Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.46% | — | Fluentcrm PROAI | 27/8/2026 | 28/8/2026 | Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions. | |
| Aplazada | Media (4.9) | 0.19% | — | Fluentcrm PROAI | 24/8/2026 | 24/8/2026 | Subscriber Server Side Request Forgery (SSRF) in FluentCRM Pro <= 3.1.12 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | Fluentcrm Fluent CRM PROAI | 24/8/2026 | 24/8/2026 | Author SQL Injection in FluentCRM Pro <= 3.1.12 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Ultimate Project Manager CRM PROAI | 29/1/2026 | 17/6/2026 | The Ultimate Project Manager CRM PRO version 2.0.5 contains a blind SQL injection vulnerability that allows attackers to extract usernames and password hashes from the tbl_users database table. Attackers can exploit the /frontend/get_article_suggestion/ endpoint by crafting malicious search parameters to progressively… | |
| Modificada | Crítica (9.8) | 0.63% | — | Small CRM Project Small CRM | 29/12/2023 | 17/6/2026 | PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection on the Users login panel because of "password" parameter is directly used in the SQL query without any sanitization and the SQL Injection payload being executed. | |
| Modificada | Media (5.4) | 0.36% | — | Small CRM Project Small CRM | 20/10/2023 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover. | |
| Modificada | Media (5.4) | 0.57% | — | Small CRM Project Small CRM | 4/10/2023 | 17/6/2026 | Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter. | |
| Modificada | Media (5.4) | 0.55% | — | Small CRM Project Small CRM | 27/9/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Add User function of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | |
| Modificada | Media (6.1) | 0.49% | — | Small CRM Project Small CRM | 28/6/2023 | 17/6/2026 | PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Media (5.4) | 0.62% | — | Small CRM Project Small CRM | 26/1/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Create Ticket page of Small CRM v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject parameter. | |
| Modificada | Crítica (9.8) | 0.66% | — | Weipdcrm Project Weipdcrm | 2/1/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM. It has been classified as critical. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The identifier of the patch is 43bad79392332fa39e31b95268e76fbda9fec3a4. It is… | |
| Modificada | Media (6.1) | 0.51% | — | Weipdcrm Project Weipdcrm | 2/1/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in 82Flex WEIPDCRM and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. The name of the patch is 43bad79392332fa39e31b95268e76fbda9fec3a4. It is… | |
| Modificada | Alta (8.8) | 1.7% | — | Small CRM Project Small CRM | 8/1/2020 | 17/6/2026 | PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page. | |
| Modificada | Crítica (9.8) | 1.1% | — | Fhcrm Project Fhcrm | 2/9/2018 | 17/6/2026 | An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the index.php/User/read limit parameter. | |
| Modificada | Crítica (9.8) | 1.1% | — | Fhcrm Project Fhcrm | 2/9/2018 | 17/6/2026 | An issue was discovered in FHCRM through 2018-02-11. There is a SQL injection via the /index.php/Customer/read limit parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | Xrms CRM Project Xrms CRM | 26/10/2014 | 17/6/2026 | SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, which is not properly handled by plugins/useradmin/fingeruser.php. | |
| Modificada | Media (6.5) | 7.1% | — | Xrms CRM Project Xrms CRM | 2/9/2014 | 17/6/2026 | plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter. |