Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2022-22113
In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has been changed by the use…
Daybyday
after 2.2.1
MEDIUM 5.4
CVE-2022-22112
In DayByDay CRM, versions 1.1 through 2.2.1 (latest) suffer from an application-wide Client-Side Template Injection (CSTI). A low privileged attacker…
Daybyday
after 2.2.1
HIGH 8.8
CVE-2022-22111
In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled…
Daybyday Crm
Patch available
HIGH 7.5
CVE-2022-22110
In Daybyday CRM, versions 1.1 through 2.2.0 enforce weak password requirements in the user update functionality. A user with privileges to update his…
Daybyday Crm
after 2.2.0
MEDIUM 5.4
CVE-2022-22109
In Daybyday CRM, version 2.2.0 is vulnerable to Stored Cross-Site Scripting (XSS) vulnerability that allows low privileged application users to store…
Daybyday Crm
Patch available
MEDIUM 5.4
CVE-2020-35707
Daybyday 2.1.0 allows stored XSS via the Company Name parameter to the New Client screen.
Daybyday
No fix yet
MEDIUM 5.4
CVE-2020-35705
Daybyday 2.1.0 allows stored XSS via the Name parameter to the New User screen.
Daybyday
No fix yet
MEDIUM 5.4
CVE-2020-35706
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Project screen.
Daybyday
No fix yet
MEDIUM 5.4
CVE-2020-35704
Daybyday 2.1.0 allows stored XSS via the Title parameter to the New Lead screen.
Daybyday
No fix yet