Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.70% | — | Adonesevangelista Laravel Property Management System | 20/8/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Laravel Property Management System 1.0 and classified as critical. This issue affects the function upload of the file PropertiesController.php. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.36% | — | Realestateconnected Easy Property Listings | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings.This issue affects Easy Property Listings: from n/a through 3.5.3. | |
| Modificada | Media (5.4) | 0.26% | — | Wp-property-hive Propertyhive | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.13. | |
| Modificada | Media (5.4) | 0.33% | — | Wp-property-hive Propertyhive | 6/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Stored XSS.This issue affects PropertyHive: from n/a through 2.0.10. | |
| Modificada | Media (4.3) | 0.61% | — | Wp-property-hive Propertyhive | 2/5/2024 | 17/6/2026 | The PropertyHive plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the delete_key_date() function in all versions up to, and including, 2.0.12. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary posts | |
| Modificada | Alta (8.8) | 0.38% | — | Wp-property-hive Propertyhive | 11/4/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.9. | |
| Modificada | Alta (8.8) | 0.77% | — | Realestateconnected Easy Property Listings | 9/4/2024 | 17/6/2026 | The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, 3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Modificada | Media (6.1) | 0.40% | — | Wp-property-hive Propertyhive | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PropertyHive allows Reflected XSS.This issue affects PropertyHive: from n/a through 2.0.8. | |
| Modificada | Media (6.5) | 0.32% | — | Wp-property-hive Propertyhive | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.6. | |
| Modificada | Crítica (9.8) | 0.52% | — | Wp-property-hive Propertyhive | 12/2/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive: from n/a through 2.0.5. | |
| Modificada | Alta (8.8) | 0.56% | — | Oracle Hospitality Opera 5 Property Services | 17/10/2023 | 17/6/2026 | Vulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality OPERA 5 Property Services.… | |
| Modificada | Alta (8.8) | 0.67% | — | Oracle Hospitality Opera 5 Property Services | 17/10/2023 | 17/6/2026 | Vulnerability in the Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Hospitality OPERA 5 Property Services.… | |
| Modificada | Media (6.1) | 3.1% | 💥 Exploit | Phpjabbers Rental Property Booking Calendar | 3/8/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in PHP Jabbers Rental Property Booking 2.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument index leads to cross site scripting. The attack may be launched remotely. The identifier of this… | |
| Modificada | Crítica (9.8) | 0.87% | — | House Rental AND Property Listing PHP Project House Rental AND Property Listing PHP | 21/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester House Rental and Property Listing System 1.0. Affected is an unknown function of the file btn_functions.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (5.3) | 0.75% | — | Sourcecodester House Rental AND Property Listing Project House Rental AND Property Listing | 17/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester/projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /index.php. The manipulation of the argument keywords/location leads to sql injection. The attack may be initiated remotely.… | |
| Modificada | Media (6.1) | 0.51% | — | Gzscripts Property Listing Script | 10/7/2023 | 17/6/2026 | A vulnerability was found in GZ Scripts Property Listing Script 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /preview.php. The manipulation of the argument page/layout/sort_by leads to cross site scripting. The attack may be initiated remotely. The associated identifier… | |
| Modificada | Crítica (9.8) | 0.75% | — | Property Cloud Platform Management Center Project Property Cloud Platform Management Center | 29/6/2023 | 17/6/2026 | Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection. | |
| Modificada | Media (6.1) | 0.38% | — | Wp-property-hive Propertyhive | 15/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.48 versions. | |
| Modificada | Media (5.4) | 0.64% | — | Personnel Property Equipment System Project Personnel Property Equipment System | 14/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in SourceCodester Personnel Property Equipment System 1.0. Affected is an unknown function of the file admin/add_item.php of the component POST Parameter Handler. The manipulation of the argument item_name leads to cross site scripting. It is possible to… | |
| Modificada | Alta (8.8) | 0.82% | — | Personnel Property Equipment System Project Personnel Property Equipment System | 14/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Personnel Property Equipment System 1.0. This issue affects some unknown processing of the file admin/returned_reuse_form.php of the component GET Parameter Handler. The manipulation of the argument client_id leads to sql injection.… | |
| Modificada | Alta (7.2) | 45% | — | Oracle Hospitality Opera 5 Property Services | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: OXI). The supported version that is affected is 5.6. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property… | |
| Modificada | Media (6.1) | 0.38% | — | Wp-property-hive Propertyhive | 7/4/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in PropertyHive plugin <= 1.5.46 versions. | |
| Modificada | Alta (7.8) | 0.38% | — | Grunt-util-property Project Grunt-util-property | 17/7/2022 | 17/6/2026 | This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload. | |
| Modificada | Alta (7.5) | 73% | 💥 Exploit | Apache TomcatDebian LinuxOracle Hospitality Cruise Shipboard Property Management System | 12/5/2022 | 17/6/2026 | The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and… | |
| Modificada | Media (5.3) | 1.1% | — | Vikwp Vikbooking Hotel Booking Engine & Property Management System Plugin | 19/4/2022 | 17/6/2026 | Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5.3 on WordPress allows attackers to get the booking data by guessing / brute-forcing easy predictable booking IDs via search POST requests. |