Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.2% | — | Salesagility Suitecrm | 28/1/2022 | 17/6/2026 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution. | |
| Modificada | Crítica (9.8) | 1.1% | — | Salesagility Suitecrm | 28/1/2022 | 17/6/2026 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion. | |
| Modificada | Alta (8.8) | 4.6% | 💥 PoC | Salesagility Suitecrm | 28/1/2022 | 17/6/2026 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution. | |
| Modificada | Alta (8.8) | 1.0% | — | Salesagility Suitecrm | 12/1/2022 | 17/6/2026 | SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive. | |
| Modificada | Media (4.3) | 1.5% | — | Microsoft Dynamics 365 Sales | 11/1/2022 | 17/6/2026 | Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability | |
| Modificada | Media (6.1) | 1.1% | — | Salesagility Suitecrm | 28/12/2021 | 17/6/2026 | A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268. | |
| Modificada | Alta (8.8) | 2.2% | 💥 PoC | Salesagility Suitecrm | 19/12/2021 | 17/6/2026 | SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date. | |
| Modificada | Crítica (9.8) | 1.5% | — | Phone Shop Sales Management System Project Phone Shop Sales Management System | 2/11/2021 | 17/6/2026 | Phone Shop Sales Managements System using PHP with Source Code 1.0 is vulnerable to authentication bypass which leads to account takeover of the admin. | |
| Modificada | Alta (8.8) | 59% | 💥 Exploit | Salesagility Suitecrm | 22/10/2021 | 17/6/2026 | SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this… | |
| Modificada | Media (4.3) | 1.2% | — | Oracle Sales Offline | 20/10/2021 | 17/6/2026 | Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Offline Template). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline.… | |
| Modificada | Media (6.5) | 0.56% | — | F-secure AtlantF-secure Cloud Protection FOR SalesforceF-secure Elements FOR Microsoft 365F-secure Internet Gatekeeper+3 | 8/10/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVRDL unpacking module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the… | |
| Modificada | Media (6.5) | 0.56% | — | F-secure AtlantF-secure Cloud Protection FOR SalesforceF-secure Elements FOR Microsoft 365F-secure Internet Gatekeeper+3 | 8/10/2021 | 17/6/2026 | A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the AVPACK module component used in certain F-Secure products can crash while scanning a fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will result in Denial-of-Service (DoS) of the Anti-Virus… | |
| Modificada | Media (5.3) | 1.8% | — | Salesagility Suitecrm | 4/10/2021 | 17/6/2026 | SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality. | |
| Modificada | Media (5.3) | 1.8% | — | Salesagility Suitecrm | 4/10/2021 | 17/6/2026 | SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality. | |
| Modificada | Alta (8.8) | 1.6% | — | Salesagility Suitecrm | 4/10/2021 | 17/6/2026 | SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation. | |
| Modificada | Alta (8) | 0.96% | — | Salesagility Suitecrm | 29/9/2021 | 17/6/2026 | In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id. | |
| Modificada | Alta (8) | 1.2% | — | Salesagility Suitecrm | 29/9/2021 | 17/6/2026 | In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access accounts module to export the data as a CSV file… | |
| Modificada | Alta (8.8) | 0.63% | — | Wpdevart Countdown AND Countup, Woocommerce Sales Timer | 28/9/2021 | 17/6/2026 | The Countdown and CountUp, WooCommerce Sales Timers WordPress plugin is vulnerable to Cross-Site Request Forgery via the save_theme function found in the ~/includes/admin/coundown_theme_page.php file due to a missing nonce check which allows attackers to inject arbitrary web scripts, in versions up to and including… | |
| Modificada | Media (5.5) | 0.41% | — | F-secure AtlantF-secure Cloud Protection FOR SalesforceF-secure Linux SecurityF-secure Elements Endpoint Protection | 7/9/2021 | 17/6/2026 | A vulnerability affecting F-Secure Antivirus engine was discovered whereby scanning WIM archive file can lead to denial-of-service (infinite loop and freezes AV engine scanner). The vulnerability can be exploit remotely by an attacker. A successful attack will result in Denial-of-Service of the Anti-Virus engine. | |
| Modificada | Media (6.1) | 1.4% | — | Salesagility Suitecrm | 18/8/2021 | 17/6/2026 | Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed. | |
| Modificada | Media (6.1) | 2.0% | — | Salesagility Suitecrm | 18/8/2021 | 17/6/2026 | Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs because text/html is blocked, but other types that allow JavaScript execution (such as text/xml) are… | |
| Modificada | Alta (7.5) | 1.1% | — | Salesforce Mule | 5/8/2021 | 17/6/2026 | XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers. | |
| Modificada | Crítica (9.8) | 1.8% | — | Phone Shop Sales Management System Project Phone Shop Sales Management System | 3/8/2021 | 17/6/2026 | Arbitrary File Upload in Sourcecodester Phone Shop Sales Management System 1.0 enables RCE. | |
| Modificada | Crítica (9.8) | 3.4% | — | Phone Shop Sales Management System Project Phone Shop Sales Management System | 30/7/2021 | 17/6/2026 | Sourcecodester Phone Shop Sales Managements System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. | |
| Modificada | Crítica (9.8) | 1.5% | — | Sales AND Inventory System Project Sales AND Inventory System | 22/7/2021 | 17/6/2026 | SQL injection vulnerability in SourceCodester Sales and Inventory System v 1.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to \ahira\admin\inventory.php. |