Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

244 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.9%—Projectworlds House Rental AND Property Listing Project27/8/202017/6/2026
File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution.
ModificadaMedia (6.1)1.4%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing24/2/202017/6/2026
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.
ModificadaMedia (6.5)1.2%💥 ExploitStylemixthemes Motors - CAR Dealer, Classifieds & Listing24/2/202017/6/2026
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.
ModificadaAlta (8.8)0.82%—Realestateconnected Easy Property Listings18/2/202017/6/2026
Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaMedia (5.4)0.72%—Cridio Listingpro26/12/201917/6/2026
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page.
ModificadaMedia (5.4)0.72%—Cridio Listingpro26/12/201917/6/2026
The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page.
ModificadaMedia (6.1)0.93%—Cridio Listingpro26/12/201917/6/2026
The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage.
ModificadaMedia (6.1)0.98%—Agentevolution Impress Listings20/9/201917/6/2026
The wp-listings plugin before 2.0.2 for WordPress has includes/views/single-listing.php XSS.
ModificadaMedia (6.1)1.00%—Realestateconnected Easy Property Listings30/8/201917/6/2026
The easy-property-listings plugin before 3.4 for WordPress has XSS.
ModificadaCrítica (9.8)3.0%💥 ExploitKindergarten - Elementary School Listing Script Project Kindergarten - Elementary School Listing Script13/12/201717/6/2026
Child Care Script 1.0 has SQL Injection via the /list city parameter.
ModificadaAlta (8.8)3.1%💥 ExploitRealtyna Property Listing18/10/201717/6/2026
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/index.php.
ModificadaAlta (7.2)2.2%💥 ExploitRealtyna Property Listing18/10/201717/6/2026
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field action, (4) css, (5) tip, (6) cat_id, (7) text_search, (8) plisting,…
ModificadaAlta (7.2)1.7%—Add-edit-delete-listing-for-member-module Project Add-edit-delete-listing-for-member-module14/9/201717/6/2026
Vulnerability in wordpress plugin add-edit-delete-listing-for-member-module v1.0, The plugin author does not sanitize user supplied input via $act before passing it into an SQL statement.
ModificadaBaja (3.8)0.26%—Hp-ux Whitelisting19/4/201417/6/2026
Unspecified vulnerability in HP HP-UX Whitelisting (aka WLI) before A.01.02.02 on HP-UX B.11.31 allows local users to bypass intended access restrictions via unknown vectors.
ModificadaBaja (3.5)1.2%💥 ExploitBarter-sites COM Listing15/12/201116/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the com_listing component in Barter Sites component 1.3 for Joomla! allow remote authenticated users to inject arbitrary web script or HTML via the (1) listing_title, (2) description, (3) homeurl (aka Website Address), (4) paystring (aka Payment types accepted),…
ModificadaAlta (7.5)1.0%💥 ExploitBarter-sites COM Listing15/12/201116/6/2026
SQL injection vulnerability in the com_listing component in Barter Sites component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter to index.php.
ModificadaAlta (7.5)1.0%💥 ExploitScriptsfeed Recipes Listing Portal2/11/201116/6/2026
SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.0%💥 ExploitSite2nite Business E-listings30/12/201016/6/2026
SQL injection vulnerability in detail.asp in Site2Nite Business e-Listings allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaAlta (7.5)1.2%💥 ExploitSite2nite Vacation Rental Listings30/12/201016/6/2026
SQL injection vulnerability in detail.asp in Site2Nite Vacation Rental (VRBO) Listings allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaAlta (10)2.7%—Serge Gebhardt DIR Listing22/7/201016/6/2026
Directory traversal vulnerability in the Directory Listing (dir_listing) extension 1.1.0 and earlier for TYPO3 allows remote attackers to have an unspecified impact via unknown vectors.
ModificadaAlta (7.5)0.96%💥 ExploitHauntmax Haunted House Directory Listing CMS16/6/201016/6/2026
SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to execute arbitrary SQL commands via the state parameter in a listings action.
ModificadaMedia (4.3)0.93%—Preprojects PRE Classified Listings ASP13/4/201016/6/2026
Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to inject arbitrary web script or HTML via the address parameter.
ModificadaAlta (7.5)1.1%—Preprojects PRE Classified Listings ASP13/4/201016/6/2026
SQL injection vulnerability in detailad.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the siteid parameter.
ModificadaAlta (7.5)0.97%💥 ExploitPreprojects PRE Classified Listings ASP13/4/201016/6/2026
SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter.
ModificadaMedia (5)2.6%💥 ExploitAspindir Uranyumsoft Listing Service6/1/201016/6/2026
UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/db.mdb.
Orbitaley — Vulnerabilidades