Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9) | 0.15% | — | Dolibarr ERP CRMAI | 12/2/2026 | 17/6/2026 | Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php NOTE: this is disputed by a third party who indicates that exploitation can only occur if an unprivileged user knows the token of an admin user. | |
| Modificada | Alta (8.4) | 0.36% | — | Dolibarr Erp/crm | 16/1/2026 | 17/6/2026 | Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the text, potentially… | |
| Modificada | Alta (8.8) | 0.50% | — | Dolibarr Erp/crm | 1/10/2025 | 5/7/2026 | Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter. | |
| Aplazada | Crítica (9.4) | 4.4% | 💥 Exploit | Dolibarr ERP CRMAI | 13/8/2025 | 16/6/2026 | Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitrary system commands, resulting in remote code execution on the… | |
| Aplazada | Alta (7.5) | 0.38% | — | Fire Safety Finder ERP CRMAI | 6/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety Finder ERP/CRM (New System) allows SQL Injection. This issue affects Finder ERP/CRM (New System): before 18.12.2024. | |
| Aplazada | Crítica (9.8) | 0.44% | — | Finder Fire Safety Finder ERP CRMAI | 6/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety Finder ERP/CRM (Old System) allows SQL Injection. This issue affects Finder ERP/CRM (Old System): before 18.12.2024. | |
| Modificada | Crítica (9) | 0.72% | — | Dolibarr Erp/crm | 27/1/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter. | |
| Modificada | Crítica (9) | 0.61% | — | Dolibarr Erp/crm | 27/1/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter. | |
| Analizada | Media (4.3) | 0.32% | — | Dolibarr Erp/crm | 15/11/2024 | 17/6/2026 | An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions. | |
| Aplazada | Media (5.5) | 0.68% | — | Dolibarr ERP CRMAI | 24/7/2024 | 17/6/2026 | Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function. | |
| Modificada | Alta (8.8) | 0.76% | — | Dolibarr Erp/crm | 18/6/2024 | 9/7/2026 | An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file. | |
| Analizada | Crítica (9.1) | 35% | 💥 Exploit | Dolibarr Erp/crm | 24/5/2024 | 17/6/2026 | Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php. | |
| Analizada | Crítica (9.1) | 0.56% | — | Dolibarr Erp/crm | 24/5/2024 | 17/6/2026 | Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in… | |
| Analizada | Alta (7.5) | 0.26% | — | Dolibarr Erp/crm | 17/4/2024 | 17/6/2026 | Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CSRF protection tokens via user interaction with a crafted web page, leading to account takeover. | |
| Modificada | Alta (8.8) | 0.81% | — | Dolibarr Erp/crm | 3/4/2024 | 9/7/2026 | Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input. | |
| Modificada | Media (6.1) | 0.56% | — | Dolibarr Erp/crm | 25/1/2024 | 17/6/2026 | Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page of the Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the… | |
| Modificada | Media (6.5) | 0.56% | — | Dolibarr Erp/crm | 1/11/2023 | 17/6/2026 | Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data | |
| Modificada | Alta (8.8) | 33% | 💥 PoC | Dolibarr Erp/crm | 1/11/2023 | 17/6/2026 | Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code. | |
| Modificada | Media (4.8) | 0.46% | — | Dolibarr Erp/crm | 30/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5. | |
| Modificada | Media (6.1) | 0.44% | — | Dolibarr Erp/crm | 1/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0. | |
| Modificada | Crítica (9.6) | 1.3% | — | Dolibarr Erp/crm | 20/9/2023 | 9/7/2026 | Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject. | |
| Modificada | Alta (8.8) | 1.5% | — | Dolibarr Erp/crm | 20/9/2023 | 9/7/2026 | File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions. | |
| Modificada | Alta (7.2) | 32% | — | Dolibarr Erp/crm | 20/9/2023 | 9/7/2026 | An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Dolibarr Erp/crm | 13/6/2023 | 17/6/2026 | An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists. | |
| Modificada | Alta (8.8) | 82% | 💥 Exploit | Dolibarr Erp/crm | 29/5/2023 | 17/6/2026 | Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data. |