Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
200 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Netartmedia Real Estate Portal | 3/2/2009 | 16/6/2026 | SQL injection vulnerability in the re_search module in NetArtMedia Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the ad parameter to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | SG Real Estate Portal | 30/1/2009 | 16/6/2026 | SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | SG Real Estate Portal | 30/1/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in SG Real Estate Portal 2.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod, (2) page, or (3) lang parameter to index.php; or the (4) action or (5) folder parameter in a security request to admin/index.php. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | SG Real Estate Portal | 30/1/2009 | 16/6/2026 | SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Netart Media Real Estate Portal | 2/12/2008 | 16/6/2026 | SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL commands via the ad_id parameter in the re_send_email module to index.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Pilot Group PG Real Estate Solution | 2/12/2008 | 16/6/2026 | SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter (username). NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 0.98% | 💥 Exploit | Conkurent Real Estate | 22/10/2008 | 16/6/2026 | SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in browse mode. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Real-estate-scripts | 15/10/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 1.00% | 💥 Exploit | Built2go Real Estate Listings | 9/10/2008 | 16/6/2026 | SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects PRE Real Estate Listings | 23/9/2008 | 16/6/2026 | SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c parameter. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Vclcomponents Relative Real Estate Systems | 15/7/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Relative Real Estate Systems 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Mole Group Real Estate Script | 10/7/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action. | |
| Modificada | Media (5) | 2.1% | 💥 Exploit | Relative Real Estate Systems | 26/6/2008 | 16/6/2026 | Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Therealestatescript THE Real Estate Script | 27/5/2008 | 16/6/2026 | SQL injection vulnerability in dpage.php in The Real Estate Script allows remote attackers to execute arbitrary SQL commands via the docID parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Site2nite Real Estate WEB | 14/2/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in default.asp in Site2Nite allow remote attackers to execute arbitrary SQL commands via the (1) txtUserName and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 0.84% | — | PHP Real Estate Script Classifieds | 20/12/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in PHP Real Estate Classifieds allow remote attackers to inject arbitrary web script or HTML via unspecified "text areas/boxes." | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | PHP Real Estate Classifieds Premium Plus | 20/12/2007 | 16/6/2026 | SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 1.1% | 💥 Exploit | Codewidgets Real Estate Listing Website Application Template | 31/7/2007 | 16/6/2026 | SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | PHP Real Estate Classifieds | 11/6/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary PHP code via a URL in the loc parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Motionborg WEB Real Estate | 11/1/2007 | 16/6/2026 | SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters. NOTE: some details were obtained from third party information. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Softwebs Nepal Ananda Real Estate | 28/12/2006 | 16/6/2026 | SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the agent parameter. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Webeveyn Whomp Real Estate Manager XP 2005 | 9/2/2006 | 16/6/2026 | SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Relative Real Estate SystemsAI | 5/12/2005 | 16/6/2026 | SQL injection vulnerability in index.php in Relative Real Estate Systems 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the mls parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Landshop Real Estate Commerce System | 5/12/2005 | 16/6/2026 | SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters. | |
| Modificada | Alta (10) | 1.7% | — | Real Estate Management Software | 31/12/2004 | 16/6/2026 | Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors. |