Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
200 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.60% | — | Smartdatasoft Essential WP Real Estate | 3/2/2025 | 17/6/2026 | The Essential WP Real Estate WordPress plugin through 1.1.3 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting. | |
| Modificada | Media (4.3) | 0.22% | — | G5plus Essential Real Estate | 24/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in g5theme Essential Real Estate essential-real-estate allows Cross Site Request Forgery.This issue affects Essential Real Estate: from n/a through <= 5.1.8. | |
| Aplazada | Crítica (9.8) | 0.55% | — | Inspiyrthemes Easy Real EstateAI | 21/1/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in InspiryThemes Easy Real Estate easy-real-estate allows Privilege Escalation.This issue affects Easy Real Estate: from n/a through <= 2.2.9. | |
| Analizada | Media (5.3) | 0.34% | — | Smartdatasoft Essential WP Real Estate | 10/1/2025 | 17/6/2026 | The Essential WP Real Estate plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the cl_delete_listing_func() function in all versions up to, and including, 1.1.3. This makes it possible for unauthenticated attackers to delete arbitrary pages and posts. | |
| Aplazada | Media (6.4) | 0.34% | — | Simplyrets Real Estate IDXAI | 9/1/2025 | 17/6/2026 | The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_search_form' shortcode in all versions up to, and including, 2.11.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (4.3) | 0.36% | — | G5plus Essential Real Estate | 12/12/2024 | 17/6/2026 | The Essential Real Estate plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on several pages/post types in all versions up to, and including, 5.1.6. This makes it possible for authenticated attackers, with Contributor-level access and above, to access invoices and… | |
| Aplazada | Media (4.3) | 0.38% | — | Wpdirectorykit Real Estate DirectoryAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in wpdirectorykit.com Real Estate Directory allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Real Estate Directory: from n/a through 1.0.5. | |
| Analizada | Media (5.1) | 0.52% | — | Codeastro Real Estate Management System | 10/11/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Real Estate Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /aboutedit.php of the component About Us Page. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The… | |
| Analizada | Media (5.1) | 0.58% | — | Codeastro Real Estate Management System | 8/11/2024 | 17/6/2026 | A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /aboutedit.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload. The attack can be launched… | |
| Analizada | Media (5.1) | 0.58% | — | Codeastro Real Estate Management System | 8/11/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /aboutadd.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload. It is possible to launch the attack remotely. The… | |
| Modificada | Media (6.9) | 0.61% | — | Angeljudesuarez Real Estate Management System | 17/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file property-detail.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Modificada | Media (4.3) | 0.46% | — | G5plus Essential Real Estate | 4/6/2024 | 17/6/2026 | The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation on the remove_property_attachment_ajax() function in all versions up to, and including, 4.4.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete… | |
| Modificada | Media (5.4) | 0.32% | — | G5plus Essential Real Estate | 4/6/2024 | 17/6/2026 | The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ere_property_map' shortcode in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Analizada | Media (5.4) | 0.57% | — | Codeastro Real Estate Management System | 31/1/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file profile.php of the component Feedback Form. The manipulation of the argument Your Feedback with the input <img src=x… | |
| Modificada | Alta (7.5) | 0.50% | — | Codeastro Real Estate Management System | 15/1/2024 | 17/6/2026 | A vulnerability classified as critical has been found in CodeAstro Real Estate Management System up to 1.0. This affects an unknown part of the file propertydetail.php. The manipulation of the argument pid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (5.4) | 0.40% | — | G5plus Essential Real Estate | 8/1/2024 | 17/6/2026 | The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks. | |
| Modificada | Alta (8.8) | 1.1% | — | G5plus Essential Real Estate | 8/1/2024 | 17/6/2026 | The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution. | |
| Modificada | Media (6.5) | 0.61% | — | G5plus Essential Real Estate | 8/1/2024 | 17/6/2026 | The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks. | |
| Modificada | Alta (8.8) | 1.3% | — | G5plus Essential Real Estate | 15/12/2023 | 17/6/2026 | The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFonts' function in versions up to, and including, 4.3.5. This makes it possible for authenticated attackers with subscriber-level capabilities or above, to upload arbitrary… | |
| Modificada | Crítica (9.8) | 0.65% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 26/10/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Real Estate Portal System 1.0. It has been classified as critical. Affected is an unknown function of the file view_estate.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.5) | 0.75% | — | Webcodingplace Real Estate Manager | 9/8/2023 | 17/6/2026 | The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role… | |
| Modificada | Alta (8.8) | 0.91% | — | E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+7 | 27/3/2023 | 17/6/2026 | The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before… | |
| Modificada | Media (6.1) | 0.38% | — | Contempothemes Real Estate 7 | 27/3/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions. | |
| Modificada | Media (5.4) | 0.88% | 💥 Exploit | G5theme Essential Real Estate | 12/12/2022 | 17/6/2026 | The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks. | |
| Modificada | Crítica (9.8) | 1.1% | — | Itechscripts Real Estate Script | 16/7/2022 | 17/6/2026 | A vulnerability was found in Itech Real Estate Script 3.12. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /real-estate-script/search_property.php. The manipulation of the argument property_for leads to sql injection. The attack can be launched remotely. The… |