Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.73% | — | Phpjabbers Yacht Listing Script | 10/8/2023 | 17/6/2026 | An information leak in PHPJabbers Yacht Listing Script v1.0 allows attackers to export clients' credit card numbers from the Reservations module. | |
| Modificada | Alta (7.5) | 46% | 💥 Exploit | Templatecookie Adlisting | 5/8/2023 | 17/6/2026 | A vulnerability was found in Templatecookie Adlisting 2.14.0. It has been classified as problematic. Affected is an unknown function of the file /ad-list of the component Redirect Handler. The manipulation leads to information disclosure. It is possible to launch the attack remotely. The identifier of this… | |
| Modificada | Crítica (9.8) | 0.50% | — | Phpscriptpoint CAR Listing | 24/7/2023 | 17/6/2026 | A vulnerability was found in phpscriptpoint Car Listing 1.6 and classified as critical. This issue affects some unknown processing of the file /search.php of the component GET Parameter Handler. The manipulation of the argument… | |
| Modificada | Media (6.1) | 0.36% | — | Phpscriptpoint CAR Listing | 24/7/2023 | 17/6/2026 | A vulnerability has been found in phpscriptpoint Car Listing 1.6 and classified as problematic. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument country/state/city leads to cross site scripting. The attack can be initiated remotely. VDB-235210 is the identifier assigned… | |
| Modificada | Media (6.1) | 0.39% | — | Bugfinder Listplace Directory Listing Platform | 22/7/2023 | 17/6/2026 | A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0. It has been classified as problematic. This affects an unknown part of the file /listplace/user/coverPhotoUpdate of the component Photo Handler. The manipulation of the argument user_cover_photo leads to cross site scripting. It is… | |
| Modificada | Media (6.1) | 0.39% | — | Bugfinder Listplace Directory Listing Platform | 22/7/2023 | 17/6/2026 | A vulnerability was found in Bug Finder Listplace Directory Listing Platform 3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /listplace/user/ticket/create of the component HTTP POST Request Handler. The manipulation of the argument message leads to cross site… | |
| Modificada | Crítica (9.8) | 0.87% | — | House Rental AND Property Listing PHP Project House Rental AND Property Listing PHP | 21/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester House Rental and Property Listing System 1.0. Affected is an unknown function of the file btn_functions.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.25% | — | Radiustheme Classified Listing | 18/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <= 2.4.5 versions. | |
| Modificada | Media (5.3) | 0.75% | — | Sourcecodester House Rental AND Property Listing Project House Rental AND Property Listing | 17/7/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester/projectworlds House Rental and Property Listing 1.0. This issue affects some unknown processing of the file /index.php. The manipulation of the argument keywords/location leads to sql injection. The attack may be initiated remotely.… | |
| Modificada | Media (6.1) | 0.51% | — | Gzscripts Property Listing Script | 10/7/2023 | 17/6/2026 | A vulnerability was found in GZ Scripts Property Listing Script 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /preview.php. The manipulation of the argument page/layout/sort_by leads to cross site scripting. The attack may be initiated remotely. The associated identifier… | |
| Modificada | Media (6.1) | 0.51% | — | Gzscripts CAR Listing Script PHP | 10/7/2023 | 17/6/2026 | A vulnerability was found in GZ Scripts Car Listing Script PHP 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file /preview.php. The manipulation of the argument page/sort_by leads to cross site scripting. The attack can be initiated remotely. VDB-233350 is the identifier… | |
| Modificada | Crítica (9.8) | 1.4% | — | Stylemixthemes Ulisting | 7/6/2023 | 17/6/2026 | The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to missing capability checks, and a missing security nonce, in the StmListingSingleLayout::import_new_layout method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any… | |
| Modificada | Crítica (9.8) | 1.4% | — | Stylemixthemes Ulisting | 7/6/2023 | 17/6/2026 | The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and endpoints are accessible to unauthenticated users, lack security nonces, and data is seldom validated. This issue exists in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to conduct… | |
| Modificada | Media (5.3) | 1.0% | — | Stylemixthemes Ulisting | 7/6/2023 | 17/6/2026 | The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability checks, and a missing security nonce, on the UlistingUserRole::save_role_api function in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to arbitrarily delete site posts and… | |
| Modificada | Alta (7.5) | 1.2% | — | Stylemixthemes Ulisting | 7/6/2023 | 17/6/2026 | The uListing plugin for WordPress is vulnerable to Unauthenticated Arbitrary Account Changes in versions up to, and including, 1.6.6. This is due to missing login checks on the stm_listing_profile_edit AJAX action. This makes it possible for unauthenticated attackers to edit any account on the blog, such as changing… | |
| Modificada | Media (5.3) | 0.73% | — | Stylemixthemes Ulisting | 7/6/2023 | 17/6/2026 | The uListing plugin for WordPress is vulnerable to authorization bypass due to missing capability and nonce checks on the UlistingUserRole::save_role_api method in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to remove or add roles, and add capabilities. | |
| Modificada | Crítica (9.8) | 1.4% | — | Stylemixthemes Ulisting | 7/6/2023 | 17/6/2026 | The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated Account Creation in versions up to, and including, 1.6.6. This is due to the stm_listing_register AJAX action function being accessible and taking roles unprotected. This makes it possible for unauthenticated attackers to create… | |
| Modificada | Crítica (9.8) | 1.1% | — | Stylemixthemes Ulisting | 7/6/2023 | 17/6/2026 | The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing capability checks, missing input validation, and a missing security nonce in the stm_update_email_data AJAX action in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to change any… | |
| Modificada | Alta (7.5) | 1.2% | — | Stylemixthemes Ulisting | 7/6/2023 | 17/6/2026 | The uListing plugin for WordPress is vulnerable to generic SQL Injection via the ‘listing_id’ parameter in versions up to, and including, 1.6.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers… | |
| Modificada | Media (5.3) | 0.95% | — | Stylemixthemes Ulisting | 7/6/2023 | 17/6/2026 | The uListing plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the "ulisting/includes/route.php" file on the /1/api/ulisting-user/search REST-API route in versions up to, and including, 1.6.6. This makes it possible for unauthenticated attackers to retrieve the list of all… | |
| Modificada | Media (5.3) | 1.6% | 💥 Exploit | Cridio Listingpro | 7/6/2023 | 17/6/2026 | The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Sensitive Data Exposure in versions before 2.6.1 via the ~/listingpro-plugin/functions.php file. This makes it possible for unauthenticated attackers to extract sensitive data including usernames, full names, email addresses, phone… | |
| Modificada | Crítica (9.8) | 4.3% | 💥 Exploit | Cridio Listingpro | 7/6/2023 | 17/6/2026 | The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary Plugin Installation, Activation and Deactivation in versions before 2.6.1. This is due to a missing capability check on the lp_cc_addons_actions function. This makes it possible for unauthenticated attackers to arbitrarily… | |
| Modificada | Alta (8.8) | 0.25% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions. | |
| Modificada | Media (5.4) | 0.36% | — | Agentevolution Impress Listings | 10/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Agent Evolution IMPress Listings plugin <= 2.6.2 versions. | |
| Modificada | Alta (8.8) | 0.25% | — | Wclovers Frontend Manager FOR Woocommerce Along With Bookings Subscription Listings Compatible | 5/4/2023 | 17/6/2026 | The WCFM Frontend Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.6.0 due to missing nonce checks on various AJAX actions. This makes it possible for unauthenticated attackers to perform a wide variety of actions such as modifying knowledge bases, modifying… |