Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 1.00% | — | Krayin Laravel-crmAI | 27/9/2026 | 30/9/2026 | A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has… | |
| Aplazada | Baja (2.1) | 0.48% | — | Krayin Laravel CRMAI | 27/9/2026 | 28/9/2026 | A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack… | |
| Aplazada | Baja (2.1) | 0.46% | — | Krayin Laravel CRMAI | 27/9/2026 | 28/9/2026 | A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been published and may be used. Upgrading to… | |
| Aplazada | Baja (1.9) | 0.26% | — | Krayin Laravel CRMAI | 27/9/2026 | 30/9/2026 | A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross… | |
| Aplazada | Media (5.1) | 0.24% | — | Krayin Laravel-crmAI | 25/9/2026 | 29/9/2026 | A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The attack may be performed from remote. Upgrading to version 2.2.6 is capable of… | |
| Aplazada | Baja (2) | 0.24% | — | Krayin Laravel CRMAI | 25/9/2026 | 29/9/2026 | A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Functionality. The manipulation leads to cross site scripting. The attack is possible to… | |
| Aplazada | Baja (2.1) | 0.27% | — | Krayin Laravel-crmAI | 25/9/2026 | 28/9/2026 | A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing a manipulation of the argument role_id can lead to improper privilege management. The attack can… | |
| Aplazada | Media (5.1) | 0.14% | — | Webkul Krayin CRMAI | 24/9/2026 | 25/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web form description field. Attackers can craft a web form description containing… | |
| Aplazada | Media (5.1) | 0.14% | — | Webkul Krayin CRMAI | 24/9/2026 | 29/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the product name field. Attackers can craft a product name containing double-brace template… | |
| Aplazada | Media (5.1) | 0.14% | — | Webkul Krayin CRMAI | 24/9/2026 | 30/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person name field. Attackers can craft a person name containing double-brace template… | |
| Aplazada | Media (5.1) | 0.17% | — | Webkul Krayin CRMAI | 24/9/2026 | 24/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead title field. Attackers can craft a lead title containing double-brace template… | |
| Aplazada | Alta (8.8) | 0.66% | — | Webkul Krayin CRMAI | 14/9/2026 | 24/9/2026 | Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body,… | |
| Aplazada | Alta (8.7) | 0.50% | — | Webkul Krayin CRMAI | 3/8/2026 | 9/9/2026 | Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw()… | |
| Aplazada | Crítica (9.3) | 3.7% | — | Krayin CRMAI | 3/8/2026 | 9/9/2026 | Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect… | |
| Aplazada | Alta (8.7) | 0.51% | — | Krayin CRMAI | 10/7/2026 | 10/7/2026 | Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or delete records owned by other users. Attackers can modify CRM records and reassign… | |
| Aplazada | Media (5.4) | 0.30% | — | Webkul Krayin CRMAI | 7/5/2026 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint | |
| Aplazada | Alta (8.1) | 0.77% | — | Krayin CRMAI | 30/4/2026 | 17/6/2026 | An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function | |
| Analizada | Alta (8.1) | 0.41% | — | Webkul Krayin CRM | 14/4/2026 | 17/6/2026 | A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. | |
| Analizada | Alta (8.1) | 0.41% | — | Webkul Krayin CRM | 14/4/2026 | 17/6/2026 | A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. | |
| Analizada | Alta (8.8) | 0.84% | — | Webkul Krayin CRM | 14/4/2026 | 17/6/2026 | A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. | |
| Aplazada | Alta (7.1) | 0.32% | — | Krayin CRMAI | 14/4/2026 | 17/6/2026 | Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDataGrid.php. | |
| Aplazada | Alta (8.5) | 0.33% | — | Webkul Krayin CRMAI | 14/4/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. | |
| Aplazada | Crítica (9.9) | 2.4% | — | Webkul Krayin CRMAI | 14/4/2026 | 17/6/2026 | An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Aplazada | Baja (2) | 0.36% | — | Krayin Laravel-crmAI | 2/4/2026 | 24/7/2026 | A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible.… | |
| Analizada | Media (5.1) | 0.42% | — | Webkul Krayin CRM | 14/4/2025 | 17/6/2026 | A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The… |