Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.46%—Netartmedia Real Estate Portal12/3/202617/6/2026
Netartmedia Real Estate Portal 5.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the page parameter. Attackers can submit POST requests to index.php with malicious SQL payloads in the page field to bypass authentication,…
AnalizadaAlta (8.8)0.46%—Netartmedia Real Estate Portal12/3/202617/6/2026
Netartmedia Real Estate Portal 5.0 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the user_email parameter. Attackers can send POST requests to index.php with malicious payloads in the user_email field to bypass authentication,…
AnalizadaAlta (8.8)0.32%—Netartmedia Real Estate Portal12/3/202617/6/2026
Netartmedia PHP Real Estate Agency 4.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the features[] parameter. Attackers can send POST requests to index.php with crafted SQL payloads in the features[] parameter to…
ModificadaCrítica (9.8)0.65%—Simple Real Estate Portal System Project Simple Real Estate Portal System26/10/202317/6/2026
A vulnerability was found in SourceCodester Simple Real Estate Portal System 1.0. It has been classified as critical. Affected is an unknown function of the file view_estate.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to…
ModificadaCrítica (9.8)1.5%—Simple Real Estate Portal System Portal Simple Real Estate Portal System21/4/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent.
ModificadaCrítica (9.8)1.5%—Simple Real Estate Portal System Project Simple Real Estate Portal System21/4/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent.
ModificadaCrítica (9.8)1.3%—Simple Real Estate Portal System Project Simple Real Estate Portal System21/4/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_estate.
ModificadaCrítica (9.8)1.3%—Simple Real Estate Portal System Project Simple Real Estate Portal System21/4/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type.
ModificadaCrítica (9.8)1.2%—Simple Real Estate Portal System Project Simple Real Estate Portal System21/4/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity.
ModificadaCrítica (9.8)1.2%—Simple Real Estate Portal System Project Simple Real Estate Portal System2/3/202217/6/2026
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
ModificadaMedia (4.3)1.1%—Netartmedia Real Estate Portal24/9/201016/6/2026
Cross-site scripting (XSS) vulnerability in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the id parameter.
ModificadaMedia (6.8)1.1%—Netartmedia Real Estate Portal24/9/201016/6/2026
Multiple directory traversal vulnerabilities in AGENTS/index.php in NetArt MEDIA Real Estate Portal 2.0 allow remote emote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) folder and (2) action parameters.
ModificadaAlta (7.5)0.91%💥 ExploitNetartmedia Real Estate Portal14/1/201016/6/2026
SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)1.0%💥 ExploitNetartmedia Media Real Estate Portal12/1/201016/6/2026
SQL injection vulnerability in realestate20/loginaction.php in NetArt Media Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the Email parameter (aka the username field). NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.97%💥 ExploitNetartmedia Real Estate Portal3/2/200916/6/2026
SQL injection vulnerability in the re_search module in NetArtMedia Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the ad parameter to index.php.
ModificadaAlta (7.5)0.97%💥 ExploitSG Real Estate Portal30/1/200916/6/2026
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.
ModificadaMedia (5)2.7%💥 ExploitSG Real Estate Portal30/1/200916/6/2026
Multiple directory traversal vulnerabilities in SG Real Estate Portal 2.0 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod, (2) page, or (3) lang parameter to index.php; or the (4) action or (5) folder parameter in a security request to admin/index.php.
ModificadaAlta (7.5)2.6%💥 ExploitSG Real Estate Portal30/1/200916/6/2026
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the Auth cookie to 1.
ModificadaAlta (7.5)1.0%💥 ExploitNetart Media Real Estate Portal2/12/200816/6/2026
SQL injection vulnerability in NetArt Media Real Estate Portal 1.2 allows remote attackers to execute arbitrary SQL commands via the ad_id parameter in the re_send_email module to index.php.
Orbitaley — Vulnerabilidades