Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

200 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Real-estate-php-script Real Estate PHP Script23/9/201316/6/2026
SQL injection vulnerability in property_listings_detail.php in Real Estate PHP Script allows remote attackers to execute arbitrary SQL commands via the listingid parameter.
ModificadaMedia (4.3)0.98%—Real-estate-php-script Real Estate PHP Script23/9/201316/6/2026
Cross-site scripting (XSS) vulnerability in search_residential.php in Real Estate PHP Script allows remote attackers to inject arbitrary web script or HTML via the bos parameter.
ModificadaAlta (7.5)1.1%💥 ExploitMyrephp Myre Real Estate Software13/8/201216/6/2026
Multiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrary SQL commands via the (1) link_idd parameter to 1_mobile/listings.php or (2) userid parameter to 1_mobile/agentprofile.php.
ModificadaAlta (7.5)1.2%💥 ExploitMckenziecreations Virtual Real Estate Manager2/11/201116/6/2026
SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter.
ModificadaAlta (7.5)1.8%💥 ExploitMyrephp Myre Real Estate Software15/9/201116/6/2026
SQL injection vulnerability in findagent.php in MYRE Real Estate Software allows remote attackers to execute arbitrary SQL commands via the page parameter.
ModificadaMedia (4.3)2.3%💥 ExploitMyrephp Myre Real Estate Software15/9/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers to inject arbitrary web script or HTML via the (1) country1, (2) state1, or (3) city1 parameter.
ModificadaAlta (7.5)1.0%💥 ExploitSoftwebsnepal Ananda Real Estate7/4/201116/6/2026
Multiple SQL injection vulnerabilities in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) city, (2) state, (3) country, (4) minprice, (5) maxprice, (6) bed, and (7) bath parameters, different vectors than CVE-2006-6807.
ModificadaAlta (7.5)1.8%💥 ExploitRaemedia Real Estate Single AND Multi Agent System16/2/201116/6/2026
Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Agent System and (2) resulttype.asp in the Single Agent System.
ModificadaMedia (4.3)1.1%—Netartmedia Real Estate Portal24/9/201016/6/2026
Cross-site scripting (XSS) vulnerability in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.
ModificadaMedia (6.8)1.1%—Netartmedia Real Estate Portal24/9/201016/6/2026
Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action parameters.
ModificadaAlta (7.5)1.0%💥 ExploitInstantrankingseo Infocus Real Estate3/5/201016/6/2026
Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)1.4%—Phpkobo Free Real Estate Contact Form Script23/3/201016/6/2026
Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) codelib/cfg/common.inc.php, (2) form/app/common.inc.php,…
ModificadaMedia (6.8)1.9%💥 ExploitPhpkobo Free Real Estate Contact Form Script23/3/201016/6/2026
Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter. NOTE: some of these details are obtained from third party…
ModificadaAlta (7.5)0.91%💥 ExploitNetartmedia Real Estate Portal14/1/201016/6/2026
SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.0%💥 ExploitNetartmedia Media Real Estate Portal12/1/201016/6/2026
SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Email parameter (aka the username field). NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.5%💥 ExploitXstate Real Estate30/12/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Xstate Real Estate 1.0 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) home.html or (2) lands.html.
ModificadaAlta (7.5)1.0%💥 ExploitXstate Real Estate30/12/200916/6/2026
SQL injection vulnerability in page.html in Xstate Real Estate 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
ModificadaMedia (4.3)1.1%—Realestatephp Real Estate Manager14/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.5)3.3%💥 ExploitPreprojects PRE Real Estate Listings24/8/200916/6/2026
Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/.
ModificadaAlta (7.5)0.97%💥 ExploitSite2nite Real Estate WEB24/8/200916/6/2026
Multiple SQL injection vulnerabilities in Site2Nite Real Estate Web allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field to an unspecified component, possibly agentlist.asp. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.
ModificadaMedia (6.5)3.4%💥 ExploitPhpstore Real Estate11/8/200916/6/2026
Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in realty/re_images/.
ModificadaMedia (5)0.90%—Mole-group Real Estate Script1/6/200916/6/2026
Mole Group Real Estate Script 1.1 and earlier stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects PRE Real Estate Listings7/5/200916/6/2026
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects PRE Real Estate Listings7/5/200916/6/2026
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the username1 parameter (aka the Admin field or Username field).
ModificadaAlta (7.5)2.7%💥 ExploitAccscripts ACC Real Estate26/2/200916/6/2026
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin."
Orbitaley — Vulnerabilidades