Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.42% | — | Webkul Krayin CRM | 7/10/2024 | 5/7/2026 | Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. | |
| Analizada | Crítica (9.6) | 0.53% | — | Webkul Krayin CRM | 27/9/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the… | |
| Analizada | Alta (8.8) | 0.53% | — | Webkul Krayin CRM | 27/9/2024 | 17/6/2026 | A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated… | |
| Modificada | Media (5.4) | 0.59% | — | Webkul Krayin CRM | 27/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site scripting. It is possible to initiate the attack… | |
| Modificada | Media (6.1) | 0.60% | — | Webkul Krayin | 21/6/2022 | 17/6/2026 | Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). |