Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.22% | — | Wpestate WpresidenceAI | 29/10/2025 | 17/6/2026 | Missing Authorization vulnerability in WpEstate wpresidence wpresidence allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects wpresidence: from n/a through <= 5.3.2. | |
| Aplazada | Media (6.5) | 0.21% | — | Rameez Iqbal Real Estate ManagerAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows DOM-Based XSS.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Aplazada | Alta (7.1) | 0.25% | — | Vizly WEB Design Real Estate PackagesAI | 19/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Vizly Web Design Real Estate Packages allows Content Spoofing, CAPEC - 593 - Session Hijacking, CAPEC - 591 - Reflected XSS. This issue affects Real Estate Packages: before 5.1. | |
| Analizada | Baja (2.1) | 0.49% | — | Codeastro Real Estate Management System | 4/9/2025 | 17/6/2026 | A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /submitproperty.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Baja (2.1) | 0.49% | — | Codeastro Real Estate Management System | 4/9/2025 | 17/6/2026 | A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /register.php. Executing manipulation of the argument uimage can lead to unrestricted upload. The attack can be launched remotely. The exploit has been published and may be used. | |
| Analizada | Baja (2) | 0.29% | — | Codeastro Real Estate Management System | 4/9/2025 | 17/6/2026 | A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the file /feature.php. Performing manipulation of the argument msg results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. | |
| Analizada | Baja (2) | 0.24% | — | Codeastro Real Estate Management System | 4/9/2025 | 17/6/2026 | A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an unknown function of the file /propertyview.php. Such manipulation of the argument msg leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed… | |
| Analizada | Media (5.5) | 0.61% | — | Scriptandtools Real Estate Management System | 3/9/2025 | 17/6/2026 | A security vulnerability has been detected in ScriptAndTools Real Estate Management System 1.0. The affected element is an unknown function of the file /admin/userlist.php. Such manipulation leads to execution after redirect. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. | |
| Analizada | Baja (2.1) | 0.40% | — | Scriptandtools Real Estate Management System | 3/9/2025 | 17/6/2026 | A weakness has been identified in ScriptAndTools Real Estate Management System 1.0. Impacted is an unknown function of the file register.php. This manipulation of the argument uimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could… | |
| Aplazada | Alta (7.1) | 0.25% | — | Webcodingplace Real-estate-manager-proAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Real Estate Manager Pro real-estate-manager-pro allows Reflected XSS.This issue affects Real Estate Manager Pro: from n/a through <= 12.7.3. | |
| Aplazada | Media (6.5) | 0.21% | — | Wpestate WP RentalsAI | 14/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpEstate WP Rentals wprentals allows Stored XSS.This issue affects WP Rentals: from n/a through <= 3.16.1. | |
| Aplazada | Media (4.3) | 0.26% | — | Sminozzi Real Estate Property 2024 Create Your OWN Fields AND Search BARAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in sminozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin real-estate-right-now allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugin: from n/a… | |
| Aplazada | Alta (8.8) | 0.81% | — | Home Villas Real Estate Wordpress ThemeAI | 2/7/2025 | 17/6/2026 | The Home Villas | Real Estate WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'wp_rem_cs_widget_file_delete' function in all versions up to, and including, 2.8. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Aplazada | Crítica (9.8) | 26% | 💥 Exploit | Opal Estate PROAI | 1/7/2025 | 17/6/2026 | The Opal Estate Pro – Property Management and Submission plugin for WordPress, used by the FullHouse - Real Estate Responsive WordPress Theme, is vulnerable to privilege escalation via in all versions up to, and including, 1.7.5. This is due to a lack of role restriction during registration in the 'on_regiser_user'… | |
| Aplazada | Alta (8.8) | 0.19% | — | Rameez Iqbal Real Estate ManagerAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Privilege Escalation.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Aplazada | Media (6.5) | 0.18% | — | Rameez Iqbal Real Estate ManagerAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Cross Site Request Forgery.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Analizada | Baja (2.1) | 0.52% | — | Scriptandtools Real Estate Management System | 20/6/2025 | 17/6/2026 | A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file userdelete.php of the component User Delete Handler. The manipulation of the argument ID leads to authorization bypass. The attack may be initiated… | |
| Analizada | Alta (8.1) | 0.40% | — | Updategadh Real Estate Management | 18/6/2025 | 17/6/2026 | Real Estate Management 1.0 is vulnerable to Cross Site Scripting (XSS) in /store/index.php. | |
| Aplazada | Alta (8.8) | 7.0% | 💥 PoC | Inspiry RH Real EstateAI | 10/6/2025 | 17/6/2026 | The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to the theme not properly restricting user roles that can be updated as part of the inspiry_update_profile() function. This makes it possible for authenticated… | |
| Modificada | Crítica (9.8) | 0.57% | — | G5plus Essential Real Estate | 9/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows PHP Local File Inclusion.This issue affects Essential Real Estate: from n/a through <= 5.2.9. | |
| Analizada | Media (5.5) | 0.58% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Admin/EditCity.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /Admin/InsertCity.php. The manipulation of the argument cmbState leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Real Estate Property Management System 1.0. This issue affects some unknown processing of the file /Admin/InsertState.php. The manipulation of the argument txtStateName leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0. This vulnerability affects unknown code of the file /Admin/InsertCategory.php. The manipulation of the argument txtCategoryName leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.49% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /Admin/NewsReport.php. The manipulation of the argument txtFrom leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… |