Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

200 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.97%💥 ExploitNetartmedia Real Estate Portal3/2/200916/6/2026
SQL injection vulnerability in the re_search module in NetArtMedia Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the ad parameter to index.php.
ModificadaAlta (7.5)0.97%💥 ExploitSG Real Estate Portal30/1/200916/6/2026
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.
ModificadaMedia (5)2.7%💥 ExploitSG Real Estate Portal30/1/200916/6/2026
Multiple directory traversal vulnerabilities in SG Real Estate Portal 2.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod, (2) page, or (3) lang parameter to index.php; or the (4) action or (5) folder parameter in a security request to admin/index.php.
ModificadaAlta (7.5)2.6%💥 ExploitSG Real Estate Portal30/1/200916/6/2026
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.
ModificadaAlta (7.5)1.0%💥 ExploitNetart Media Real Estate Portal2/12/200816/6/2026
SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL commands via the ad_id parameter in the re_send_email module to index.php.
ModificadaAlta (7.5)1.2%💥 ExploitPilot Group PG Real Estate Solution2/12/200816/6/2026
SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter (username). NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)0.98%💥 ExploitConkurent Real Estate22/10/200816/6/2026
SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in browse mode.
ModificadaAlta (7.5)1.0%💥 ExploitReal-estate-scripts15/10/200816/6/2026
SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the cat parameter.
ModificadaAlta (7.5)1.00%💥 ExploitBuilt2go Real Estate Listings9/10/200816/6/2026
SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute arbitrary SQL commands via the event_id parameter.
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects PRE Real Estate Listings23/9/200816/6/2026
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c parameter.
ModificadaMedia (6.8)1.1%💥 ExploitVclcomponents Relative Real Estate Systems15/7/200816/6/2026
SQL injection vulnerability in index.php in Relative Real Estate Systems 3.0 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.
ModificadaAlta (7.5)0.97%💥 ExploitMole Group Real Estate Script10/7/200816/6/2026
SQL injection vulnerability in index.php in Mole Group Real Estate Script 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the listing_id parameter in a listings action.
ModificadaMedia (5)2.1%💥 ExploitRelative Real Estate Systems26/6/200816/6/2026
Relative Real Estate Systems 3.0 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information.
ModificadaAlta (7.5)1.0%💥 ExploitTherealestatescript THE Real Estate Script27/5/200816/6/2026
SQL injection vulnerability in dpage.php in The Real Estate Script allows remote attackers to execute arbitrary SQL commands via the docID parameter.
ModificadaAlta (7.5)1.1%—Site2nite Real Estate WEB14/2/200816/6/2026
Multiple SQL injection vulnerabilities in default.asp in Site2Nite allow remote attackers to execute arbitrary SQL commands via the (1) txtUserName and (2) txtPassword parameters. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)0.84%—PHP Real Estate Script Classifieds20/12/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the admin panel in PHP Real Estate Classifieds allow remote attackers to inject arbitrary web script or HTML via unspecified "text areas/boxes."
ModificadaAlta (7.5)1.0%💥 ExploitPHP Real Estate Classifieds Premium Plus20/12/200716/6/2026
SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (6.8)1.1%💥 ExploitCodewidgets Real Estate Listing Website Application Template31/7/200716/6/2026
SQL injection vulnerability in the login script in Real Estate listing website application template, when logging in as user or manager, allows remote attackers to execute arbitrary SQL commands via the Password parameter.
ModificadaAlta (7.5)3.1%💥 ExploitPHP Real Estate Classifieds11/6/200716/6/2026
PHP remote file inclusion vulnerability in admin/header.php in PHP Real Estate Classifieds Premium Plus allows remote attackers to execute arbitrary PHP code via a URL in the loc parameter.
ModificadaAlta (7.5)1.2%💥 ExploitMotionborg WEB Real Estate11/1/200716/6/2026
SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the username field (txtUserName parameter) and possibly other parameters. NOTE: some details were obtained from third party information.
ModificadaAlta (7.5)1.1%💥 ExploitSoftwebs Nepal Ananda Real Estate28/12/200616/6/2026
SQL injection vulnerability in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the agent parameter.
ModificadaAlta (7.5)1.3%💥 ExploitWebeveyn Whomp Real Estate Manager XP 20059/2/200616/6/2026
SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters.
ModificadaAlta (7.5)1.2%💥 ExploitRelative Real Estate SystemsAI5/12/200516/6/2026
SQL injection vulnerability in index.php in Relative Real Estate Systems 1.02 and earlier allows remote attackers to execute arbitrary SQL commands via the mls parameter.
ModificadaAlta (7.5)1.1%💥 ExploitLandshop Real Estate Commerce System5/12/200516/6/2026
SQL injection vulnerability in ls.php in Landshop Real Estate Commerce System 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) start, (2) search_order, (3) search_type, (4) search_area, and (5) keyword parameters.
ModificadaAlta (10)1.7%—Real Estate Management Software31/12/200416/6/2026
Multiple unknown vulnerabilities in Real Estate Management Software 1.0 have unknown impact and attack vectors.