Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.19% | — | Real Estate ManagerAI | 30/9/2026 | 30/9/2026 | The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_price_text' parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| En análisis | Media (5.3) | 0.26% | — | Ordasoft Real Estate ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same… | |
| En análisis | Crítica (9.3) | 0.28% | — | Ordasoft Real Estate ManagerAI | 28/9/2026 | 30/9/2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field… | |
| Aplazada | Alta (7.5) | 0.36% | — | Real Estate Manager PROAI | 15/8/2026 | 20/8/2026 | The Real Estate Manager Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 12.8.6. This is due to improper capability handling in the allow_attachment_actions() function, which can treat a target user ID as a media attachment ID during user capability checks. This… | |
| Aplazada | Alta (7.1) | 0.25% | — | Real Estate Manager PROAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Real Estate Manager Pro <= 12.8.5 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Webcodingplace Real Estate Manager PROAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Real Estate Manager Pro real-estate-manager-pro allows Reflected XSS.This issue affects Real Estate Manager Pro: from n/a through <= 12.8.3. | |
| Aplazada | Media (6.5) | 0.21% | — | Rameez Iqbal Real Estate ManagerAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows DOM-Based XSS.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Aplazada | Alta (7.1) | 0.25% | — | Webcodingplace Real-estate-manager-proAI | 20/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebCodingPlace Real Estate Manager Pro real-estate-manager-pro allows Reflected XSS.This issue affects Real Estate Manager Pro: from n/a through <= 12.7.3. | |
| Aplazada | Alta (8.8) | 0.19% | — | Rameez Iqbal Real Estate ManagerAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Privilege Escalation.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Aplazada | Media (6.5) | 0.18% | — | Rameez Iqbal Real Estate ManagerAI | 20/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Cross Site Request Forgery.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Aplazada | Alta (7.3) | 0.37% | — | Rameez Iqbal Real Estate ManagerAI | 17/4/2025 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Code Injection.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Aplazada | Alta (8.1) | 0.66% | — | Rameez Iqbal Real Estate ManagerAIPHPAI | 10/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows PHP Local File Inclusion.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Aplazada | Alta (7.5) | 1.1% | — | Rameez Iqbal Real Estate ManagerAI | 4/4/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows PHP Local File Inclusion.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Aplazada | Crítica (9.8) | 0.56% | — | WP Real Estate ManagerAI | 5/3/2025 | 17/6/2026 | The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.8. This is due to insufficient identity verification on the LinkedIn login request process. This makes it possible for unauthenticated attackers to bypass official authentication and log in as… | |
| Aplazada | Media (5.3) | 0.34% | — | Rameez Iqbal Real Estate ManagerAI | 18/2/2025 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Password Brute Forcing.This issue affects Real Estate Manager: from n/a through <= 7.3. | |
| Aplazada | Media (5.1) | 0.35% | — | Ingenico Estate ManagerAI | 30/6/2024 | 17/6/2026 | A vulnerability classified as problematic was found in Ingenico Estate Manager 2023. Affected by this vulnerability is an unknown functionality of the file /emgui/rest/preferences/PREF_HOME_PAGE/sponsor/3/ of the component New Widget Handler. The manipulation of the argument URL leads to cross site scripting. The… | |
| Modificada | Media (6.5) | 0.75% | — | Webcodingplace Real Estate Manager | 9/8/2023 | 17/6/2026 | The Real Estate Manager plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.2 due to insufficient restriction on the 'rem_save_profile_front' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role… | |
| Modificada | Alta (7.5) | 1.2% | — | Mckenziecreations Virtual Real Estate Manager | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in listing_detail.asp in Mckenzie Creations Virtual Real Estate Manager (VRM) 3.5 allows remote attackers to execute arbitrary SQL commands via the Lid parameter. | |
| Modificada | Media (4.3) | 1.1% | — | Realestatephp Real Estate Manager | 14/12/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.3% | — | Webeveyn Whomp Real Estate Manager XP 2005 | 9/2/2006 | 16/6/2026 | SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameters. |