Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.4
CVE-2024-36413
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in the im…
Suitecrm
7.14.4 / 8.6.1+
CRITICAL 9.8
CVE-2024-36412EPSS 6%
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a vulnerability in events…
Suitecrm
7.14.4 / 8.6.1+
HIGH 8.8
CVE-2024-36411
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation …
Suitecrm
7.14.4 / 8.6.1+
HIGH 8.8
CVE-2024-36409
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation …
Suitecrm
7.14.4 / 8.6.1+
HIGH 8.8
CVE-2024-36410
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation …
Suitecrm
7.14.4 / 8.6.1+
HIGH 8.8
CVE-2024-36408
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, poor input validation …
Suitecrm
7.14.4 / 8.6.1+
MEDIUM 6.5
CVE-2024-36407
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, a user password can be…
Suitecrm
7.14.4 / 8.6.1+
MEDIUM 5.4
CVE-2024-36406
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. In versions prior to 7.14.4 and 8.6.1, unchecked input allows…
Suitecrm
7.14.4 / 8.6.1+
HIGH 8.8
CVE-2024-1644
Suite CRM version 7.14.2 allows including local php files. This is possible
because the application is vulnerable to LFI.
Suitecrm
No fix yet
MEDIUM 5.0
CVE-2023-6388
Suite CRM version 7.14.2 allows making arbitrary HTTP requests through
the vulnerable server. This is possible because the application is vulnerable…
Suitecrm
No fix yet
MEDIUM 5.3
CVE-2023-47643
SuiteCRM is a Customer Relationship Management (CRM) software application. Prior to version 8.4.2, Graphql Introspection is enabled without authentic…
Suitecrm
Patch available
HIGH 8.8
CVE-2023-6130
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Suitecrm
7.12.14+
HIGH 8.8
CVE-2023-6131
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Suitecrm
7.12.14+
MEDIUM 5.4
CVE-2023-6127
Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Suitecrm
7.12.14+
MEDIUM 5.4
CVE-2023-6128
Cross-site Scripting (XSS) - Reflected in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Suitecrm
7.12.14+
CRITICAL 9.8
CVE-2023-6126
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Suitecrm
7.12.14+
HIGH 8.8
CVE-2023-6125
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
Suitecrm
7.12.14+
MEDIUM 6.5
CVE-2023-5353
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.
Suitecrm
7.14.1+
CRITICAL 9.1
CVE-2023-5350
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.
Suitecrm
7.14.1+
MEDIUM 5.4
CVE-2023-5351
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.
Suitecrm
7.14.1+
HIGH 8.8
CVE-2023-3627
Cross-Site Request Forgery (CSRF) in GitHub repository salesagility/suitecrm-core prior to 8.3.1.
Suitecrm
8.3.1+
HIGH 8.8
CVE-2023-1034EPSS 28%
Path Traversal: '\..\filename' in GitHub repository salesagility/suitecrm prior to 7.12.9.
Suitecrm
7.12.9+
HIGH 7.2
CVE-2022-27474EPSS 23%
SuiteCRM v7.11.23 was discovered to allow remote code execution via a crafted payload injected into the FirstName text field.
Suitecrm
No fix yet
HIGH 8.8
CVE-2022-23940EPSS 53%
SuiteCRM through 7.12.1 and 8.x through 8.0.1 allows Remote Code Execution. Authenticated users with access to the Scheduled Reports module can achie…
Suitecrm
7.12.5 / 8.0.4+
MEDIUM 6.5
CVE-2022-0756
Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.
Suitecrm
7.12.5+
MEDIUM 6.5
CVE-2022-0754
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.12.5.
Suitecrm
7.12.5+
CRITICAL 9.8
CVE-2021-45898
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows local file inclusion.
Suitecrm
7.12.3 / 8.0.2+
CRITICAL 9.8
CVE-2021-45899
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows PHAR deserialization that can lead to remote code execution.
Suitecrm
7.12.3 / 8.0.2+
HIGH 8.8
CVE-2021-45897
SuiteCRM before 7.12.3 and 8.x before 8.0.2 allows remote code execution.
Suitecrm
7.12.3 / 8.0.2+
HIGH 8.8
CVE-2021-41597
SuiteCRM through 7.11.21 is vulnerable to CSRF, with resultant remote code execution, via the UpgradeWizard functionality, if a PHP file is included …
Suitecrm
7.10.35 / 7.12.2+