Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
200 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.59% | — | Simple Real Estate Pack Project Simple Real Estate Pack | 30/5/2022 | 17/6/2026 | The Simple Real Estate Pack WordPress plugin through 1.4.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks when the unfiltered_html capability is disallowed | |
| Modificada | Crítica (9.8) | 1.5% | — | Simple Real Estate Portal System Portal Simple Real Estate Portal System | 21/4/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent. | |
| Modificada | Crítica (9.8) | 1.5% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 21/4/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent. | |
| Modificada | Crítica (9.8) | 1.3% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 21/4/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_estate. | |
| Modificada | Crítica (9.8) | 1.3% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 21/4/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type. | |
| Modificada | Crítica (9.8) | 1.2% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 21/4/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity. | |
| Modificada | Crítica (9.8) | 1.2% | — | Simple Real Estate Portal System Project Simple Real Estate Portal System | 2/3/2022 | 17/6/2026 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Contempothemes Real Estate 7 | 6/7/2021 | 17/6/2026 | The WP Pro Real Estate 7 WordPress theme before 3.1.1 did not properly sanitise the ct_community parameter in its search listing page before outputting it back in it, leading to a reflected Cross-Site Scripting which can be triggered in both unauthenticated or authenticated user context | |
| Modificada | Alta (7.2) | 1.0% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 5/1/2020 | 17/6/2026 | In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injection. | |
| Modificada | Media (6.1) | 0.70% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 5/1/2020 | 17/6/2026 | In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS. | |
| Modificada | Media (5.3) | 1.5% | — | Open Source Real-estate Script Project Open Source Real-estate Script | 4/10/2018 | 17/6/2026 | PHP Scripts Mall Open Source Real-estate Script 3.6.2 allows remote attackers to list the wp-content/themes/template_dp_dec2015/img directory. | |
| Modificada | Media (5.4) | 0.55% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 10/8/2018 | 17/6/2026 | PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile. | |
| Modificada | Media (6.5) | 0.94% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 10/8/2018 | 17/6/2026 | PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure loss) via crafted JavaScript code in the Name field of a profile. | |
| Modificada | Alta (8) | 0.45% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 10/8/2018 | 17/6/2026 | PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php. | |
| Modificada | Crítica (9.8) | 2.0% | 💥 Exploit | OS Property Real Estate Project OS Property Real Estate | 22/2/2018 | 17/6/2026 | SQL Injection exists in the OS Property Real Estate 3.12.7 component for Joomla! via the cooling_system1, heating_system1, or laundry parameter. | |
| Modificada | Media (5.4) | 0.54% | — | Multilanguage Real Estate MLM Script Project Multilanguage Real Estate MLM Script | 7/2/2018 | 17/6/2026 | PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Multilanguage Real Estate MLM Script Project Multilanguage Real Estate MLM Script | 29/1/2018 | 17/6/2026 | SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter. | |
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/eventlist.php cast parameter. | |
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter. | |
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/newsedit.php newstitle parameter. | |
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/snacks_edit.php snacks_name parameter. | |
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/manageownerlist.php contact parameter. | |
| Modificada | Media (6.8) | 0.40% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has CSRF via admin/movieedit.php. | |
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/sitesettings.php keyword parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Advanced Real Estate Script Project Advanced Real Estate Script | 13/12/2017 | 17/6/2026 | Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. |