Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Xrms CRM Project Xrms CRM | 26/10/2014 | 17/6/2026 | SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, which is not properly handled by plugins/useradmin/fingeruser.php. | |
| Modificada | Media (6.5) | 7.1% | 💥 Exploit | Xrms CRM Project Xrms CRM | 2/9/2014 | 17/6/2026 | plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Xrms CRM | 5/9/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XRMS allow remote attackers to inject arbitrary web script or HTML via (1) the real name field, related to the user list; (2) the target parameter to login.php, (3) the title parameter to activities/some.php, (4) the company_name parameter to companies/some.php,… | |
| Modificada | Alta (7.5) | 1.1% | — | Xrms CRM | 5/9/2008 | 16/6/2026 | SQL injection vulnerability in admin/users/self-2.php in XRMS allows remote attackers to execute arbitrary SQL commands and modify name and email fields via unspecified vectors. | |
| Modificada | Baja (2.6) | 1.9% | 💥 Exploit | Xrms CRM | 31/7/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web script or HTML via the msg parameter to unspecified components, possibly including login.php. NOTE: this may overlap CVE-2008-1129. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Xrms CRM | 31/7/2008 | 16/6/2026 | XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, which calls the phpinfo function. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Xrms CRM | 31/7/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in activities/workflow-activities.php in XRMS CRM 1.99.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the include_directory parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Xrms CRM Xrms | 4/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/users/self.php in XRMS CRM allows remote attackers to inject arbitrary web script or HTML via the msg parameter. NOTE: some of these details are obtained from third party information. |