Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2022-22113 In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has been changed by the use… Daybyday after 2.2.1 Fix from $1,9502022-01-13 MEDIUM 5.4 CVE-2022-22112 In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker… Daybyday after 2.2.1 Fix from $1,6002022-01-13 HIGH 8.8 CVE-2022-22111 In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled… Daybyday Crm Patch available Fix from $1,9502022-01-05 HIGH 7.5 CVE-2022-22110 In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his… Daybyday Crm after 2.2.0 Fix from $1,9502022-01-05 MEDIUM 5.4 CVE-2022-22109 In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store… Daybyday Crm Patch available Fix from $1,6002022-01-05 MEDIUM 5.4 CVE-2020-35707 Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen. Daybyday No fix yet Fix from $1,6002020-12-25 MEDIUM 5.4 CVE-2020-35705 Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen. Daybyday No fix yet Fix from $1,6002020-12-25 MEDIUM 5.4 CVE-2020-35706 Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen. Daybyday No fix yet Fix from $1,6002020-12-25 MEDIUM 5.4 CVE-2020-35704 Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen. Daybyday No fix yet Fix from $1,6002020-12-25