Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
200 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Real-estate-php-script Real Estate PHP Script | 23/9/2013 | 16/6/2026 | SQL injection vulnerability in property_listings_detail.php in Real Estate PHP Script allows remote attackers to execute arbitrary SQL commands via the listingid parameter. | |
| Modificada | Media (4.3) | 0.98% | — | Real-estate-php-script Real Estate PHP Script | 23/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search_residential.php in Real Estate PHP Script allows remote attackers to inject arbitrary web script or HTML via the bos parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Myrephp Myre Real Estate Software | 13/8/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrary SQL commands via the (1) link_idd parameter to 1_mobile/listings.php or (2) userid parameter to 1_mobile/agentprofile.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Mckenziecreations Virtual Real Estate Manager | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Myrephp Myre Real Estate Software | 15/9/2011 | 16/6/2026 | SQL injection vulnerability in findagent.php in MYRE Real Estate Software allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Myrephp Myre Real Estate Software | 15/9/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers to inject arbitrary web script or HTML via the (1) country1, (2) state1, or (3) city1 parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Softwebsnepal Ananda Real Estate | 7/4/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) city, (2) state, (3) country, (4) minprice, (5) maxprice, (6) bed, and (7) bath parameters, different vectors than CVE-2006-6807. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Raemedia Real Estate Single AND Multi Agent System | 16/2/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Agent System and (2) resulttype.asp in the Single Agent System. | |
| Modificada | Media (4.3) | 1.1% | — | Netartmedia Real Estate Portal | 24/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (6.8) | 1.1% | — | Netartmedia Real Estate Portal | 24/9/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action parameters. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Instantrankingseo Infocus Real Estate | 3/5/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 1.4% | — | Phpkobo Free Real Estate Contact Form Script | 23/3/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) codelib/cfg/common.inc.php, (2) form/app/common.inc.php,… | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Phpkobo Free Real Estate Contact Form Script | 23/3/2010 | 16/6/2026 | Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Netartmedia Real Estate Portal | 14/1/2010 | 16/6/2026 | SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Netartmedia Media Real Estate Portal | 12/1/2010 | 16/6/2026 | SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Email parameter (aka the username field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Xstate Real Estate | 30/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Xstate Real Estate 1.0 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) home.html or (2) lands.html. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Xstate Real Estate | 30/12/2009 | 16/6/2026 | SQL injection vulnerability in page.html in Xstate Real Estate 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Realestatephp Real Estate Manager | 14/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.5) | 3.3% | 💥 Exploit | Preprojects PRE Real Estate Listings | 24/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Site2nite Real Estate WEB | 24/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Site2Nite Real Estate Web allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field to an unspecified component, possibly agentlist.asp. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect. | |
| Modificada | Media (6.5) | 3.4% | 💥 Exploit | Phpstore Real Estate | 11/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in realty/re_images/. | |
| Modificada | Media (5) | 0.90% | — | Mole-group Real Estate Script | 1/6/2009 | 16/6/2026 | Mole Group Real Estate Script 1.1 and earlier stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects PRE Real Estate Listings | 7/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field). | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects PRE Real Estate Listings | 7/5/2009 | 16/6/2026 | SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the username1 parameter (aka the Admin field or Username field). | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Accscripts ACC Real Estate | 26/2/2009 | 16/6/2026 | admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin." |