Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
127 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.4% | — | Dolibarr Erp/crm | 3/1/2019 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php. | |
| Modificada | Media (5.4) | 1.1% | — | Dolibarr Erp/crm | 3/1/2019 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php. | |
| Modificada | Crítica (9.8) | 1.9% | — | Dolibarr Erp/crm | 8/7/2018 | 17/6/2026 | SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the status_batch parameter. | |
| Modificada | Crítica (9.8) | 1.9% | — | Dolibarr Erp/crm | 8/7/2018 | 17/6/2026 | SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut_buy parameter. | |
| Modificada | Crítica (9.8) | 1.9% | — | Dolibarr Erp/crm | 8/7/2018 | 17/6/2026 | SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the country_id parameter. | |
| Modificada | Crítica (9.8) | 1.9% | — | Dolibarr Erp/crm | 8/7/2018 | 17/6/2026 | SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut parameter. | |
| Modificada | Alta (8.8) | 1.0% | — | Dolibarr Erp/crm | 11/4/2018 | 17/6/2026 | Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter). | |
| Modificada | Media (5.4) | 0.62% | — | Dolibarr Erp/crm | 11/4/2018 | 17/6/2026 | Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter), core/ajax/box.php (PATH_INFO), product/stats/card.php (type parameter), holiday/list.php (month_create, month_start, and month_end parameters), and don/card.php… | |
| Modificada | Alta (8.8) | 1.0% | — | Dolibarr Erp/crm | 11/4/2018 | 17/6/2026 | Dolibarr ERP/CRM is affected by multiple SQL injection vulnerabilities in versions through 7.0.0 via comm/propal/list.php (viewstatut parameter) or comm/propal/list.php (propal_statut parameter, aka search_statut parameter). | |
| Modificada | Media (5.4) | 0.62% | — | Dolibarr Erp/crm | 11/4/2018 | 17/6/2026 | Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0. | |
| Modificada | Media (5.4) | 0.90% | — | Dolibarr Erp/crm | 9/2/2018 | 17/6/2026 | Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code. | |
| Modificada | Media (6.1) | 1.0% | — | Dolibarr Erp/crm | 29/12/2017 | 17/6/2026 | The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS. | |
| Modificada | Crítica (9.8) | 1.9% | — | Dolibarr Erp/crm | 27/12/2017 | 17/6/2026 | SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter. | |
| Modificada | Crítica (9.8) | 1.9% | — | Dolibarr Erp/crm | 27/12/2017 | 17/6/2026 | SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter. | |
| Modificada | Alta (7.5) | 2.1% | — | Dolibarr Erp/crm | 27/12/2017 | 17/6/2026 | Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information. | |
| Modificada | Crítica (9.8) | 1.9% | — | Dolibarr Erp/crm | 27/12/2017 | 17/6/2026 | SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (6.8) | 0.44% | — | Dolibarr Erp/crm | 10/5/2017 | 17/6/2026 | Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation. | |
| Modificada | Crítica (9.8) | 1.1% | — | Dolibarr Erp/crm | 10/5/2017 | 17/6/2026 | Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier. | |
| Modificada | Media (6.1) | 0.95% | — | Dolibarr Erp/crm | 10/5/2017 | 17/6/2026 | Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter. | |
| Modificada | Crítica (9.8) | 1.7% | — | Dolibarr Erp/crm | 10/5/2017 | 17/6/2026 | Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter. | |
| Modificada | Media (6.5) | 2.0% | 💥 Exploit | Dolibarr Erp/crm | 11/7/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) entity parameter in an update action to user/fiche.php or (2) sortorder parameter to user/group/index.php. | |
| Modificada | Media (4.3) | 2.7% | 💥 Exploit | Dolibarr Erp/crm | 11/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) dol_use_jmobile, (2) dol_optimize_smallscreen, (3) dol_no_mouse_hover, (4) dol_hide_topmenu, (5) dol_hide_leftmenu, (6) mainmenu, or (7) leftmenu parameter to… | |
| Modificada | Alta (7.5) | 24% | 💥 Exploit | Dolibarr Erp/crm | 21/2/2012 | 16/6/2026 | Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the (1) file parameter to document.php or (2) backtopage parameter in a create action to comm/action/fiche.php. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Dolibarr Erp/crm | 21/2/2012 | 16/6/2026 | Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) memberslist parameter (aka Member List) in list.php or (2) rowid parameter to adherents/fiche.php. | |
| Modificada | Media (4.3) | 5.5% | 💥 Exploit | Dolibarr Erp/crm | 14/12/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) admin/boxes.php, (3) comm/clients.php, (4) commande/index.php; and the optioncss parameter to (5) admin/ihm.php and (6)… |