Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.1% | — | Netartmedia Real Estate Portal | 24/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (6.8) | 1.1% | — | Netartmedia Real Estate Portal | 24/9/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action parameters. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Eicrasoft Eicra Realestate Script | 21/6/2010 | 16/6/2026 | SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Instantrankingseo Infocus Real Estate | 3/5/2010 | 16/6/2026 | Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 1.4% | — | Phpkobo Free Real Estate Contact Form Script | 23/3/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) codelib/cfg/common.inc.php, (2) form/app/common.inc.php,… | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Phpkobo Free Real Estate Contact Form Script | 23/3/2010 | 16/6/2026 | Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 0.91% | 💥 Exploit | Netartmedia Real Estate Portal | 14/1/2010 | 16/6/2026 | SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Netartmedia Media Real Estate Portal | 12/1/2010 | 16/6/2026 | SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Email parameter (aka the username field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Xstate Real Estate | 30/12/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Xstate Real Estate 1.0 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) home.html or (2) lands.html. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Xstate Real Estate | 30/12/2009 | 16/6/2026 | SQL injection vulnerability in page.html in Xstate Real Estate 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Realestatephp Real Estate Manager | 14/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.5) | 3.3% | 💥 Exploit | Preprojects PRE Real Estate Listings | 24/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Site2nite Real Estate WEB | 24/8/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in Site2Nite Real Estate Web allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field to an unspecified component, possibly agentlist.asp. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect. | |
| Modificada | Media (6.5) | 3.4% | 💥 Exploit | Phpstore Real Estate | 11/8/2009 | 16/6/2026 | Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in realty/re_images/. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Ordasoft COM Realestatemanager | 28/7/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Media (5) | 0.90% | — | Mole-group Real Estate Script | 1/6/2009 | 16/6/2026 | Mole Group Real Estate Script 1.1 and earlier stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects PRE Real Estate Listings | 7/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field). | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects PRE Real Estate Listings | 7/5/2009 | 16/6/2026 | SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the username1 parameter (aka the Admin field or Username field). | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Accscripts ACC Real Estate | 26/2/2009 | 16/6/2026 | admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin." | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Netartmedia Real Estate Portal | 3/2/2009 | 16/6/2026 | SQL injection vulnerability in the re_search module in NetArtMedia Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the ad parameter to index.php. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | SG Real Estate Portal | 30/1/2009 | 16/6/2026 | SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | SG Real Estate Portal | 30/1/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in SG Real Estate Portal 2.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod, (2) page, or (3) lang parameter to index.php; or the (4) action or (5) folder parameter in a security request to admin/index.php. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | SG Real Estate Portal | 30/1/2009 | 16/6/2026 | SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Netart Media Real Estate Portal | 2/12/2008 | 16/6/2026 | SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL commands via the ad_id parameter in the re_send_email module to index.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Pilot Group PG Real Estate Solution | 2/12/2008 | 16/6/2026 | SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter (username). NOTE: some of these details are obtained from third party information. |