Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2019-17309
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the EmailMan module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17310
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Campaigns module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17293
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Project module by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17294
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the export function by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17295
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the history function by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17296
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Contacts module by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17292
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17318
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the pmse_Inbox module by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17319
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows SQL injection in the Emails module by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17317
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the UpgradeWizard module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 8.8
CVE-2019-17316
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Import module by a Regular user.
Sugarcrm
7.9.5.0 / 8.0.4+
HIGH 7.2
CVE-2019-17315
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP object injection in the Administration module by an Admin user.
Sugarcrm
7.9.5.0 / 8.0.4+
MEDIUM 6.1
CVE-2019-14974EPSS 28%
SugarCRM Enterprise 9.0.0 allows mobile/error-not-supported-platform.html?desktop_url= XSS.
Sugarcrm
No fix yet
MEDIUM 6.1
CVE-2018-17784
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to cond…
Sugarcrm
after 6.5.26
CRITICAL 9.8
CVE-2014-3244EPSS 5%
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potent…
Sugarcrm
6.5.16+
CRITICAL 9.8
CVE-2018-6308
Multiple SQL injections exist in SugarCRM Community Edition 6.5.26 and below via the track parameter to modules\Campaigns\Tracker.php and modules\Cam…
Sugarcrm
No fix yet
MEDIUM 6.1
CVE-2018-5715EPSS 7%
phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
Sugarcrm
No fix yet
HIGH 8.8
CVE-2017-14508
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). Several area…
Sugarcrm
after 7.7.2.2
HIGH 8.8
CVE-2017-14509EPSS 6%
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). A remote fil…
Sugarcrm
after 7.7.2.2
MEDIUM 6.1
CVE-2017-14510
An issue was discovered in SugarCRM before 7.7.2.3, 7.8.x before 7.8.2.2, and 7.9.x before 7.9.2.0 (and Sugar Community Edition 6.5.26). The WebToLea…
Sugarcrm
after 7.7.2.2
HIGH 7.8
CVE-2015-5946
Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executab…
Sugarcrm
No fix yet
HIGH 7.5
CVE-2011-4833
Multiple SQL injection vulnerabilities in the Leads module in SugarCRM 6.1 before 6.1.7, 6.2 before 6.2.4, 6.3 before 6.3.0RC3, and 6.4 before 6.4.0b…
Sugarcrm
No fix yet
MEDIUM 5.0
CVE-2011-3803
SugarCRM 6.1.0 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an…
Sugarcrm
Mitigation only
HIGH 7.5
CVE-2009-2978
SQL injection vulnerability in SugarCRM 4.5.1o and earlier, 5.0.0k and earlier, and 5.2.0g and earlier, allows remote attackers to execute arbitrary …
Sugarcrm
after 5.2.0g
MEDIUM 6.0
CVE-2009-2146EPSS 21%
Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows…
Sugarcrm
after 5.2e
MEDIUM 5.0
CVE-2008-2045EPSS 5%
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full …
Sugarcrm
Patch available
MEDIUM 6.8
CVE-2006-6712
Cross-site scripting (XSS) vulnerability in SugarCRM Open Source 4.5.0f and earlier allows remote attackers to inject arbitrary web script or HTML vi…
Sugarcrm
after 4.5.0f
HIGH 7.5
CVE-2006-5082
Unspecified vulnerability in Sugar Suite Open Source (SugarCRM) before 4.2.1 Patch C (20060917) has unspecified impact, related to code execution, an…
Sugar Suite
Patch available
MEDIUM 6.4
CVE-2006-2460EPSS 10%
Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SES…
Sugarcrm
No fix yet
HIGH 7.5
CVE-2005-4087
PHP remote file include vulnerability in acceptDecline.php in Sugar Suite Open Source Customer Relationship Management (SugarCRM) 4.0 beta and earlie…
Sugar Suite
No fix yet