Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
171 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.22% | — | Wp-property-hive PropertyhiveAI | 17/9/2026 | 17/9/2026 | Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. | |
| Aplazada | Media (6.9) | 0.50% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked directory confinement checks. | |
| Aplazada | Media (6.9) | 0.43% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potential email manipulation. | |
| Aplazada | Alta (8.6) | 0.44% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping. | |
| Aplazada | Media (6.9) | 0.33% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gallery management controller tasks lacked authorization checks and CSRF token validation.. Users could invoke file removal actions with arbitrary path strings or upload unverified file types. | |
| Aplazada | Alta (7.1) | 0.21% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) endpoints processed POST requests without verifying Joomla session anti-CSRF tokens. | |
| Aplazada | Crítica (9.3) | 0.51% | — | Joomshaper SP PropertyAI | 10/9/2026 | 10/9/2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4 - The property search and listing query builders assembled several WHERE and ORDER BY clauses (zipcode, sorting, price_range_dropdown, and psize_range_dropdown) by directly concatenating raw… | |
| Analizada | Alta (8.8) | 0.42% | — | Oracle Hospitality Opera 5 Property Services | 18/8/2026 | 4/9/2026 | Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera Servlet). Supported versions that are affected are 5.6.28.0-5.6.28.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Pendiente de análisis | Media (6.7) | 0.47% | — | Otalio Ship Property Management SystemAI | 18/8/2026 | 29/9/2026 | Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via persistent cross-site scripting | |
| Pendiente de análisis | Alta (8.1) | 0.26% | — | Otalio Ship Property Management SystemAI | 18/8/2026 | 29/9/2026 | Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to escalate privileges via tampering with JWTs | |
| Aplazada | Alta (7.1) | 0.25% | — | Houzez Property FeedAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions. | |
| Aplazada | Media (6.4) | 0.33% | — | Realestateconnected Easy Property ListingsAI | 1/8/2026 | 12/8/2026 | The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to, and including, 3.5.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and… | |
| Analizada | Baja (1.9) | 0.14% | — | Oracle Property Manager | 21/7/2026 | 11/8/2026 | Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Property Manager executes to… | |
| Analizada | Media (5.4) | 0.23% | — | Oracle Property Manager | 21/7/2026 | 11/8/2026 | Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful… | |
| Analizada | Media (5.4) | 0.12% | — | Oracle Property Manager | 21/7/2026 | 11/8/2026 | Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Property Manager | 21/7/2026 | 11/8/2026 | Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wp-property-hive PropertyhiveAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows Reflected XSS.This issue affects PropertyHive: from n/a through <= 2.2.3. | |
| Aplazada | Media (4.9) | 0.48% | — | Wp-property-hive Houzez Property FeedAI | 2/7/2026 | 2/7/2026 | The Houzez Property Feed plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter in all versions up to, and including, 2.5.46 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query in the prepare_items() method of the… | |
| Analizada | Alta (8.8) | 0.43% | — | Faboba Ultimate Property Listing | 19/6/2026 | 19/8/2026 | Joomla Ultimate Property Listing 1.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the sf_selectuser_id parameter. Attackers can send GET requests to index.php with the option=com_upl and view=propertylisting… | |
| Analizada | Alta (7.2) | 0.49% | — | Oracle Property Manager | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful… | |
| Analizada | Crítica (9.8) | 0.55% | — | Oracle Hospitality Opera 5 Property Services | 28/5/2026 | 17/6/2026 | Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6 and 5.6.28. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wp-property-hive PropertyhiveAI | 27/5/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Property Hive PropertyHive propertyhive allows DOM-Based XSS.This issue affects PropertyHive: from n/a through <= 2.2.2. | |
| Aplazada | Media (5.1) | 0.22% | — | Jproperty Iproperty Real EstateAI | 9/4/2026 | 26/9/2026 | Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter of the all-properties-with-map endpoint… | |
| Aplazada | Baja (1.9) | 0.15% | — | Propertyguru AgentnetAI | 3/4/2026 | 24/7/2026 | A security flaw has been discovered in PropertyGuru AgentNet Singapore App up to 23.7.10 on Android. This affects an unknown function of the file com/allproperty/android/agentnet/BuildConfig.java of the component com.allproperty.android.agentnet. The manipulation of the argument… | |
| Modificada | Crítica (9.8) | 0.52% | — | Jon-remus-sevellejo Personnel Property Equipment System | 2/3/2026 | 17/6/2026 | sourcecodester Personnel Property Equipment System v1.0 is vulnerable to SQL Injection in /ppes/admin/edit_employee.php. |