Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.7) | 1.4% | — | Oracle Hospitality Opera 5 Property Services | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote authenticated users to affect confidentiality via vectors related to OPERA. | |
| Modificada | Alta (7.4) | 1.2% | — | Oracle Hospitality Opera 5 Property Services | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to OPERA. | |
| Modificada | Alta (7.9) | 1.1% | — | Oracle Hospitality Opera 5 Property Services | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Hospitality OPERA 5 Property Services component in Oracle Hospitality Applications 5.4.0.0 through 5.4.3.0, 5.5.0.0, and 5.5.1.0 allows remote administrators to affect confidentiality, integrity, and availability via vectors related to OPERA. | |
| Modificada | Media (5.4) | 0.27% | — | Userfriendlymedia Mills-hazel Property Mgmt | 21/10/2014 | 17/6/2026 | The Mills-Hazel Property Mgmt (aka com.appexpress.millshazelpropertymanagement) application 3.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Micronetsoft Rental Property Website | 8/10/2011 | 16/6/2026 | SQL injection vulnerability in detail.asp in Micronetsoft Rental Property Management Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ad_ID parameter. | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Com-property COM Properties | 12/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Com-property COM Properties | 12/5/2010 | 16/6/2026 | SQL injection vulnerability in the Real Estate Property (com_properties) component 3.1.22-03 for Joomla! allows remote attackers to execute arbitrary SQL commands via the aid parameter in an agentlisting action to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Thethinkery COM Iproperty | 4/5/2010 | 16/6/2026 | SQL injection vulnerability in the Intellectual Property (aka IProperty or com_iproperty) component 1.5.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an agentproperties action to index.php. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Propertywatchscript Property Watch | 3/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PropertyWatchScript.com Property Watch 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) videoid parameter to tools/email.php and (2) redirect parameter to tools/login.php. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Zeeways Zeeproperty | 7/8/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in view_prop_details.php in Zeeways ZEEPROPERTY 1.0 allows remote attackers to inject arbitrary web script or HTML via the propid parameter. | |
| Modificada | Media (6.5) | 3.1% | 💥 Exploit | Zeeways Zeeproperty | 7/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a photo in a profile modification, then accessing a related file via a direct request to the file in companylogo/. | |
| Modificada | Media (6.8) | 0.89% | 💥 Exploit | Propertymaxpro Propertymax PRO Free | 5/6/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Propertymaxpro Propertymax PRO Free | 5/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbitrary web script or HTML via the pl parameter in a mi action. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Zeescripts Zeeproperty | 21/10/2008 | 16/6/2026 | SQL injection vulnerability in bannerclick.php in ZeeScripts Zeeproperty allows remote attackers to execute arbitrary SQL commands via the adid parameter. | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Romedchim International SRL Online Rent Property Script | 14/5/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter. NOTE: it was later reported that 5.0 and earlier are also affected. | |
| Modificada | Alta (7.5) | 1.0% | — | Iexpress Property PRO | 25/7/2007 | 16/6/2026 | SQL injection vulnerability in vir_login.asp in iExpress Property Pro allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the Username parameter is covered by CVE-2006-6029. NOTE: the provenance of this information is unknown; the details are obtained solely from third party… | |
| Modificada | Media (6.8) | 1.8% | 💥 Exploit | Mginternet Property Site Manager | 23/12/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in listings.asp in MGinternet Property Site Manager allows remote attackers to inject arbitrary web script or HTML via the s parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Mginternet Property Site Manager | 23/12/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in MGinternet Property Site Manager allow remote attackers to execute arbitrary SQL commands via the (1) p parameter to (a) detail.asp; the (2) l, (3) typ, or (4) loc parameter to (b) listings.asp; or the (5) Password or (6) Username parameter to (c) admin_login.asp. NOTE: some… | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Property PRO | 21/11/2006 | 16/6/2026 | SQL injection vulnerability in vir_Login.asp in Property Pro 1.0 allows remote attackers to execute arbitrary SQL commands via the UserName field. | |
| Modificada | Media (5) | 1.4% | — | Widget Press Widget PropertyAI | 5/12/2005 | 16/6/2026 | property.php in Widget Property 1.1.19 allows remote attackers to obtain the full server path via an invalid lang value, which leaks the path in the resulting error message. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Widget Press Widget Property | 5/12/2005 | 16/6/2026 | SQL injection vulnerability in Widget Property 1.1.19 allows remote attackers to execute arbitrary SQL commands via the (1) property_id, (2) zip_code, (3) property_type_id, (4) price, and (5) city_id parameters to property.php. |