Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.31% | — | Realestateconnected Easy Property Listings | 15/5/2025 | 17/6/2026 | The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Aplazada | Media (6.5) | 0.32% | — | Wp-property-hive PropertyhiveAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Stored XSS.This issue affects PropertyHive: from n/a through <= 2.1.2. | |
| Aplazada | Alta (7.5) | 0.60% | — | Wp-property-hive Houzez Property FeedAI | 1/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Property Hive Houzez Property Feed houzez-property-feed allows Path Traversal.This issue affects Houzez Property Feed: from n/a through <= 2.5.4. | |
| Analizada | Media (5.3) | 0.44% | — | Fabian Real Estate Property Management System | 17/3/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /InsertFeedback.php. The manipulation of the argument txtName/txtEmail/txtMobile/txtFeedback leads to sql injection. It is possible to launch the attack… | |
| Analizada | Media (5.3) | 0.44% | — | Fabian Real Estate Property Management System | 17/3/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /InsertCustomer.php of the component Parameter Handler. The manipulation of the argument… | |
| Analizada | Media (5.3) | 0.56% | — | Fabian Real Estate Property Management System | 23/2/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax_state.php. The manipulation of the argument StateName as part of String leads to sql injection. The attack can be launched remotely.… | |
| Analizada | Media (5.3) | 0.56% | — | Code-projects Real Estate Property Management System | 17/2/2025 | 17/6/2026 | A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been classified as critical. This affects an unknown part of the file /ajax_city.php. The manipulation of the argument CityName leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.54% | — | Code-projects Real Estate Property Management System | 17/2/2025 | 17/6/2026 | A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /Admin/CustomerReport.php. The manipulation of the argument city leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (5.3) | 0.45% | — | Fabian Real Estate Property Management System | 17/2/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /search.php. The manipulation of the argument StateName/CityName/AreaName/CatId leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Media (5.3) | 0.45% | — | Fabian Real Estate Property Management System | 12/2/2025 | 17/6/2026 | A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /_parse/load_user-profile.php. The manipulation of the argument userhash leads to sql injection. The attack can be launched… | |
| Analizada | Media (5.1) | 0.37% | — | Fabian Real Estate Property Management System | 12/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /search.php. The manipulation of the argument PropertyName leads to cross site scripting. It is possible to launch the attack remotely. The exploit… | |
| Analizada | Media (5.1) | 0.34% | — | Fabian Real Estate Property Management System | 12/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in code-projects Real Estate Property Management System 1.0. This issue affects some unknown processing of the file /Admin/EditCategory. The manipulation of the argument CategoryId leads to cross site scripting. The attack may be initiated remotely.… | |
| Analizada | Media (5.4) | 0.16% | — | Wp-property-hive Houzez Property Feed | 12/2/2025 | 17/6/2026 | The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to missing or incorrect nonce validation on the "deleteexport" action. This makes it possible for unauthenticated attackers to delete property feed exports via a forged… | |
| Analizada | Media (5.1) | 0.42% | — | Fabian Real Estate Property Management System | 11/2/2025 | 17/6/2026 | A vulnerability classified as problematic was found in code-projects Real Estate Property Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /Admin/CustomerReport.php. The manipulation of the argument Address leads to cross site scripting. The attack can be launched remotely.… | |
| Analizada | Media (5.1) | 0.40% | — | Fabian Real Estate Property Management System | 11/2/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /Admin/Category.php. The manipulation of the argument Desc leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (6.1) | 0.62% | 💥 Exploit | Wp-property-hive Propertyhive | 8/1/2025 | 17/6/2026 | The Property Hive WordPress plugin before 2.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.4) | 0.31% | — | Propertyhive Stamp Duty CalculatorAI | 13/12/2024 | 17/6/2026 | The Property Hive Stamp Duty Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stamp_duty_calculator_scotland' shortcode in all versions up to, and including, 1.0.22 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it… | |
| Aplazada | Alta (7.1) | 0.27% | — | Chris Gipple PropertyshiftAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris Gipple PropertyShift propertyshift allows Reflected XSS.This issue affects PropertyShift: from n/a through <= 1.0.0. | |
| Analizada | Media (4.3) | 0.39% | — | Wp-property-hive Propertyhive | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in PropertyHive PropertyHive allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PropertyHive: from n/a through 2.0.9. | |
| Modificada | Alta (8.8) | 0.49% | — | Myriadsolutionz Property LOT Management System | 20/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Myriad Solutionz Property Lot Management System plms allows Upload a Web Shell to a Web Server.This issue affects Property Lot Management System: from n/a through <= 4.2.38. | |
| Aplazada | Crítica (9.8) | 0.68% | — | Changate Property Management SystemAI | 15/10/2024 | 17/6/2026 | Property Management System from ChanGate has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Media (6.5) | 0.35% | — | Wp-property-hive Propertyhive | 17/9/2024 | 17/6/2026 | The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.19. This is due to missing or incorrect nonce validation on the 'save_account_details' function. This makes it possible for unauthenticated attackers to edit the name, email address, and password… | |
| Analizada | Media (4.3) | 0.23% | — | Realestateconnected Easy Property Listings | 12/9/2024 | 17/6/2026 | The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack | |
| Analizada | Media (5.3) | 0.48% | — | Adonesevangelista Laravel Property Management System | 20/8/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/notes/create of the component Notes Page. The manipulation of the argument Note text leads to cross site scripting. The… | |
| Analizada | Media (5.3) | 0.52% | — | Adonesevangelista Laravel Property Management System | 20/8/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Laravel Property Management System 1.0. It has been classified as critical. Affected is the function UpdateDocumentsRequest of the file DocumentsController.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been… |