Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.2% | — | Best Software SaleslogixSaleslogix Corporation Saleslogix | 18/10/2004 | 16/6/2026 | SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables. | |
| Modificada | Media (5) | 3.3% | — | Saleslogix Corporation Saleslogix | 18/10/2004 | 16/6/2026 | Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request. | |
| Modificada | Alta (7.5) | 1.5% | — | Best Software SaleslogixSaleslogix Corporation Saleslogix | 18/10/2004 | 16/6/2026 | SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation. | |
| Modificada | Media (5.1) | 1.6% | — | Best Software SaleslogixSaleslogix Corporation Saleslogix | 18/10/2004 | 16/6/2026 | SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port… | |
| Modificada | Media (5) | 1.8% | — | Best Software SaleslogixSaleslogix Corporation Saleslogix | 18/10/2004 | 16/6/2026 | slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message. | |
| Modificada | Media (5) | 1.8% | — | Best Software SaleslogixSaleslogix Corporation Saleslogix | 18/10/2004 | 16/6/2026 | SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access. | |
| Modificada | Media (6.4) | 2.0% | — | Best Software SaleslogixSaleslogix Corporation Saleslogix | 18/10/2004 | 16/6/2026 | slxweb.dll in SalesLogix 6.1 allows remote attackers to cause a denial service (application crash) via an invalid HTTP request, which might also leak sensitive information in the ErrorLogMsg cookie. | |
| Modificada | Alta (7.5) | 2.1% | — | Best Software SaleslogixSaleslogix Corporation Saleslogix | 14/10/2004 | 16/6/2026 | SalesLogix 6.1 allows remote attackers to bypass authentication by modifying the slxweb cookie to set user=Admin, teams=ADMIN!, and usertype=Administrator. | |
| Modificada | Media (5) | 5.4% | — | Saleslogix Corporation Eviewer | 3/8/2000 | 16/6/2026 | The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll administration program, which does not authenticate the user. |