Vulnerability index

Browse CVEs

65 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2019-17309 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the EmailMan module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17310 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Campaigns module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17293 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Project module by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17294 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the export function by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17295 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the history function by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17296 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Contacts module by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17292 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17318 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17319 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17317 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 8.8 CVE-2019-17316 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 HIGH 7.2 CVE-2019-17315 SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user. Sugarcrm 7.9.5.0 / 8.0.4+ Fix from $1,9502019-10-07 MEDIUM 6.1 CVE-2019-14974EPSS 28% SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS. Sugarcrm No fix yet Fix from $1,6002019-08-14 MEDIUM 6.1 CVE-2018-17784 Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to cond… Sugarcrm after 6.5.26 Fix from $1,6002018-10-10 CRITICAL 9.8 CVE-2014-3244EPSS 5% XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potent… Sugarcrm 6.5.16+ Fix from $2,3002018-02-01 CRITICAL 9.8 CVE-2018-6308 Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Cam… Sugarcrm No fix yet Fix from $2,3002018-01-25 MEDIUM 6.1 CVE-2018-5715EPSS 7% phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable). Sugarcrm No fix yet Fix from $1,6002018-01-16 HIGH 8.8 CVE-2017-14508 An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several area… Sugarcrm after 7.7.2.2 Fix from $1,9502017-09-17 HIGH 8.8 CVE-2017-14509EPSS 6% An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote fil… Sugarcrm after 7.7.2.2 Fix from $1,9502017-09-17 MEDIUM 6.1 CVE-2017-14510 An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLea… Sugarcrm after 7.7.2.2 Fix from $1,6002017-09-17 HIGH 7.8 CVE-2015-5946 Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executab… Sugarcrm No fix yet Fix from $1,9502017-08-07 HIGH 7.5 CVE-2011-4833 Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0b… Sugarcrm No fix yet Fix from $1,9502011-12-15 MEDIUM 5.0 CVE-2011-3803 SugarCRM 6.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an… Sugarcrm Mitigation only Fix from $1,6002011-09-24 HIGH 7.5 CVE-2009-2978 SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and earlier, and 5.2.0g and earlier, allows remote attackers to execute arbitrary … Sugarcrm after 5.2.0g Fix from $1,9502009-08-27 MEDIUM 6.0 CVE-2009-2146EPSS 21% Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows… Sugarcrm after 5.2e Fix from $1,6002009-06-22 MEDIUM 5.0 CVE-2008-2045EPSS 5% Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full … Sugarcrm Patch available Fix from $1,6002008-05-01 MEDIUM 6.8 CVE-2006-6712 Cross-site scripting (XSS) vulnerability in SugarCRM Open Source 4.5.0f and earlier allows remote attackers to inject arbitrary web script or HTML vi… Sugarcrm after 4.5.0f Fix from $1,6002006-12-23 HIGH 7.5 CVE-2006-5082 Unspecified vulnerability in Sugar Suite Open Source (SugarCRM) before 4.2.1 Patch C (20060917) has unspecified impact, related to code execution, an… Sugar Suite Patch available Fix from $1,9502006-09-29 MEDIUM 6.4 CVE-2006-2460EPSS 10% Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SES… Sugarcrm No fix yet Fix from $1,6002006-05-19 HIGH 7.5 CVE-2005-4087 PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlie… Sugar Suite No fix yet Fix from $1,9502005-12-08