Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2023-46815 An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. An Unrestricted File Upload vulnerability has been identified in the Notes… Sugarcrm 12.0.4+ Fix from $1,9502023-10-27 HIGH 8.8 CVE-2023-46816 An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified … Sugarcrm 12.0.4+ Fix from $1,9502023-10-27 HIGH 8.8 CVE-2023-35808 An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in… Sugarcrm 11.0.6 / 12.0.3+ Fix from $1,9502023-06-17 HIGH 8.8 CVE-2023-35809 An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability has been identified in the RES… Sugarcrm 11.0.6 / 12.0.3+ Fix from $1,9502023-06-17 HIGH 8.8 CVE-2023-35811 An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. Two SQL Injection vectors have been identified in the REST API. … Sugarcrm 11.0.6 / 12.0.3+ Fix from $1,9502023-06-17 HIGH 7.2 CVE-2023-35810 An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Second-Order PHP Object Injection vulnerability has been ident… Sugarcrm 11.0.6 / 12.0.3+ Fix from $1,9502023-06-17 HIGH 8.8 CVE-2023-22952 KEVEPSS 80% In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. Sugarcrm 11.0.5 / 12.0.2+ Fix from $1,9502023-01-11 MEDIUM 5.4 CVE-2020-36501 Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HT… Sugarcrm No fix yet Fix from $1,6002021-10-22 MEDIUM 5.4 CVE-2020-28955 SugarCRM v6.5.18 was discovered to contain a cross-site scripting (XSS) vulnerability in the Create Employee module. This vulnerability allows attack… Sugarcrm No fix yet Fix from $1,6002021-10-22 MEDIUM 5.4 CVE-2020-28956 Multiple cross-site scripting (XSS) vulnerabilities in the Sales module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML… Sugarcrm No fix yet Fix from $1,6002021-10-22 CRITICAL 9.8 CVE-2020-7472 An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9… Sugarcrm 8.0.7 / 9.0.4+ Fix from $2,3002020-11-12 MEDIUM 5.4 CVE-2020-17372 SugarCRM before 10.1.0 (Q3 2020) allows XSS. Sugarcrm 10.1.0+ Fix from $1,6002020-08-12 MEDIUM 5.3 CVE-2020-17373 SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection. Sugarcrm 10.1.0+ Fix from $1,6002020-08-12 CRITICAL 9.8 CVE-2012-0694EPSS 67% SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code. Sugarcrm after 6.3.1 Fix from $2,3002019-10-29 HIGH 8.8 CVE-2019-17311 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the attachment function by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17312 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17313 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17314 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17297 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Quotes module by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17298 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17300 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17302 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17303 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17305 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17308 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17299 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17301 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17304 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17306 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17307 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Tracker module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07