Vulnerability index

Browse CVEs

13 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2020-36501 Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HT… Sugarcrm No fix yet Fix from $1,6002021-10-22 MEDIUM 5.4 CVE-2020-28955 SugarCRM v6.5.18 was discovered to contain a cross-site scripting (XSS) vulnerability in the Create Employee module. This vulnerability allows attack… Sugarcrm No fix yet Fix from $1,6002021-10-22 MEDIUM 5.4 CVE-2020-28956 Multiple cross-site scripting (XSS) vulnerabilities in the Sales module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML… Sugarcrm No fix yet Fix from $1,6002021-10-22 MEDIUM 6.1 CVE-2019-14974EPSS 28% SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS. Sugarcrm No fix yet Fix from $1,6002019-08-14 CRITICAL 9.8 CVE-2018-6308 Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Cam… Sugarcrm No fix yet Fix from $2,3002018-01-25 MEDIUM 6.1 CVE-2018-5715EPSS 7% phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable). Sugarcrm No fix yet Fix from $1,6002018-01-16 HIGH 7.8 CVE-2015-5946 Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executab… Sugarcrm No fix yet Fix from $1,9502017-08-07 HIGH 7.5 CVE-2011-4833 Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0b… Sugarcrm No fix yet Fix from $1,9502011-12-15 MEDIUM 5.0 CVE-2011-3803 SugarCRM 6.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an… Sugarcrm Mitigation only Fix from $1,6002011-09-24 MEDIUM 6.4 CVE-2006-2460EPSS 10% Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SES… Sugarcrm No fix yet Fix from $1,6002006-05-19 HIGH 7.5 CVE-2005-4087 PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlie… Sugar Suite No fix yet Fix from $1,9502005-12-08 MEDIUM 5.0 CVE-2005-4086EPSS 7% Directory traversal vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlier al… Sugar Suite No fix yet Fix from $1,6002005-12-08 HIGH 10.0 CVE-2004-1225 SQL injection vulnerability in SugarCRM Sugar Sales before 2.0.1a allows remote attackers to execute arbitrary SQL commands and gain privileges via t… Sugarcrm No fix yet Fix from $1,9502005-01-10