Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

171 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.7)1.4%—Oracle Hospitality Opera 5 Property Services25/10/201617/6/2026
Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote authenticated users to affect confidentiality via vectors related to OPERA.
ModificadaAlta (7.4)1.2%—Oracle Hospitality Opera 5 Property Services25/10/201617/6/2026
Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to OPERA.
ModificadaAlta (7.9)1.1%—Oracle Hospitality Opera 5 Property Services25/10/201617/6/2026
Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote administrators to affect confidentiality, integrity, and availability via vectors related to OPERA.
ModificadaMedia (5.4)0.27%—Userfriendlymedia Mills-hazel Property Mgmt21/10/201417/6/2026
The Mills-Hazel Property Mgmt (aka com.appexpress.millshazelpropertymanagement) application 3.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)0.98%💥 ExploitMicronetsoft Rental Property Website8/10/201116/6/2026
SQL injection vulnerability in detail.asp in Micronetsoft Rental Property Management Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ad_ID parameter.
ModificadaAlta (7.5)16%💥 ExploitCom-property COM Properties12/5/201016/6/2026
Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third…
ModificadaAlta (7.5)2.0%💥 ExploitCom-property COM Properties12/5/201016/6/2026
SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.2%💥 ExploitThethinkery COM Iproperty4/5/201016/6/2026
SQL injection vulnerability in the Intellectual Property (aka IProperty or com_iproperty) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an agentproperties action to index.php.
ModificadaMedia (4.3)1.3%💥 ExploitPropertywatchscript Property Watch3/9/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PropertyWatchScript.com Property Watch 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) videoid parameter to tools/email.php and (2) redirect parameter to tools/login.php.
ModificadaMedia (4.3)1.5%💥 ExploitZeeways Zeeproperty7/8/200916/6/2026
Cross-site scripting (XSS) vulnerability in view_prop_details.php in Zeeways ZEEPROPERTY 1.0 allows remote attackers to inject arbitrary web script or HTML via the propid parameter.
ModificadaMedia (6.5)3.1%💥 ExploitZeeways Zeeproperty7/8/200916/6/2026
Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile modification, then accessing a related file via a direct request to the file in companylogo/.
ModificadaMedia (6.8)0.89%💥 ExploitPropertymaxpro Propertymax PRO Free5/6/200916/6/2026
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaMedia (4.3)1.3%💥 ExploitPropertymaxpro Propertymax PRO Free5/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbitrary web script or HTML via the pl parameter in a mi action.
ModificadaAlta (7.5)1.2%💥 ExploitZeescripts Zeeproperty21/10/200816/6/2026
SQL injection vulnerability in bannerclick.php in ZeeScripts Zeeproperty allows remote attackers to execute arbitrary SQL commands via the adid parameter.
ModificadaMedia (6.8)2.2%💥 ExploitRomedchim International SRL Online Rent Property Script14/5/200816/6/2026
SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter. NOTE: it was later reported that 5.0 and earlier are also affected.
ModificadaAlta (7.5)1.0%—Iexpress Property PRO25/7/200716/6/2026
SQL injection vulnerability in vir_login.asp in iExpress Property Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the Username parameter is covered by CVE-2006-6029. NOTE: the provenance of this information is unknown; the details are obtained solely from third party…
ModificadaMedia (6.8)1.8%💥 ExploitMginternet Property Site Manager23/12/200616/6/2026
Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet Property Site Manager allows remote attackers to inject arbitrary web script or HTML via the s parameter.
ModificadaAlta (7.5)1.1%💥 ExploitMginternet Property Site Manager23/12/200616/6/2026
Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some…
ModificadaAlta (7.5)1.2%💥 ExploitProperty PRO21/11/200616/6/2026
SQL injection vulnerability in vir_Login.asp in Property Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the UserName field.
ModificadaMedia (5)1.4%—Widget Press Widget PropertyAI5/12/200516/6/2026
property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value, which leaks the path in the resulting error message.
ModificadaAlta (7.5)1.1%💥 ExploitWidget Press Widget Property5/12/200516/6/2026
SQL injection vulnerability in Widget Property 1.1.19 allows remote attackers to execute arbitrary SQL commands via the (1) property_id, (2) zip_code, (3) property_type_id, (4) price, and (5) city_id parameters to property.php.