Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

127 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9)0.15%—Dolibarr ERP CRMAI12/2/202617/6/2026
Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php NOTE: this is disputed by a third party who indicates that exploitation can only occur if an unprivileged user knows the token of an admin user.
ModificadaAlta (8.4)0.36%—Dolibarr Erp/crm16/1/202617/6/2026
Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an administrator copies the text, potentially…
ModificadaAlta (8.8)0.50%—Dolibarr Erp/crm1/10/20255/7/2026
Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter.
AplazadaCrítica (9.4)4.4%💥 ExploitDolibarr ERP CRMAI13/8/202516/6/2026
Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitrary system commands, resulting in remote code execution on the…
AplazadaAlta (7.5)0.38%—Fire Safety Finder ERP CRMAI6/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety Finder ERP/CRM (New System) allows SQL Injection. This issue affects Finder ERP/CRM (New System): before 18.12.2024.
AplazadaCrítica (9.8)0.44%—Finder Fire Safety Finder ERP CRMAI6/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Finder Fire Safety Finder ERP/CRM (Old System) allows SQL Injection. This issue affects Finder ERP/CRM (Old System): before 18.12.2024.
ModificadaCrítica (9)0.72%—Dolibarr Erp/crm27/1/202517/6/2026
A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.
ModificadaCrítica (9)0.61%—Dolibarr Erp/crm27/1/202517/6/2026
A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.
AnalizadaMedia (4.3)0.32%—Dolibarr Erp/crm15/11/202417/6/2026
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.
AplazadaMedia (5.5)0.68%—Dolibarr ERP CRMAI24/7/202417/6/2026
Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function.
ModificadaAlta (8.8)0.76%—Dolibarr Erp/crm18/6/20249/7/2026
An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.
AnalizadaCrítica (9.1)35%💥 ExploitDolibarr Erp/crm24/5/202417/6/2026
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.
AnalizadaCrítica (9.1)0.56%—Dolibarr Erp/crm24/5/202417/6/2026
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in…
AnalizadaAlta (7.5)0.26%—Dolibarr Erp/crm17/4/202417/6/2026
Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CSRF protection tokens via user interaction with a crafted web page, leading to account takeover.
ModificadaAlta (8.8)0.81%—Dolibarr Erp/crm3/4/20249/7/2026
Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.
ModificadaMedia (6.1)0.56%—Dolibarr Erp/crm25/1/202417/6/2026
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page of the Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the…
ModificadaMedia (6.5)0.56%—Dolibarr Erp/crm1/11/202317/6/2026
Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data
ModificadaAlta (8.8)33%💥 PoCDolibarr Erp/crm1/11/202317/6/2026
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
ModificadaMedia (4.8)0.46%—Dolibarr Erp/crm30/10/202317/6/2026
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.
ModificadaMedia (6.1)0.44%—Dolibarr Erp/crm1/10/202317/6/2026
Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.
ModificadaCrítica (9.6)1.3%—Dolibarr Erp/crm20/9/20239/7/2026
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
ModificadaAlta (8.8)1.5%—Dolibarr Erp/crm20/9/20239/7/2026
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
ModificadaAlta (7.2)32%—Dolibarr Erp/crm20/9/20239/7/2026
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
ModificadaAlta (7.5)15%💥 ExploitDolibarr Erp/crm13/6/202317/6/2026
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
ModificadaAlta (8.8)82%💥 ExploitDolibarr Erp/crm29/5/202317/6/2026
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
Orbitaley — Vulnerabilidades