Vulnerabilities
Summary — last 7 days
New vulnerabilities2,965▲ 27 vs. last week
Critical / high1,456▲ 193 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)272▼ 254 vs. last week
115 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (2.1) | 0.43% | — | Defaultfunction Customer Relationship Management IN C ProjectAI | 8/16/2026 | 8/20/2026 | A weakness has been identified in DefaultFuction Customer-Relationship-Management-In-C-Project 2.0. Impacted is the function gets of the component Customer Search Module. This manipulation causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available to the public and… | |
| Deferred | Low (2) | 0.33% | — | Sourcecodester Simple Customer Relationship Management SystemAI | 4/2/2026 | 6/17/2026 | A vulnerability was determined in SourceCodester Simple Customer Relationship Management System 1.0. This issue affects some unknown processing of the file /create-ticket.php of the component Create Ticket. This manipulation of the argument Description causes cross site scripting. Remote exploitation of the attack is… | |
| Deferred | Medium (5.5) | 0.51% | — | Defaultfuction Jeson Customer Relationship Management SystemAI | 3/24/2026 | 6/17/2026 | A security vulnerability has been detected in DefaultFuction Jeson-Customer-Relationship-Management-System up to 1b4679c4d06b90d31dd521c2b000bfdec5a36e00. This affects an unknown function of the file /api/System.php of the component API Module. The manipulation of the argument url leads to server-side request forgery.… | |
| Deferred | Low (2.1) | 0.35% | — | Defaultfuction Jeson Customer Relationship Management SystemAI | 3/6/2026 | 6/17/2026 | A vulnerability was detected in DefaultFuction Jeson Customer Relationship Management System 1.0.0. Impacted is an unknown function of the file /modules/customers/edit.php. Performing a manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit is now public and may be… | |
| Analyzed | High (7.5) | 0.41% | — | Oracle Siebel Customer Relationship Management Deployment | 1/20/2026 | 6/17/2026 | Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure). Supported versions that are affected are 17.0-25.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Siebel CRM Deployment. Successful attacks of this… | |
| Analyzed | Low (2.1) | 0.30% | — | 07flycms07fly Customer Relationship Management | 7/6/2025 | 6/17/2026 | A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is… | |
| Analyzed | Medium (4.3) | 0.17% | — | 07fly Customer Relationship Management | 1/16/2025 | 6/17/2026 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html | |
| Analyzed | Medium (4.3) | 0.17% | — | 07fly Customer Relationship Management | 1/16/2025 | 6/17/2026 | 07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html. | |
| Analyzed | Medium (5.1) | 0.63% | — | 07flycms07fly Customer Relationship Management | 10/13/2024 | 6/17/2026 | A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pictureUpload. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Analyzed | Medium (5.1) | 0.63% | — | 07flycms07fly Customer Relationship Management | 10/12/2024 | 6/17/2026 | A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The manipulation of the argument file leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been… | |
| Analyzed | Medium (5.1) | 0.42% | — | 07flycms07fly Customer Relationship Management | 10/11/2024 | 6/17/2026 | A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the component System Settings Page. The manipulation of the argument Login Interface Copyright leads to cross site scripting. The attack may be launched… | |
| Analyzed | Medium (5.1) | 0.63% | — | 07flycms07fly Customer Relationship Management | 10/11/2024 | 6/17/2026 | A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of the file /admin/SysModule/upload/ajaxmodel/upload/uploadfilepath/sysmodule_1 of the component Module Plug-In Handler. The manipulation of the argument file… | |
| Modified | Medium (6.5) | 0.30% | — | SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI | 7/9/2024 | 6/17/2026 | SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information. | |
| Modified | High (7.7) | 0.31% | — | SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI | 7/9/2024 | 6/17/2026 | SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application. | |
| Modified | Medium (6.1) | 0.26% | — | SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI | 7/9/2024 | 6/17/2026 | Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application. | |
| Modified | Medium (6.1) | 0.27% | — | SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI | 7/9/2024 | 6/17/2026 | — | |
| Modified | Medium (6.1) | 0.27% | — | SAP Customer Relationship Management Webclient UI | 6/11/2024 | 6/17/2026 | Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on… | |
| Analyzed | Medium (5.4) | 0.64% | — | Oretnom23 Simple Customer Relationship Management System | 5/14/2024 | 6/17/2026 | SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php. | |
| Analyzed | Medium (5.4) | 0.61% | — | Oretnom23 Simple Customer Relationship Management System | 5/14/2024 | 6/17/2026 | Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s). | |
| Analyzed | Medium (4.3) | 0.38% | — | Oracle Customer Relationship Management Technical Foundation | 4/16/2024 | 6/17/2026 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.… | |
| Analyzed | Medium (4.3) | 0.46% | — | Oracle Customer Relationship Management Technical Foundation | 2/17/2024 | 6/17/2026 | Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Admin Console). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.… | |
| Modified | Medium (6.5) | 1.0% | — | Yetiforce Customer Relationship Management | 2/16/2024 | 6/17/2026 | Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component. | |
| Modified | Critical (9.8) | 0.82% | — | 07fly Customer Relationship Management | 9/17/2023 | 6/17/2026 | A vulnerability, which was classified as critical, has been found in 07FLY CRM V2. This issue affects some unknown processing of the file /index.php/sysmanage/Login/login_auth/ of the component Administrator Login Page. The manipulation of the argument account leads to sql injection. The attack may be initiated… | |
| Modified | Critical (9.8) | 0.85% | — | Simple Customer Relationship Management Project Simple Customer Relationship Management | 6/16/2023 | 6/17/2026 | Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter. | |
| Modified | Medium (6.1) | 0.41% | — | SAP Customer Relationship Management Abap | 6/13/2023 | 6/17/2026 | SAP CRM ABAP (Grantor Management) - versions 700, 701, 702, 712, 713, 714, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application. |