Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

262 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.1%—Netartmedia Real Estate Portal24/9/201016/6/2026
Cross-site scripting (XSS) vulnerability in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.
ModificadaMedia (6.8)1.1%—Netartmedia Real Estate Portal24/9/201016/6/2026
Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action parameters.
ModificadaAlta (7.5)1.0%💥 ExploitEicrasoft Eicra Realestate Script21/6/201016/6/2026
SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.0%💥 ExploitInstantrankingseo Infocus Real Estate3/5/201016/6/2026
Multiple SQL injection vulnerabilities in system_member_login.php in Infocus Real Estate Enterprise Edition allow remote attackers to execute arbitrary SQL commands via the (1) username (aka login) and (2) password parameters. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.8)1.4%—Phpkobo Free Real Estate Contact Form Script23/3/201016/6/2026
Multiple directory traversal vulnerabilities in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the LANG_CODE parameter to (1) codelib/cfg/common.inc.php, (2) form/app/common.inc.php,…
ModificadaMedia (6.8)1.9%💥 ExploitPhpkobo Free Real Estate Contact Form Script23/3/201016/6/2026
Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG_CODE parameter. NOTE: some of these details are obtained from third party…
ModificadaAlta (7.5)0.91%💥 ExploitNetartmedia Real Estate Portal14/1/201016/6/2026
SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.0%💥 ExploitNetartmedia Media Real Estate Portal12/1/201016/6/2026
SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Email parameter (aka the username field). NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.5%💥 ExploitXstate Real Estate30/12/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Xstate Real Estate 1.0 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) home.html or (2) lands.html.
ModificadaAlta (7.5)1.0%💥 ExploitXstate Real Estate30/12/200916/6/2026
SQL injection vulnerability in page.html in Xstate Real Estate 1.0 allows remote attackers to execute arbitrary SQL commands via the pid parameter.
ModificadaMedia (4.3)1.1%—Realestatephp Real Estate Manager14/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (6.5)3.3%💥 ExploitPreprojects PRE Real Estate Listings24/8/200916/6/2026
Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in re_images/.
ModificadaAlta (7.5)0.97%💥 ExploitSite2nite Real Estate WEB24/8/200916/6/2026
Multiple SQL injection vulnerabilities in Site2Nite Real Estate Web allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password field to an unspecified component, possibly agentlist.asp. NOTE: this issue was disclosed by an unreliable researcher, so it might be incorrect.
ModificadaMedia (6.5)3.4%💥 ExploitPhpstore Real Estate11/8/200916/6/2026
Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a logo, then accessing it via a direct request to the file in realty/re_images/.
ModificadaAlta (7.5)2.1%💥 ExploitOrdasoft COM Realestatemanager28/7/200916/6/2026
PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.0 Basic for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
ModificadaMedia (5)0.90%—Mole-group Real Estate Script1/6/200916/6/2026
Mole Group Real Estate Script 1.1 and earlier stores passwords in cleartext, which allows context-dependent attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects PRE Real Estate Listings7/5/200916/6/2026
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL commands via (1) the us parameter (aka the Username field) or (2) the ps parameter (aka the Password field).
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects PRE Real Estate Listings7/5/200916/6/2026
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the username1 parameter (aka the Admin field or Username field).
ModificadaAlta (7.5)2.7%💥 ExploitAccscripts ACC Real Estate26/2/200916/6/2026
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the username_cookie to "admin."
ModificadaAlta (7.5)0.97%💥 ExploitNetartmedia Real Estate Portal3/2/200916/6/2026
SQL injection vulnerability in the re_search module in NetArtMedia Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the ad parameter to index.php.
ModificadaAlta (7.5)0.97%💥 ExploitSG Real Estate Portal30/1/200916/6/2026
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.
ModificadaMedia (5)2.7%💥 ExploitSG Real Estate Portal30/1/200916/6/2026
Multiple directory traversal vulnerabilities in SG Real Estate Portal 2.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod, (2) page, or (3) lang parameter to index.php; or the (4) action or (5) folder parameter in a security request to admin/index.php.
ModificadaAlta (7.5)2.6%💥 ExploitSG Real Estate Portal30/1/200916/6/2026
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.
ModificadaAlta (7.5)1.0%💥 ExploitNetart Media Real Estate Portal2/12/200816/6/2026
SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL commands via the ad_id parameter in the re_send_email module to index.php.
ModificadaAlta (7.5)1.2%💥 ExploitPilot Group PG Real Estate Solution2/12/200816/6/2026
SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary SQL commands via the login_lg parameter (username). NOTE: some of these details are obtained from third party information.
Orbitaley — Vulnerabilidades