Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

74 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.53%—Realtyworkstation Realty Workstation28/10/202417/6/2026
Authentication Bypass Using an Alternate Path or Channel vulnerability in realtyworkstation Realty Workstation realty-workstation allows Authentication Bypass.This issue affects Realty Workstation: from n/a through <= 1.0.45.
AplazadaCrítica (9.1)0.49%—Realtyna Organic IDXAI12/7/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Realtyna Realtyna Organic IDX plugin allows Code Injection.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.13.
AplazadaAlta (7.1)0.33%—Realtyna Organic IDXAI3/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Realtyna Realtyna Organic IDX plugin allows Reflected XSS.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.4.
AplazadaCrítica (9.3)1.7%—Realtyna Organic IDXAI15/4/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Realtyna Realtyna Organic IDX plugin.This issue affects Realtyna Organic IDX plugin: from n/a through 4.14.4.
ModificadaMedia (4.9)0.99%—Realtyworkstation Realty Workstation8/6/202217/6/2026
The Realty Workstation WordPress plugin before 1.0.15 does not sanitise and escape the trans_edit parameter before using it in a SQL statement when an agent edit a transaction, leading to an SQL injection
ModificadaCrítica (9.8)1.8%—Simplerealtytheme Simple Login LOG22/8/201917/6/2026
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
ModificadaMedia (6.1)1.4%—Bestwebsoft Realty20/8/201917/6/2026
The realty plugin before 1.1.0 for WordPress has multiple XSS issues.
ModificadaCrítica (9.8)1.7%—Simplerealtytheme Simple Login LOG14/8/201917/6/2026
The simple-login-log plugin before 1.1.2 for WordPress has SQL injection.
ModificadaAlta (8.8)3.1%—Realtyna Property Listing18/10/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/index.php.
ModificadaAlta (7.2)2.2%—Realtyna Property Listing18/10/201717/6/2026
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field action, (4) css, (5) tip, (6) cat_id, (7) text_search, (8) plisting,…
ModificadaMedia (6.1)0.89%—Bestwebsoft CaptchaBestwebsoft CAR RentalBestwebsoft Contact FormBestwebsoft Contact Form Multi+4722/5/201717/6/2026
Cross-site scripting vulnerability in Captcha prior to version 4.3.0, Car Rental prior to version 1.0.5, Contact Form Multi prior to version 1.2.1, Contact Form prior to version 4.0.6, Contact Form to DB prior to version 1.5.7, Custom Admin Page prior to version 0.1.2, Custom Fields Search prior to version 1.3.2,…
ModificadaMedia (4.3)1.3%—Myrephp Myre Realty Manager25/8/201316/6/2026
Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter.
ModificadaAlta (7.5)1.0%—Myrephp Myre Realty Manager25/8/201316/6/2026
Multiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands via the bathrooms1 parameter to (1) demo2/search.php or (2) search.php.
ModificadaMedia (4.3)10%—Simplerealtytheme Advanced Text Widget Plugin24/1/201316/6/2026
Cross-site scripting (XSS) vulnerability in advancedtext.php in Advanced Text Widget plugin before 2.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.
ModificadaMedia (6.8)2.8%—Open-realty6/9/201216/6/2026
Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the select_users_template parameter to index.php.
ModificadaMedia (6.8)1.1%—Rwcinc Free Realty13/8/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in admin/agenteditor.php in Free Realty 3.1-0.6 allow remote attackers to hijack the authentication of administrators for requests that (1) add an agent via an addagent action or (2) modify an agent.
ModificadaAlta (7.5)1.1%—Rwcinc Free Realty13/8/201216/6/2026
Multiple SQL injection vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to execute arbitrary SQL commands via the (1) view parameter to agentdisplay.php or (2) edit parameter to admin/admin.php.
ModificadaMedia (4.3)1.6%—Rwcinc Free Realty13/8/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Free Realty 3.1-0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) notes parameter to (a) admin/agenteditor.php; (2) title, (3) previewdesc, (4) fulldesc, or (5) notes parameter (b) to agentadmin.php or (c) in an addlisting action to…
ModificadaAlta (7.5)1.2%—Emophp EMO Realty Manager2/11/201116/6/2026
SQL injection vulnerability in googlemap/index.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the cat1 parameter.
ModificadaMedia (5)1.2%—Open-realty24/9/201116/6/2026
Open-Realty 2.5.8 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by install/versions/upgrade_115.inc.php and certain other files.
ModificadaAlta (7.5)14%—COM Realtyna12/7/201016/6/2026
Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
ModificadaAlta (7.5)0.97%—Freerealty.rwcinc Free Realty4/5/201016/6/2026
Multiple SQL injection vulnerabilities in agentadmin.php in Free Realty allow remote attackers to execute arbitrary SQL commands via the (1) login field (aka agentname parameter) or (2) password field (aka agentpassword parameter).
ModificadaMedia (5)10%—Software.realtyna COM Joomlaupdater8/4/201016/6/2026
Directory traversal vulnerability in the Magic Updater (com_joomlaupdater) component for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
ModificadaMedia (4.3)1.8%—Realtysoft PG Roomate Finder Solution14/8/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via the part parameter to (1) quick_search.php and (2) viewprofile.php.
ModificadaAlta (7.5)0.99%—Realtywebware Realty Web-base22/5/200916/6/2026
SQL injection vulnerability in list_list.php in Realty Webware Technologies Web-Base 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.