Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

17 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.46%—Fluentcrm PROAI27/8/202628/8/2026
Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
AplazadaMedia (4.9)0.19%—Fluentcrm PROAI24/8/202624/8/2026
Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions.
AplazadaAlta (7.6)0.38%—Fluentcrm Fluent CRM PROAI24/8/202624/8/2026
Author SQL Injection in FluentCRM Pro <= 3.1.12 versions.
AplazadaAlta (7.1)0.25%—Ultimate Project Manager CRM PROAI29/1/202617/6/2026
The Ultimate Project Manager CRM PRO version 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and password hashes from the tbl_users database table. Attackers can exploit the /frontend/get_article_suggestion/ endpoint by crafting malicious search parameters to progressively…
ModificadaCrítica (9.8)0.63%—Small CRM Project Small CRM29/12/202317/6/2026
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed.
ModificadaMedia (5.4)0.36%—Small CRM Project Small CRM20/10/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.
ModificadaMedia (5.4)0.57%—Small CRM Project Small CRM4/10/202317/6/2026
Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter.
ModificadaMedia (5.4)0.55%—Small CRM Project Small CRM27/9/202317/6/2026
A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
ModificadaMedia (6.1)0.49%—Small CRM Project Small CRM28/6/202317/6/2026
PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS).
ModificadaMedia (5.4)0.62%—Small CRM Project Small CRM26/1/202317/6/2026
A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter.
ModificadaCrítica (9.8)0.66%—Weipdcrm Project Weipdcrm2/1/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM. It has been classified as critical. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The identifier of the patch is 43bad79392332fa39e31b95268e76fbda9fec3a4. It is…
ModificadaMedia (6.1)0.51%—Weipdcrm Project Weipdcrm2/1/202317/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is 43bad79392332fa39e31b95268e76fbda9fec3a4. It is…
ModificadaAlta (8.8)1.7%—Small CRM Project Small CRM8/1/202017/6/2026
PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page.
ModificadaCrítica (9.8)1.1%—Fhcrm Project Fhcrm2/9/201817/6/2026
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the index.php/User/read limit parameter.
ModificadaCrítica (9.8)1.1%—Fhcrm Project Fhcrm2/9/201817/6/2026
An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the /index.php/Customer/read limit parameter.
ModificadaAlta (7.5)2.6%—Xrms CRM Project Xrms CRM26/10/201417/6/2026
SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, which is not properly handled by plugins/useradmin/fingeruser.php.
ModificadaMedia (6.5)7.1%—Xrms CRM Project Xrms CRM2/9/201417/6/2026
plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.