Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2018-19992 A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the … Dolibarr Erp\/crm Patch available Fix from $1,6002019-01-03 MEDIUM 6.1 CVE-2018-19799 Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS. Dolibarr after 8.0.3 Fix from $1,6002018-12-26 CRITICAL 9.8 CVE-2018-13447 SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the s… Dolibarr Erp\/crm Patch available Fix from $2,3002018-07-08 CRITICAL 9.8 CVE-2018-13448 SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the c… Dolibarr Erp\/crm Patch available Fix from $2,3002018-07-08 CRITICAL 9.8 CVE-2018-13449 SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the s… Dolibarr Erp\/crm Patch available Fix from $2,3002018-07-08 CRITICAL 9.8 CVE-2018-13450 SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the s… Dolibarr Erp\/crm Patch available Fix from $2,3002018-07-08 CRITICAL 9.8 CVE-2018-10094EPSS 71% SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer paramete… Dolibarr 7.0.2+ Fix from $2,3002018-05-22 CRITICAL 9.8 CVE-2018-9019 SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to… Dolibarr 7.0.2+ Fix from $2,3002018-05-22 HIGH 8.0 CVE-2018-10092 The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus … Dolibarr 7.0.2+ Fix from $1,9502018-05-22 MEDIUM 6.1 CVE-2018-10095EPSS 87% Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin… Dolibarr 7.0.2+ Fix from $1,6002018-05-22 HIGH 8.8 CVE-2017-18260 Dolibarr ERP/CRM is affected by multiple SQL injection vulnerabilities in versions through 7.0.0 via comm/propal/list.php (viewstatut parameter) or c… Dolibarr Erp\/crm after 7.0.0 Fix from $1,9502018-04-11 HIGH 8.8 CVE-2017-9839 Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter). Dolibarr Erp\/crm 5.0.4+ Fix from $1,9502018-04-11 MEDIUM 5.4 CVE-2017-18259 Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0. Dolibarr Erp\/crm after 7.0.0 Fix from $1,6002018-04-11 MEDIUM 5.4 CVE-2017-9838 Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter… Dolibarr Erp\/crm 5.0.4+ Fix from $1,6002018-04-11 MEDIUM 5.4 CVE-2017-1000509 Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code. Dolibarr Erp\/crm No fix yet Fix from $1,6002018-02-09 MEDIUM 6.1 CVE-2017-17971 The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscrol… Dolibarr Erp\/crm No fix yet Fix from $1,6002017-12-29 CRITICAL 9.8 CVE-2017-17900 SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the so… Dolibarr Erp\/crm Patch available Fix from $2,3002017-12-27 CRITICAL 9.8 CVE-2017-17897 SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the… Dolibarr Erp\/crm Patch available Fix from $2,3002017-12-27 CRITICAL 9.8 CVE-2017-17899 SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL com… Dolibarr Erp\/crm Patch available Fix from $2,3002017-12-27 HIGH 7.5 CVE-2017-17898 Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information. Dolibarr Erp\/crm Patch available Fix from $1,9502017-12-27 CRITICAL 9.8 CVE-2017-14238 SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via t… Dolibarr Patch available Fix from $2,3002017-09-11 CRITICAL 9.8 CVE-2017-14242 SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parame… Dolibarr Patch available Fix from $2,3002017-09-11 HIGH 7.5 CVE-2017-14240 There is a sensitive information disclosure vulnerability in document.php in Dolibarr ERP/CRM version 6.0.0 via the file parameter. Dolibarr Patch available Fix from $1,9502017-09-11 MEDIUM 5.4 CVE-2017-14239 Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML… Dolibarr Patch available Fix from $1,6002017-09-11 MEDIUM 5.4 CVE-2017-14241 Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the T… Dolibarr Patch available Fix from $1,6002017-09-11 HIGH 8.8 CVE-2017-9840 Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within t… Dolibarr after 5.0.3 Fix from $1,9502017-06-25 CRITICAL 9.8 CVE-2017-9435 Dolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in user/index.php (search_supervisor and search_statut parameters). Dolibarr after 5.0.2 Fix from $2,3002017-06-05 CRITICAL 9.8 CVE-2017-7886 Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter. Dolibarr Erp\/crm No fix yet Fix from $2,3002017-05-10 CRITICAL 9.8 CVE-2017-7888 Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier. Dolibarr Erp\/crm No fix yet Fix from $2,3002017-05-10 MEDIUM 6.8 CVE-2017-8879 Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to ob… Dolibarr Erp\/crm No fix yet Fix from $1,6002017-05-10