Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
74 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Realtywebware Realty Web-base | 18/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user (username) and (2) password parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Aspsiteware Realtylistings | 30/12/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in ASPSiteWare RealtyListings 1.0 and 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) iType parameter to type.asp and the (2) iPro parameter to detail.asp. | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Phprealty | 19/9/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remote attackers to execute arbitrary PHP code via a URL in the INC parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Phpmyrealty | 29/8/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the id parameter in pages.php and (2) the price_max parameter in search.php. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Ypninc PHP Realty | 14/8/2008 | 16/6/2026 | SQL injection vulnerability in dpage.php in YPN PHP Realty allows remote attackers to execute arbitrary SQL commands via the docID parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Phpmyrealty | 4/8/2008 | 16/6/2026 | SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL commands via the location parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Emophp EMO Realty Manager | 16/5/2008 | 16/6/2026 | SQL injection vulnerability in news.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands via the ida parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Phpmyrealty | 20/12/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL commands via the type parameter to search.php and (2) remote authenticated administrators to execute arbitrary SQL commands via the listing_updated_days parameter to admin/findlistings.php. NOTE: some… | |
| Modificada | Alta (7.5) | 1.0% | — | Gouae DWD Realty | 29/11/2007 | 16/6/2026 | SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the uname parameter, a different vector than CVE-2007-6163. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Gouae DWD Realty | 29/11/2007 | 16/6/2026 | SQL injection vulnerability in admin/index2.asp in GOUAE DWD Realty allows remote attackers to execute arbitrary SQL commands via the pword (aka Password) parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 28% | 💥 Exploit | Adodb LiteCmsmadesimple CMS Made SimpleJournalnessOpen-realty+2 | 24/9/2007 | 16/6/2026 | Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including CMS Made Simple, SAPID CMF, Journalness, PacerCMS, and Open-Realty, allows remote attackers to execute arbitrary code via PHP sequences in the last_module parameter. | |
| Modificada | Alta (7.5) | 59% | 💥 Exploit | Phprealty | 12/9/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR parameter to (1) index.php, (2) p_ins.php, and (3) u_ins.php in manager/admin/. | |
| Modificada | Media (5) | 1.1% | — | Open-realty | 25/1/2007 | 16/6/2026 | index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Klf-design Klf-realty | 7/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in KLF-DESIGN (aka Kim L. Fraser) KLF-REALTY allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) agent parameters in (a) search_listing.asp, and the (3) property_id parameter in (b) detail.asp. | |
| Analizada | Alta (7.5) | 2.1% | — | Abarcar Realty Portal | 10/11/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in Abarcar Realty Portal allow remote attackers to execute arbitrary SQL commands via the (1) neid parameter to newsdetails.php, or the (2) slid parameter to slistl.php. NOTE: the cat vector is already covered by CVE-2006-2853. NOTE: the vendor has notified CVE that the current… | |
| Modificada | Media (5) | 1.2% | — | Free Realty | 22/6/2006 | 16/6/2026 | Free Realty before 2.9 allows remote attackers to obtain the full path and other sensitive information via unspecified manipulations that produce an error message. | |
| Modificada | Alta (7.5) | 1.3% | — | Open-realty | 22/6/2006 | 16/6/2026 | SQL injection vulnerability, possibly in search.inc.php, in Open-Realty 2.3.1 allows remote attackers to execute arbitrary SQL commands via the sorttype parameter to index.php. | |
| Modificada | Media (4.3) | 0.94% | — | Free Realty | 22/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in propview.php in Free Realty 2.9-0.6 and earlier allows remote attackers to execute arbitrary web script or HTML via the sort parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Free Realty | 22/6/2006 | 16/6/2026 | SQL injection vulnerability in propview.php in Free Realty 2.9-0.7 and earlier allows remote attackers to execute arbitrary SQL commands via the sort parameter. | |
| Modificada | Baja (2.6) | 1.2% | — | Cescripts Realty Home Rent | 15/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Home Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this script and others at cescripts.com have been addressed and fixed." | |
| Modificada | Baja (2.6) | 1.2% | — | Cescripts Realty Room Rent | 15/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Cescripts Realty Room Rent allows remote attackers to inject arbitrary web script or HTML via the sel_menu parameter. NOTE: the vendor notified CVE on 20060823 that "All issues concerning this script and others at cescripts.com have been addressed and fixed." | |
| Modificada | Media (4.3) | 3.9% | 💥 Exploit | Baby Katie Media Very Simple CAR ListerBaby Katie Media Very Simple Realty Lister | 13/6/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) very simple Realty Lister (vsREAL) 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) lid parameter in index.php and the (2) title parameter in myslideshow.php. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Abarcar Realty Portal | 6/6/2006 | 16/6/2026 | SQL injection vulnerability in content.php in abarcar Realty Portal 5.1.5 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Media (6.8) | 1.6% | — | Interquest Internet Services Realty PRO ONE | 30/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Realty Pro One allow remote attackers to inject arbitrary web script or HTML via the (1) listingid parameter to (a) images.php, (b) index_other.php, or (c) request_info.php; (2) propertyid parameter to (d) searchlookup.php, (3) id parameter to (e) images.php, or… |