Total CVEs

137,228

Critical Severity

3,305

High Severity

12,247

Last 7 Days

1,458
Quick preset (or use dates below)
Clear Filters
Showing 21 - 40 of 659 CVEs
CVE-2026-10154 MEDIUM - 4.3

A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. Upgrading to version 23.0.3 is sufficie...

Vendor: Dolibarr
Product: ERP CRM
Published: May 31, 2026
Source: NVD
CVE-2026-41160 MEDIUM - 4.3

EspoCRM is an open source customer relationship management application. Prior to 9.3.5, a business logic flaw (Broken Access Control) in EspoCRM 9.3.3 allows low-privileged users to pin arbitrary notes without having the required edit permissions for the parent object. Due to a "write first, au...

Vendor: espocrm
Product: espocrm
Published: May 28, 2026
Source: NVD
CVE-2026-41141 MEDIUM - 6.5

EspoCRM is an open source customer relationship management application. Prior to 9.3.5, the POST /api/v1/EmailTemplate/:id/prepare endpoint accepts an emailAddress parameter and resolves the owning entity (Contact, Lead, Account, or User) without performing an ACL check. An authenticated user with E...

Vendor: espocrm
Product: espocrm
Published: May 28, 2026
Source: NVD

In the Linux kernel, the following vulnerability has been resolved: LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang() The switch case in loongson_gpu_fixup_dma_hang() may not DC2 or DC3, and readl(crtc_reg) will access with random address, because the "device" is from "b...

Vendor: Linux
Product: Linux
Published: May 28, 2026
Source: NVD
CVE-2026-37713 HIGH - 7.3

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/class/commonobject.class.php.

Published: May 27, 2026
Source: NVD
CVE-2026-37712 HIGH - 7.3

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, call_user_func_array() in function job type

Published: May 27, 2026
Source: NVD
CVE-2026-37711 HIGH - 7.3

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/actions_addupdatedelete.inc.php

Published: May 27, 2026
Source: NVD
CVE-2026-46624 CRITICAL - 9.9

Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. If Postgres user is a super user then any authenticated user can execute arbitrary OS commands on the ...

Vendor: twentyhq
Product: twenty
Published: May 26, 2026
Source: NVD
CVE-2026-44729 HIGH - 8.7

Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fileFolder/:id serve uploaded files using fileStream.pipe(res) without setting any Content-Type, Content-Disposition, or X-Content-Type-Options response headers. This allows an authen...

Vendor: twentyhq
Product: twenty
Published: May 26, 2026
Source: NVD
CVE-2018-25357 CRITICAL - 9.8

Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then exe...

Vendor: dolibarr
Product: dolibarr_erp\/crm
Published: May 23, 2026
Source: NVD
CVE-2026-7798 MEDIUM - 5.4

The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.9.87 via the 'SubscribeURL' parameter. This makes it possible for ...

Published: May 22, 2026
Source: NVD
CVE-2026-33741 MEDIUM - 6.8

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later serve those SVG files as top-level inline documents through both the attachment and image entry poin...

Vendor: espocrm
Product: espocrm
Published: May 19, 2026
Source: NVD
CVE-2026-8758 HIGH - 7.3

A vulnerability was determined in Metasoft ηΎŽη‰Ήθ½―δ»Ά MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp. Executing a manipulation of the argument File can lead to unrestricted upload. The attack may be launched remotely. The exploit has been publicly disclose...

Published: May 17, 2026
Source: NVD

EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in EcclesiaCRM's query view passes user-supplied POST parameters directly into SQL queries via str_replace without any sanitization, enabling SQL injection through query par...

Vendor: phili67
Product: ecclesiacrm
Published: May 13, 2026
Source: NVD
CVE-2026-44548 HIGH - 8.1

ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php, or NoteDelete.php causes a logged-in ChurchCRM user with the relevant role to silently delete records, including...

Vendor: ChurchCRM
Product: CRM
Published: May 12, 2026
Source: NVD
CVE-2026-44547 CRITICAL - 9.6

ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from src/api/routes/public/public-user.php by an unrelated PR before any 7.2.x tag was cut. Every shipped 7.2.x release there...

Vendor: ChurchCRM
Product: CRM
Published: May 12, 2026
Source: NVD
CVE-2026-42289 HIGH - 8.8

ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and permission updates entirely through $_POST parameters with no CSRF token validation. An unauthenticated attacker can craft a malicious HTML page that, when visited by an authentic...

Vendor: ChurchCRM
Product: CRM
Published: May 12, 2026
Source: NVD
CVE-2026-42288 CRITICAL - 10.0

ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard via unsanitized DB_PASSWORD remains fully exploitable This vulnerability is fixed in 7.3.2.

Vendor: ChurchCRM
Product: CRM
Published: May 12, 2026
Source: NVD

Horilla is an HR and CRM software. In 1.5.0, the notification endpoints trust the unvalidated next parameter and redirect users to arbitrary external URLs. This allows an attacker to turn trusted application links into phishing or social-engineering redirects.

Vendor: horilla
Product: horilla-hr
Published: May 12, 2026
Source: NVD
CVE-2025-67486 HIGH - 7.2

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerability in the user extrafields functionality. User-controlled input from the "computed value" fi...

Vendor: Dolibarr
Product: dolibarr
Published: May 08, 2026
Source: NVD