Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2023-46815
An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. An Unrestricted File Upload vulnerability has been identified in the Notes…
Sugarcrm
12.0.4+
HIGH 8.8
CVE-2023-46816
An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified …
Sugarcrm
12.0.4+
HIGH 8.8
CVE-2023-35808
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. An Unrestricted File Upload vulnerability has been identified in…
Sugarcrm
11.0.6 / 12.0.3+
HIGH 8.8
CVE-2023-35809
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Bean Manipulation vulnerability has been identified in the RES…
Sugarcrm
11.0.6 / 12.0.3+
HIGH 8.8
CVE-2023-35811
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. Two SQL Injection vectors have been identified in the REST API. …
Sugarcrm
11.0.6 / 12.0.3+
HIGH 7.2
CVE-2023-35810
An issue was discovered in SugarCRM Enterprise before 11.0.6 and 12.x before 12.0.3. A Second-Order PHP Object Injection vulnerability has been ident…
Sugarcrm
11.0.6 / 12.0.3+
HIGH 8.8
CVE-2023-22952 KEVEPSS 80%
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
Sugarcrm
11.0.5 / 12.0.2+
MEDIUM 5.4
CVE-2020-36501
Multiple cross-site scripting (XSS) vulnerabilities in the Support module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HT…
Sugarcrm
No fix yet
MEDIUM 5.4
CVE-2020-28955
SugarCRM v6.5.18 was discovered to contain a cross-site scripting (XSS) vulnerability in the Create Employee module. This vulnerability allows attack…
Sugarcrm
No fix yet
MEDIUM 5.4
CVE-2020-28956
Multiple cross-site scripting (XSS) vulnerabilities in the Sales module of SugarCRM v6.5.18 allows attackers to execute arbitrary web scripts or HTML…
Sugarcrm
No fix yet
CRITICAL 9.8
CVE-2020-7472
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9…
Sugarcrm
8.0.7 / 9.0.4+
MEDIUM 5.4
CVE-2020-17372
SugarCRM before 10.1.0 (Q3 2020) allows XSS.
Sugarcrm
10.1.0+
MEDIUM 5.3
CVE-2020-17373
SugarCRM before 10.1.0 (Q3 2020) allows SQL Injection.
Sugarcrm
10.1.0+
CRITICAL 9.8
CVE-2012-0694EPSS 67%
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
Sugarcrm
after 6.3.1
HIGH 8.8
CVE-2019-17311
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the attachment function by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17312
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the file function by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17313
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Studio module by a Developer user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17314
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows directory traversal in the Configurator module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17297
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Quotes module by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17298
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Administration module by a Developer user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17300
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17302
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17303
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17305
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17308
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17299
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17301
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17304
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17306
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17307
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Tracker module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+