Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.52% | — | Jon-remus-sevellejo Personnel Property Equipment System | 2/3/2026 | 17/6/2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_tecnical_user.php. | |
| Modificada | Alta (7.2) | 0.74% | — | Jon-remus-sevellejo Personnel Property Equipment System | 2/3/2026 | 17/6/2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php. | |
| Modificada | Crítica (9.8) | 0.52% | — | Jon-remus-sevellejo Personnel Property Equipment System | 2/3/2026 | 17/6/2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/advance_search.php. | |
| Modificada | Crítica (9.8) | 0.52% | — | Jon-remus-sevellejo Personnel Property Equipment System | 2/3/2026 | 17/6/2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/myitem_reuse.php. | |
| Analizada | Baja (2) | 0.26% | — | Projectworlds House Rental AND Property Listing Project | 30/1/2026 | 17/6/2026 | A weakness has been identified in projectworlds House Rental and Property Listing 1.0. This vulnerability affects unknown code of the file /app/sms.php. This manipulation of the argument Message causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the… | |
| Aplazada | Media (6.5) | 0.32% | — | Realestateconnected Easy Property ListingsAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.20. | |
| Analizada | Media (5.5) | 0.42% | — | Projectworlds House Rental AND Property Listing Project | 7/1/2026 | 17/6/2026 | A flaw has been found in projectworlds House Rental and Property Listing 1.0. Impacted is an unknown function of the file /app/register.php?action=reg of the component Signup. This manipulation of the argument image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been… | |
| Modificada | Baja (1.9) | 0.25% | — | Projectworlds House Rental AND Property Listing Project | 7/1/2026 | 17/6/2026 | A vulnerability was detected in projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /app/complaint.php. The manipulation of the argument Name results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Media (4.3) | 0.17% | — | Easy Property Listings XML CSV ImportAI | 30/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Merv Barrett Import into Easy Property Listings easy-property-listings-xml-csv-import allows Cross Site Request Forgery.This issue affects Import into Easy Property Listings: from n/a through <= 2.2.1. | |
| Aplazada | Alta (7.5) | 0.27% | — | Wp-property-hive PropertyhiveAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12. | |
| Aplazada | Media (4.3) | 0.22% | — | Realestateconnected Easy Property ListingsAI | 16/12/2025 | 5/10/2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.22. | |
| Analizada | Baja (2) | 0.46% | — | Remyandrade Real Estate Property Listing APP | 11/12/2025 | 17/6/2026 | A vulnerability has been found in SourceCodester Real Estate Property Listing App 1.0. The impacted element is an unknown function of the file /admin/property.php. Such manipulation of the argument image leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Media (4.3) | 0.18% | — | Property HiveAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Property Hive PropertyHive propertyhive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through <= 2.1.12. | |
| Aplazada | Alta (8.8) | 0.53% | — | Designthemes Single PropertyAI | 22/10/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in designthemes Single Property single-property allows Object Injection.This issue affects Single Property: from n/a through <= 2.8. | |
| Aplazada | Media (6.5) | 0.21% | — | Wp-property-hive PropertyhiveAI | 3/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.5. | |
| Aplazada | Crítica (9.3) | 1.9% | 💥 Exploit | Wp-propertyAI | 5/8/2025 | 16/6/2026 | WP-Property plugin for WordPress up to and including version 1.35.0 contains an unauthenticated file upload vulnerability in the third-party `uploadify.php` script. A remote attacker can upload arbitrary PHP files to a temporary directory without authentication, leading to remote code execution. | |
| Aplazada | Media (4.3) | 0.26% | — | Sminozzi Real Estate Property 2024 Create Your OWN Fields AND Search BARAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in sminozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin real-estate-right-now allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin: from n/a… | |
| Analizada | Media (5.5) | 0.58% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Admin/EditCity.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /Admin/InsertCity.php. The manipulation of the argument cmbState leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Real Estate Property Management System 1.0. This issue affects some unknown processing of the file /Admin/InsertState.php. The manipulation of the argument txtStateName leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0. This vulnerability affects unknown code of the file /Admin/InsertCategory.php. The manipulation of the argument txtCategoryName leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.49% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /Admin/NewsReport.php. The manipulation of the argument txtFrom leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Admin/Property.php. The manipulation of the argument cmbCat leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Real Estate Property Management System | 5/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Real Estate Property Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /Admin/User.php. The manipulation of the argument txtUserName leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Alta (8.8) | 0.44% | — | PropertyAI | 27/5/2025 | 17/6/2026 | The Property plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the use of the property_package_user_role metadata in versions 1.0.5 to 1.0.6. This makes it possible for authenticated attackers, with Author‐level access and above, to elevate their privileges to that of an… |