Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.52% | — | Codeastro Real Estate Management System | 10/11/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Real Estate Management System up to 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /aboutedit.php of the component About Us Page. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The… | |
| Analizada | Media (5.1) | 0.58% | — | Codeastro Real Estate Management System | 8/11/2024 | 17/6/2026 | A vulnerability classified as problematic was found in CodeAstro Real Estate Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /aboutedit.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload. The attack can be launched… | |
| Analizada | Media (5.1) | 0.58% | — | Codeastro Real Estate Management System | 8/11/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the file /aboutadd.php of the component About Us Page. The manipulation of the argument aimage leads to unrestricted upload. It is possible to launch the attack remotely. The… | |
| Analizada | Media (4.3) | 0.23% | — | Realestateconnected Easy Property Listings | 12/9/2024 | 17/6/2026 | The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack | |
| Aplazada | Media (5.1) | 0.35% | — | Ingenico Estate ManagerAI | 30/6/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Ingenico Estate Manager 2023. Affected by this vulnerability is an unknown functionality of the file /emgui/rest/preferences/PREF_HOME_PAGE/sponsor/3/ of the component New Widget Handler. The manipulation of the argument URL leads to cross site scripting. The… | |
| Modificada | Media (5.1) | 0.41% | — | Ingenico Estate Management | 17/6/2024 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Ingenico Estate Manager 2023. This issue affects some unknown processing of the file /emgui/rest/ums/messages of the component News Feed. The manipulation of the argument message leads to cross site scripting. The attack may be initiated remotely.… | |
| Modificada | Media (6.9) | 0.61% | — | Angeljudesuarez Real Estate Management System | 17/6/2024 | 17/6/2026 | A vulnerability was found in itsourcecode Real Estate Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file property-detail.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.36% | — | Realestateconnected Easy Property Listings | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Merv Barrett Easy Property Listings.This issue affects Easy Property Listings: from n/a through 3.5.3. | |
| Modificada | Media (4.3) | 0.46% | — | G5plus Essential Real Estate | 4/6/2024 | 17/6/2026 | The Essential Real Estate plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation on the remove_property_attachment_ajax() function in all versions up to, and including, 4.4.2. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete… | |
| Modificada | Media (5.4) | 0.32% | — | G5plus Essential Real Estate | 4/6/2024 | 17/6/2026 | The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ere_property_map' shortcode in all versions up to, and including, 4.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.26% | — | Opal Estate PROAI | 22/5/2024 | 17/6/2026 | The Opal Estate Pro – Property Management and Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the agent latitude and longitude parameters in all versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Modificada | Alta (8.8) | 0.77% | — | Realestateconnected Easy Property Listings | 9/4/2024 | 17/6/2026 | The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, 3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Analizada | Media (5.4) | 0.57% | — | Codeastro Real Estate Management System | 31/1/2024 | 17/6/2026 | A vulnerability was found in CodeAstro Real Estate Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file profile.php of the component Feedback Form. The manipulation of the argument Your Feedback with the input <img src=x… | |
| Modificada | Alta (7.5) | 0.50% | — | Codeastro Real Estate Management System | 15/1/2024 | 17/6/2026 | A vulnerability classified as critical has been found in CodeAstro Real Estate Management System up to 1.0. This affects an unknown part of the file propertydetail.php. The manipulation of the argument pid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Media (5.4) | 0.40% | — | G5plus Essential Real Estate | 8/1/2024 | 17/6/2026 | The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Stored XSS attacks. | |
| Modificada | Alta (8.8) | 1.1% | — | G5plus Essential Real Estate | 8/1/2024 | 17/6/2026 | The Essential Real Estate WordPress plugin before 4.4.0 does not prevent users with limited privileges on the site, like subscribers, from momentarily uploading malicious PHP files disguised as ZIP archives, which may lead to remote code execution. | |
| Modificada | Media (6.5) | 0.61% | — | G5plus Essential Real Estate | 8/1/2024 | 17/6/2026 | The Essential Real Estate WordPress plugin before 4.4.0 does not apply proper capability checks on its AJAX actions, which among other things, allow attackers with a subscriber account to conduct Denial of Service attacks. | |
| Modificada | Alta (8.8) | 1.3% | — | G5plus Essential Real Estate | 15/12/2023 | 17/6/2026 | The Essential Real Estate plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation on the 'ajaxUploadFonts' function in versions up to, and including, 4.3.5. This makes it possible for authenticated attackers with subscriber-level capabilities or above, to upload arbitrary… | |
| Modificada | Crítica (9.8) | 0.65% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 26/10/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Simple Real Estate Portal System 1.0. It has been classified as critical. Affected is an unknown function of the file view_estate.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.5) | 0.75% | — | Webcodingplace Real Estate Manager | 9/8/2023 | 17/6/2026 | The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role… | |
| Modificada | Media (5.3) | 0.73% | — | Wpopal Opal Estate | 1/7/2023 | 17/6/2026 | The Opal Estate plugin for WordPress is vulnerable to featured property modifications in versions up to, and including, 1.6.11. This is due to missing capability checks on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated attackers to… | |
| Modificada | Alta (8.8) | 0.58% | — | Wpopal Opal Estate | 1/7/2023 | 17/6/2026 | The Opal Estate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.11. This is due to missing or incorrect nonce validation on the opalestate_set_feature_property() and opalestate_remove_feature_property() functions. This makes it possible for unauthenticated… | |
| Modificada | Alta (8.8) | 0.91% | — | E-plugins Directory PROE-plugins Final UserE-plugins Fitness TrainerE-plugins Hospital & Doctor Directory+7 | 27/3/2023 | 17/6/2026 | The directory-pro WordPress plugin before 1.9.5, final-user-wp-frontend-user-profiles WordPress plugin before 1.2.2, producer-retailer WordPress plugin through TODO, photographer-directory WordPress plugin before 1.0.9, real-estate-pro WordPress plugin before 1.7.1, institutions-directory WordPress plugin before… | |
| Modificada | Media (6.1) | 0.38% | — | Contempothemes Real Estate 7 | 27/3/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Contempoinc Real Estate 7 WordPress theme <= 3.3.1 versions. | |
| Modificada | Media (5.4) | 0.88% | 💥 Exploit | G5theme Essential Real Estate | 12/12/2022 | 17/6/2026 | The Essential Real Estate WordPress plugin before 3.9.6 does not sanitize and escapes some parameters, which could allow users with a role as low as Admin to perform Cross-Site Scripting attacks. |