Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
130 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 3.3% | 💥 Exploit | Saleslogix Corporation Saleslogix | 18/10/2004 | 16/6/2026 | Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request. | |
| Modificada | Media (6.4) | 2.0% | — | Best Software SaleslogixSaleslogix Corporation Saleslogix | 18/10/2004 | 16/6/2026 | slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie. | |
| Modificada | Media (5.1) | 1.6% | — | Best Software SaleslogixSaleslogix Corporation Saleslogix | 18/10/2004 | 16/6/2026 | SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port… | |
| Modificada | Alta (7.5) | 2.1% | — | Best Software SaleslogixSaleslogix Corporation Saleslogix | 14/10/2004 | 16/6/2026 | SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator. | |
| Modificada | Media (5) | 5.4% | 💥 Exploit | Saleslogix Corporation Eviewer | 3/8/2000 | 16/6/2026 | The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user. |