component Administrator Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and… | |
| Aplazada | Media (6.5) | 0.25% | — | G5theme Essential Real EstateAI | 16/12/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Real Estate: from n/a through <= 5.3.2. | |
| Aplazada | Media (5.3) | 0.27% | — | G5theme Essential Real EstateAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Essential Real Estate: from n/a through <= 5.3.2. | |
| Aplazada | Media (4.3) | 0.22% | — | Realestateconnected Easy Property ListingsAI | 16/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.22. | |
| Analizada | Baja (2) | 0.46% | — | Remyandrade Real Estate Property Listing APP | 11/12/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin/property.php. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the… |