Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.33%—Realestateconnected Easy Property ListingsAI1/8/202612/8/2026
The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to, and including, 3.5.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and…
AplazadaAlta (7.1)0.54%—MicrorealestateAI7/7/20267/7/2026
Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3.
AplazadaMedia (5.3)0.36%—MicrorealestateAI7/7/20267/7/2026
Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.
AplazadaAlta (7.1)0.36%—MicrorealestateAI7/7/20267/7/2026
Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.
AplazadaAlta (7.1)0.36%—Microrealestate Micro Real EstateAI7/7/20267/7/2026
MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0-alpha3.
AplazadaAlta (8.8)0.60%—MicrorealestateAI7/7/20267/7/2026
MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through 1.0.0-alpha3.
AplazadaAlta (8.8)0.38%—Inout RealestateAI12/3/202617/6/2026
Inout RealEstate contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the city parameter. Attackers can send POST requests to the agents/agentlistdetails endpoint with malicious SQL payloads in the city parameter to extract sensitive…
AplazadaMedia (6.5)0.32%—Realestateconnected Easy Property ListingsAI22/1/202617/6/2026
Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.20.
AplazadaMedia (4.3)0.22%—Realestateconnected Easy Property ListingsAI16/12/20255/10/2026
Missing Authorization vulnerability in Merv Barrett Easy Property Listings easy-property-listings allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Property Listings: from n/a through <= 3.5.22.
AnalizadaMedia (4.8)0.31%—Realestateconnected Easy Property Listings15/5/202517/6/2026
The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
AplazadaCrítica (9.8)0.45%—WP RealestateAI1/4/202517/6/2026
The WP RealEstate plugin for WordPress, used by the Homeo theme, is vulnerable to privilege escalation in all versions up to, and including, 1.6.26. This is due to insufficient role restrictions in the 'process_register' function. This makes it possible for unauthenticated attackers to register an account with the…
AnalizadaMedia (4.3)0.23%—Realestateconnected Easy Property Listings12/9/202417/6/2026
The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting contacts in bulk, which could allow attackers to make a logged in admin delete them via a CSRF attack
AnalizadaCrítica (9.8)0.36%—Realestateconnected Easy Property Listings9/6/202417/6/2026
Missing Authorization vulnerability in Merv Barrett Easy Property Listings.This issue affects Easy Property Listings: from n/a through 3.5.3.
ModificadaAlta (8.8)0.77%—Realestateconnected Easy Property Listings9/4/202417/6/2026
The Easy Property Listings plugin for WordPress is vulnerable to time-based SQL Injection via the ‘property_status’ shortcode attribute in all versions up to, and including, 3.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it…
ModificadaCrítica (9.3)1.4%—Realestate Project Realestate11/7/202217/6/2026
The deepaliupadhyay/RealEstate repository through 2018-11-30 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (8.8)0.82%—Realestateconnected Easy Property Listings18/2/202017/6/2026
Cross-site request forgery (CSRF) vulnerability in Easy Property Listings versions prior to 3.4 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaMedia (6.1)1.00%—Realestateconnected Easy Property Listings30/8/201917/6/2026
The easy-property-listings plugin before 3.4 for WordPress has XSS.
ModificadaMedia (4.8)0.49%—Responsive Realestate Script Project Responsive Realestate Script27/12/201717/6/2026
PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter.
ModificadaAlta (8.8)0.46%—Responsive Realestate Script Project Responsive Realestate Script27/12/201717/6/2026
PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general.
ModificadaCrítica (9.8)2.2%—Responsive Realestate Script Project Responsive Realestate Script13/12/201717/6/2026
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
ModificadaCrítica (9.8)4.4%—Realestate Crowdfunding Script Project Realestate Crowdfunding Script13/12/201717/6/2026
Realestate Crowdfunding Script 2.7.2 has SQL Injection via the single-cause.php pid parameter.
ModificadaAlta (7.5)1.2%—Wcs4web Easywebrealestate4/10/201216/6/2026
Multiple SQL injection vulnerabilities in EasyWebRealEstate allow remote attackers to execute arbitrary SQL commands via the (1) lstid parameter to listings.php or (2) infoid parameter to index.php.
ModificadaAlta (7.5)1.1%—Extensionsforjoomla COM Vikrealestate15/12/201116/6/2026
Multiple SQL injection vulnerabilities in Vik Real Estate (com_vikrealestate) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) contract parameter in a results action and (2) imm parameter in a show action to index.php.
ModificadaAlta (7.5)1.0%—Eicrasoft Eicra Realestate Script21/6/201016/6/2026
SQL injection vulnerability in index.php in Eicra Realestate Script 1.0 and 1.6.0 allows remote attackers to execute arbitrary SQL commands via the p_id parameter. NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.3)1.1%—Realestatephp Real Estate Manager14/12/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Real Estate Manager 1.0.1 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. NOTE: some of these details are obtained from third party information.