Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
200 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.19% | — | Rameez Iqbal Real Estate ManagerAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Privilege Escalation.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Aplazada | Media (6.5) | 0.18% | — | Rameez Iqbal Real Estate ManagerAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Cross Site Request Forgery.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Analizada | Baja (2.1) | 0.52% | — | Scriptandtools Real Estate Management System | 20/6/2025 | 17/6/2026 | A vulnerability was found in ScriptAndTools Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file userdelete.php of the component User Delete Handler. The manipulation of the argument ID leads to authorization bypass. The attack may be initiated… | |
| Analizada | Alta (8.1) | 0.40% | — | Updategadh Real Estate Management | 18/6/2025 | 17/6/2026 | Real Estate Management 1.0 is vulnerable to Cross Site Scripting (XSS) in /store/index.php. | |
| Aplazada | Alta (8.8) | 7.0% | 💥 PoC | Inspiry RH Real EstateAI | 10/6/2025 | 17/6/2026 | The "RH - Real Estate WordPress Theme" theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.4.0. This is due to the theme not properly restricting user roles that can be updated as part of the inspiry_update_profile() function. This makes it possible for authenticated… | |
| Modificada | Crítica (9.8) | 0.57% | — | G5plus Essential Real Estate | 9/6/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in g5theme Essential Real Estate essential-real-estate allows PHP Local File Inclusion.This issue affects Essential Real Estate: from n/a through <= 5.2.9. | |
| Analizada | Media (5.5) | 0.58% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Admin/EditCity.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /Admin/InsertCity.php. The manipulation of the argument cmbState leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Real Estate Property Management System 1.0. This issue affects some unknown processing of the file /Admin/InsertState.php. The manipulation of the argument txtStateName leads to sql injection. The attack may be initiated remotely. The… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in code-projects Real Estate Property Management System 1.0. This vulnerability affects unknown code of the file /Admin/InsertCategory.php. The manipulation of the argument txtCategoryName leads to sql injection. The attack can be initiated remotely. The exploit has… | |
| Analizada | Media (5.5) | 0.49% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /Admin/NewsReport.php. The manipulation of the argument txtFrom leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.51% | — | Fabian Real Estate Property Management System | 6/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /Admin/Property.php. The manipulation of the argument cmbCat leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (5.5) | 0.48% | — | Fabian Real Estate Property Management System | 5/6/2025 | 17/6/2026 | A vulnerability was found in code-projects Real Estate Property Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /Admin/User.php. The manipulation of the argument txtUserName leads to sql injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.45% | — | Codeastro Real Estate Management System | 4/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in CodeAstro Real Estate Management System 1.0. This affects an unknown part of the file /submitpropertyupdate.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.52% | — | Codeastro Real Estate Management System | 4/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in CodeAstro Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file /submitpropertydelete.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.55% | — | Codeastro Real Estate Management System | 4/6/2025 | 17/6/2026 | A vulnerability classified as critical has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /register.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.3) | 0.52% | — | Codeastro Real Estate Management System | 4/6/2025 | 17/6/2026 | A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument content leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.58% | — | Codeastro Real Estate Management System | 4/6/2025 | 17/6/2026 | A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument User leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (6.9) | 0.58% | — | Codeastro Real Estate Management System | 4/6/2025 | 17/6/2026 | A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been classified as critical. This affects an unknown part of the file /login.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.60% | — | Scriptandtools Real Estate Management System | 24/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in ScriptAndTools Real-Estate-website-in-PHP 1.0. Affected is an unknown function of the file /admin/ of the component Admin Login Panel. The manipulation of the argument Password leads to sql injection. It is possible to launch the attack remotely. The… | |
| Aplazada | Alta (7.3) | 0.38% | 💥 PoC | Contempoinc Real EstateAI | 19/5/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in contempoinc Real Estate 7 realestate-7 allows Privilege Escalation.This issue affects Real Estate 7: from n/a through <= 3.5.2. | |
| Aplazada | Media (5.1) | 0.21% | — | Real Estate Management SystemAI | 6/5/2025 | 17/6/2026 | Real Estate Management System v1.0 was discovered to contain a SQL injection vulnerability via the message parameter at /contact.php. | |
| Aplazada | Media (5.3) | 0.29% | — | Reales WP Real Estate Wordpress ThemeAI | 24/4/2025 | 17/6/2026 | The Reales WP - Real Estate WordPress Theme theme for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'reales_delete_file', 'reales_delete_file_plans', 'reales_add_to_favourites', and 'reales_remove_from_favourites' functions in all versions up to, and… | |
| Aplazada | Alta (7.3) | 0.37% | — | Rameez Iqbal Real Estate ManagerAI | 17/4/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Code Injection.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Aplazada | Alta (7.1) | 0.23% | — | Reichertbrothers Simplyrets Real Estate IDXAI | 15/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ReichertBrothers SimplyRETS Real Estate IDX simply-rets allows Reflected XSS.This issue affects SimplyRETS Real Estate IDX: from n/a through <= 3.2.2. |