Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

124 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)53%💥 PoCSalesagility Suitecrm10/3/202217/6/2026
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a…
ModificadaMedia (6.5)0.62%—Salesagility Suitecrm7/3/202217/6/2026
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
ModificadaMedia (4.3)0.66%—Salesagility Suitecrm7/3/202217/6/2026
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
ModificadaMedia (6.5)0.82%—Salesagility Suitecrm7/3/202217/6/2026
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.
ModificadaCrítica (9.8)2.2%—Salesagility Suitecrm28/1/202217/6/2026
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
ModificadaCrítica (9.8)1.1%—Salesagility Suitecrm28/1/202217/6/2026
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
ModificadaAlta (8.8)4.6%💥 PoCSalesagility Suitecrm28/1/202217/6/2026
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
ModificadaAlta (8.8)1.0%—Salesagility Suitecrm12/1/202217/6/2026
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive.
ModificadaMedia (6.1)1.1%—Salesagility Suitecrm28/12/202117/6/2026
A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268.
ModificadaAlta (8.8)2.2%💥 PoCSalesagility Suitecrm19/12/202117/6/2026
SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date.
ModificadaAlta (8.8)59%💥 ExploitSalesagility Suitecrm22/10/202117/6/2026
SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this…
ModificadaMedia (5.3)1.8%—Salesagility Suitecrm4/10/202117/6/2026
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality.
ModificadaMedia (5.3)1.8%—Salesagility Suitecrm4/10/202117/6/2026
SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality.
ModificadaAlta (8.8)1.6%—Salesagility Suitecrm4/10/202117/6/2026
SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation.
ModificadaAlta (8)0.96%—Salesagility Suitecrm29/9/202117/6/2026
In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id.
ModificadaAlta (8)1.2%—Salesagility Suitecrm29/9/202117/6/2026
In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access accounts module to export the data as a CSV file…
ModificadaMedia (6.1)1.4%—Salesagility Suitecrm18/8/202117/6/2026
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed.
ModificadaMedia (6.1)2.0%—Salesagility Suitecrm18/8/202117/6/2026
Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs because text/html is blocked, but other types that allow JavaScript execution (such as text/xml) are…
ModificadaMedia (5.4)0.87%—Salesagility Suitecrm30/4/202117/6/2026
XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field
ModificadaMedia (6.1)0.71%—Salesagility Suitecrm18/11/202017/6/2026
SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document.
ModificadaMedia (5.4)0.64%—Salesagility Suitecrm18/11/202017/6/2026
SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML.
ModificadaAlta (7.8)0.79%—Salesagility Suitecrm18/11/202017/6/2026
SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation.
ModificadaAlta (8.8)63%💥 ExploitSalesagility Suitecrm6/11/202017/6/2026
SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root.
ModificadaAlta (7.5)1.0%—Suitecrm20/3/202017/6/2026
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials.
ModificadaMedia (5.3)0.87%—Salesagility Suitecrm20/3/202017/6/2026
SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism.
Orbitaley — Vulnerabilidades