Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
244 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.9% | — | Projectworlds House Rental AND Property Listing Project | 27/8/2020 | 17/6/2026 | File Upload component in Projects World House Rental v1.0 suffers from an arbitrary file upload vulnerability with regular users, which allows remote attackers to conduct code execution. | |
| Modificada | Media (6.1) | 1.4% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 24/2/2020 | 17/6/2026 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues. | |
| Modificada | Media (6.5) | 1.2% | 💥 Exploit | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 24/2/2020 | 17/6/2026 | includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes. | |
| Modificada | Alta (8.8) | 0.82% | — | Realestateconnected Easy Property Listings | 18/2/2020 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (5.4) | 0.72% | — | Cridio Listingpro | 26/12/2019 | 17/6/2026 | The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Good For field on the new listing submit page. | |
| Modificada | Media (5.4) | 0.72% | — | Cridio Listingpro | 26/12/2019 | 17/6/2026 | The ListingPro theme before v2.0.14.2 for WordPress has Persistent XSS via the Best Day/Night field on the new listing submit page. | |
| Modificada | Media (6.1) | 0.93% | — | Cridio Listingpro | 26/12/2019 | 17/6/2026 | The ListingPro theme before v2.0.14.2 for WordPress has Reflected XSS via the What field on the homepage. | |
| Modificada | Media (6.1) | 0.98% | — | Agentevolution Impress Listings | 20/9/2019 | 17/6/2026 | The wp-listings plugin before 2.0.2 for WordPress has includes/views/single-listing.php XSS. | |
| Modificada | Media (6.1) | 1.00% | — | Realestateconnected Easy Property Listings | 30/8/2019 | 17/6/2026 | The easy-property-listings plugin before 3.4 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Kindergarten - Elementary School Listing Script Project Kindergarten - Elementary School Listing Script | 13/12/2017 | 17/6/2026 | Child Care Script 1.0 has SQL Injection via the /list city parameter. | |
| Modificada | Alta (8.8) | 3.1% | 💥 Exploit | Realtyna Property Listing | 18/10/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/index.php. | |
| Modificada | Alta (7.2) | 2.2% | 💥 Exploit | Realtyna Property Listing | 18/10/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote administrators to execute arbitrary SQL commands via the (1) id, (2) copy_field in a data_copy action, (3) pshow in an update_field action, (4) css, (5) tip, (6) cat_id, (7) text_search, (8) plisting,… | |
| Modificada | Alta (7.2) | 1.7% | — | Add-edit-delete-listing-for-member-module Project Add-edit-delete-listing-for-member-module | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin add-edit-delete-listing-for-member-module v1.0, The plugin author does not sanitize user supplied input via $act before passing it into an SQL statement. | |
| Modificada | Baja (3.8) | 0.26% | — | Hp-ux Whitelisting | 19/4/2014 | 17/6/2026 | Unspecified vulnerability in HP HP-UX Whitelisting (aka WLI) before A.01.02.02 on HP-UX B.11.31 allows local users to bypass intended access restrictions via unknown vectors. | |
| Modificada | Baja (3.5) | 1.2% | 💥 Exploit | Barter-sites COM Listing | 15/12/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the com_listing component in Barter Sites component 1.3 for Joomla! allow remote authenticated users to inject arbitrary web script or HTML via the (1) listing_title, (2) description, (3) homeurl (aka Website Address), (4) paystring (aka Payment types accepted),… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Barter-sites COM Listing | 15/12/2011 | 16/6/2026 | SQL injection vulnerability in the com_listing component in Barter Sites component 1.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter to index.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Scriptsfeed Recipes Listing Portal | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in control/admin_login.php in ScriptsFeed Recipes Listing Portal 1.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter (aka the UserName field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Site2nite Business E-listings | 30/12/2010 | 16/6/2026 | SQL injection vulnerability in detail.asp in Site2Nite Business e-Listings allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Site2nite Vacation Rental Listings | 30/12/2010 | 16/6/2026 | SQL injection vulnerability in detail.asp in Site2Nite Vacation Rental (VRBO) Listings allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (10) | 2.7% | — | Serge Gebhardt DIR Listing | 22/7/2010 | 16/6/2026 | Directory traversal vulnerability in the Directory Listing (dir_listing) extension 1.1.0 and earlier for TYPO3 allows remote attackers to have an unspecified impact via unknown vectors. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Hauntmax Haunted House Directory Listing CMS | 16/6/2010 | 16/6/2026 | SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to execute arbitrary SQL commands via the state parameter in a listings action. | |
| Modificada | Media (4.3) | 0.93% | — | Preprojects PRE Classified Listings ASP | 13/4/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to inject arbitrary web script or HTML via the address parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Preprojects PRE Classified Listings ASP | 13/4/2010 | 16/6/2026 | SQL injection vulnerability in detailad.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the siteid parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Preprojects PRE Classified Listings ASP | 13/4/2010 | 16/6/2026 | SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the email parameter. | |
| Modificada | Media (5) | 2.6% | 💥 Exploit | Aspindir Uranyumsoft Listing Service | 6/1/2010 | 16/6/2026 | UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/db.mdb. |