Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/newsedit.php newstitle parameter. | |
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/snacks_edit.php snacks_name parameter. | |
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/manageownerlist.php contact parameter. | |
| Modificada | Media (6.8) | 0.40% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has CSRF via admin/movieedit.php. | |
| Modificada | Media (4.8) | 0.49% | — | Advanced Real Estate Script Project Advanced Real Estate Script | 3/1/2018 | 17/6/2026 | Online Ticket Booking has XSS via the admin/sitesettings.php keyword parameter. | |
| Modificada | Media (4.8) | 0.49% | — | Responsive Realestate Script Project Responsive Realestate Script | 27/12/2017 | 17/6/2026 | PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter. | |
| Modificada | Alta (8.8) | 0.46% | — | Responsive Realestate Script Project Responsive Realestate Script | 27/12/2017 | 17/6/2026 | PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general. | |
| Modificada | Crítica (9.8) | 2.2% | 💥 Exploit | Responsive Realestate Script Project Responsive Realestate Script | 13/12/2017 | 17/6/2026 | Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Advanced Real Estate Script Project Advanced Real Estate Script | 13/12/2017 | 17/6/2026 | Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. | |
| Modificada | Crítica (9.8) | 4.4% | 💥 Exploit | Realestate Crowdfunding Script Project Realestate Crowdfunding Script | 13/12/2017 | 17/6/2026 | Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter. | |
| Modificada | Media (5.4) | 0.27% | — | Estateapps Acorn Estate Agents | 19/10/2014 | 17/6/2026 | The Acorn Estate Agents (aka com.acorn.ea) application 3.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 1.2% | — | Real-estate-php-script Real Estate PHP Script | 23/9/2013 | 16/6/2026 | SQL injection vulnerability in property_listings_detail.php in Real Estate PHP Script allows remote attackers to execute arbitrary SQL commands via the listingid parameter. | |
| Modificada | Media (4.3) | 0.98% | — | Real-estate-php-script Real Estate PHP Script | 23/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in search_residential.php in Real Estate PHP Script allows remote attackers to inject arbitrary web script or HTML via the bos parameter. | |
| Modificada | Alta (7.3) | 1.2% | 💥 Exploit | Activestate Activepython | 11/10/2012 | 16/6/2026 | Untrusted search path vulnerability in the installation functionality in ActivePython 3.2.2.3, when installed in the top-level C:\ directory, might allow local users to gain privileges via a Trojan horse DLL in the C:\Python27 or C:\Python27\Scripts directory, which may be added to the PATH system environment variable… | |
| Modificada | Media (6) | 0.91% | 💥 Exploit | Activestate Activetcl | 11/10/2012 | 16/6/2026 | Untrusted search path vulnerability in the installation functionality in ActiveTcl 8.5.12, when installed in the top-level C:\ directory, allows local users to gain privileges via a Trojan horse DLL in the C:\TD\bin directory, which is added to the PATH system environment variable, as demonstrated by a Trojan horse… | |
| Modificada | Media (6) | 1.3% | 💥 Exploit | Activestate Activeperl | 11/10/2012 | 16/6/2026 | Untrusted search path vulnerability in the installation functionality in ActivePerl 5.16.1.1601, when installed in the top-level C:\ directory, allows local users to gain privileges via a Trojan horse DLL in the C:\Perl\Site\bin directory, which is added to the PATH system environment variable, as demonstrated by a… | |
| Modificada | Alta (7.5) | 1.2% | — | Wcs4web Easywebrealestate | 4/10/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in EasyWebRealEstate allow remote attackers to execute arbitrary SQL commands via the (1) lstid parameter to listings.php or (2) infoid parameter to index.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Myrephp Myre Real Estate Software | 13/8/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in MYRE Real Estate Software (2012 Q2) allow remote attackers to execute arbitrary SQL commands via the (1) link_idd parameter to 1_mobile/listings.php or (2) userid parameter to 1_mobile/agentprofile.php. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Extensionsforjoomla COM Vikrealestate | 15/12/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Eaimproved COM Estateagent | 29/11/2011 | 16/6/2026 | SQL injection vulnerability in the Estate Agent (com_estateagent) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a showEO action to index.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Mckenziecreations Virtual Real Estate Manager | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Myrephp Myre Real Estate Software | 15/9/2011 | 16/6/2026 | SQL injection vulnerability in findagent.php in MYRE Real Estate Software allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Myrephp Myre Real Estate Software | 15/9/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers to inject arbitrary web script or HTML via the (1) country1, (2) state1, or (3) city1 parameter. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Softwebsnepal Ananda Real Estate | 7/4/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) city, (2) state, (3) country, (4) minprice, (5) maxprice, (6) bed, and (7) bath parameters, different vectors than CVE-2006-6807. | |
| Modificada | Alta (7.5) | 1.8% | 💥 Exploit | Raemedia Real Estate Single AND Multi Agent System | 16/2/2011 | 16/6/2026 | Multiple SQL injection vulnerabilities in Rae Media INC Real Estate Single and Multi Agent System 3.0 allow remote attackers to execute arbitrary SQL commands via the probe parameter to (1) multi/city.asp in the Multi Agent System and (2) resulttype.asp in the Single Agent System. |