Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 53% | 💥 PoC | Salesagility Suitecrm | 10/3/2022 | 17/6/2026 | SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achieve this by leveraging PHP deserialization in the email_recipients property. By using a crafted request, they can create a malicious report, containing a… | |
| Modificada | Media (6.5) | 0.62% | — | Salesagility Suitecrm | 7/3/2022 | 17/6/2026 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | |
| Modificada | Media (4.3) | 0.66% | — | Salesagility Suitecrm | 7/3/2022 | 17/6/2026 | Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5. | |
| Modificada | Media (6.5) | 0.82% | — | Salesagility Suitecrm | 7/3/2022 | 17/6/2026 | SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5. | |
| Modificada | Crítica (9.8) | 2.2% | — | Salesagility Suitecrm | 28/1/2022 | 17/6/2026 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution. | |
| Modificada | Crítica (9.8) | 1.1% | — | Salesagility Suitecrm | 28/1/2022 | 17/6/2026 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion. | |
| Modificada | Alta (8.8) | 4.6% | 💥 PoC | Salesagility Suitecrm | 28/1/2022 | 17/6/2026 | SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution. | |
| Modificada | Alta (8.8) | 1.0% | — | Salesagility Suitecrm | 12/1/2022 | 17/6/2026 | SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included in a ZIP archive. | |
| Modificada | Media (6.1) | 1.1% | — | Salesagility Suitecrm | 28/12/2021 | 17/6/2026 | A persistent cross-site scripting (XSS) issue in the web interface of SuiteCRM before 7.10.35, and 7.11.x and 7.12.x before 7.12.2, allows a remote attacker to introduce arbitrary JavaScript via attachments upload, a different vulnerability than CVE-2021-39267 and CVE-2021-39268. | |
| Modificada | Alta (8.8) | 2.2% | 💥 PoC | Salesagility Suitecrm | 19/12/2021 | 17/6/2026 | SuiteCRM before 7.12.2 and 8.x before 8.0.1 allows authenticated SQL injection via the Tooltips action in the Project module, involving resource_id and start_date. | |
| Modificada | Alta (8.8) | 59% | 💥 Exploit | Salesagility Suitecrm | 22/10/2021 | 17/6/2026 | SuiteCRM before 7.11.19 allows remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled PHP file under the web root, because only the all-lowercase PHP file extensions were blocked. NOTE: this… | |
| Modificada | Media (5.3) | 1.8% | — | Salesagility Suitecrm | 4/10/2021 | 17/6/2026 | SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the importFile parameter of the RefreshMapping import functionality. | |
| Modificada | Media (5.3) | 1.8% | — | Salesagility Suitecrm | 4/10/2021 | 17/6/2026 | SuiteCRM before 7.10.33 and 7.11.22 allows information disclosure via Directory Traversal. An attacker can partially include arbitrary files via the file_name parameter of the Step3 import functionality. | |
| Modificada | Alta (8.8) | 1.6% | — | Salesagility Suitecrm | 4/10/2021 | 17/6/2026 | SuiteCRM 7.10.x before 7.10.33 and 7.11.x before 7.11.22 is vulnerable to privilege escalation. | |
| Modificada | Alta (8) | 0.96% | — | Salesagility Suitecrm | 29/9/2021 | 17/6/2026 | In “SuiteCRM” application, v7.1.7 through v7.10.31 and v7.11-beta through v7.11.20 fail to properly invalidate password reset links that is associated with a deleted user id, which makes it possible for account takeover of any newly created user with the same user id. | |
| Modificada | Alta (8) | 1.2% | — | Salesagility Suitecrm | 29/9/2021 | 17/6/2026 | In “SuiteCRM” application, v7.11.18 through v7.11.19 and v7.10.29 through v7.10.31 are affected by “CSV Injection” vulnerability (Formula Injection). A low privileged attacker can use accounts module to inject payloads in the input fields. When an administrator access accounts module to export the data as a CSV file… | |
| Modificada | Media (6.1) | 1.4% | — | Salesagility Suitecrm | 18/8/2021 | 17/6/2026 | Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via malicious SVG files. This occurs because the clean_file_output protection mechanism can be bypassed. | |
| Modificada | Media (6.1) | 2.0% | — | Salesagility Suitecrm | 18/8/2021 | 17/6/2026 | Persistent cross-site scripting (XSS) in the web interface of SuiteCRM before 7.11.19 allows a remote attacker to introduce arbitrary JavaScript via a Content-Type Filter bypass to upload malicious files. This occurs because text/html is blocked, but other types that allow JavaScript execution (such as text/xml) are… | |
| Modificada | Media (5.4) | 0.87% | — | Salesagility Suitecrm | 30/4/2021 | 17/6/2026 | XSS in the client account page in SuiteCRM before 7.11.19 allows an attacker to inject JavaScript via the name field | |
| Modificada | Media (6.1) | 0.71% | — | Salesagility Suitecrm | 18/11/2020 | 17/6/2026 | SuiteCRM through 7.11.13 has an Open Redirect in the Documents module via a crafted SVG document. | |
| Modificada | Media (5.4) | 0.64% | — | Salesagility Suitecrm | 18/11/2020 | 17/6/2026 | SuiteCRM 7.11.13 is affected by stored Cross-Site Scripting (XSS) in the Documents preview functionality. This vulnerability could allow remote authenticated attackers to inject arbitrary web script or HTML. | |
| Modificada | Alta (7.8) | 0.79% | — | Salesagility Suitecrm | 18/11/2020 | 17/6/2026 | SuiteCRM through 7.11.13 allows CSV Injection via registration fields in the Accounts, Contacts, Opportunities, and Leads modules. These fields are mishandled during a Download Import File Template operation. | |
| Modificada | Alta (8.8) | 63% | 💥 Exploit | Salesagility Suitecrm | 6/11/2020 | 17/6/2026 | SuiteCRM before 7.11.17 is vulnerable to remote code execution via the system settings Log File Name setting. In certain circumstances involving admin account takeover, logger_file_name can refer to an attacker-controlled .php file under the web root. | |
| Modificada | Alta (7.5) | 1.0% | — | Suitecrm | 20/3/2020 | 17/6/2026 | SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 mishandles API access tokens and credentials. | |
| Modificada | Media (5.3) | 0.87% | — | Salesagility Suitecrm | 20/3/2020 | 17/6/2026 | SuiteCRM 7.10.x prior to 7.10.21 and 7.11.x prior to 7.11.9 does not correctly implement the .htaccess protection mechanism. |