Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.31% | — | Salesagility Suitecrm | 10/6/2024 | 17/6/2026 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the import module error view allows for a cross-site scripting attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | |
| Modificada | Crítica (9.8) | 5.7% | 💥 Exploit | Salesagility Suitecrm | 10/6/2024 | 17/6/2026 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events response entry point allows for a SQL injection attack. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | |
| Modificada | Alta (8.8) | 0.43% | — | Salesagility Suitecrm | 10/6/2024 | 17/6/2026 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax displayView controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | |
| Modificada | Alta (8.8) | 0.42% | — | Salesagility Suitecrm | 10/6/2024 | 17/6/2026 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in EmailUIAjax messages count controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | |
| Modificada | Alta (8.8) | 0.43% | — | Salesagility Suitecrm | 10/6/2024 | 17/6/2026 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in Tree data entry point. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | |
| Modificada | Alta (8.8) | 0.46% | — | Salesagility Suitecrm | 10/6/2024 | 17/6/2026 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation allows for SQL Injection in the `Alerts` controller. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | |
| Modificada | Media (6.5) | 0.32% | — | Salesagility Suitecrm | 10/6/2024 | 17/6/2026 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be reset from an unauthenticated attacker. The attacker does not get access to the new password. But this can be annoying for the user. This attack is also dependent on… | |
| Analizada | Media (5.4) | 0.28% | — | Salesagility Suitecrm | 10/6/2024 | 17/6/2026 | SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unchecked input allows for open re-direct. Versions 7.14.4 and 8.6.1 contain a fix for this issue. | |
| Analizada | Alta (8.8) | 0.86% | — | Salesagility Suitecrm | 20/2/2024 | 17/6/2026 | Suite CRM version 7.14.2 allows including local php files. This is possible because the application is vulnerable to LFI. | |
| Modificada | Media (5) | 0.46% | — | Salesagility Suitecrm | 7/2/2024 | 17/6/2026 | Suite CRM version 7.14.2 allows making arbitrary HTTP requests through the vulnerable server. This is possible because the application is vulnerable to SSRF. | |
| Modificada | Media (5.3) | 3.0% | 💥 Exploit | Salesagility Suitecrm | 21/11/2023 | 17/6/2026 | SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentication, exposing the scheme defining all object types, arguments, and functions. An attacker can obtain the GraphQL schema and understand the entire attack surface of the… | |
| Modificada | Alta (8.8) | 1.0% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Alta (8.8) | 0.96% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Media (5.4) | 0.58% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Media (5.4) | 0.43% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Crítica (9.8) | 0.69% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Alta (8.8) | 0.81% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | |
| Modificada | Media (4.3) | 0.50% | — | Salesagility Suitecrm | 14/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository salesagility/suitecrm prior to 7.14.2, 8.4.2, 7.12.14. | |
| Modificada | Media (6.5) | 0.68% | — | Salesagility Suitecrm | 3/10/2023 | 17/6/2026 | Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1. | |
| Modificada | Media (5.4) | 0.54% | — | Salesagility Suitecrm | 3/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1. | |
| Modificada | Crítica (9.1) | 2.2% | — | Salesagility Suitecrm | 3/10/2023 | 17/6/2026 | SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1. | |
| Modificada | Alta (8.8) | 0.35% | — | Salesagility Suitecrm | 11/7/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1. | |
| Modificada | Media (4.8) | 0.55% | — | Salesagility Suitecrm | 16/6/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0. | |
| Modificada | Alta (8.8) | 26% | — | Salesagility Suitecrm | 25/2/2023 | 17/6/2026 | Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9. | |
| Modificada | Alta (7.2) | 23% | — | Salesagility Suitecrm | 15/4/2022 | 17/6/2026 | SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field. |