浏览 27+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2019-25710 | Dolibarr ERP-CRM 8.0.4 SQL Injection via rowid Parameter | Dolibarr | Dolibarr ERP-CRM | High | 8.2 | 2026-04-12 12:28:55 | Deep Dive |
| CVE-2026-22666 | Dolibarr ERP/CRM < 23.0.2 Authenticated RCE via dol_eval_standard() | Dolibarr | Dolibarr ERP/CRM | High | 7.2 | 2026-04-07 12:41:31 | Deep Dive |
| CVE-2019-25452 | Dolibarr ERP/CRM 10.0.1 SQL Injection via elemid | Dolibarr | Dolibarr ERP/CRM | High | 7.5 | 2026-02-22 13:18:26 | Deep Dive |
| CVE-2019-25450 | Dolibarr ERP/CRM 10.0.1 SQL Injection via card.php | Dolibarr | Dolibarr ERP/CRM | High | 7.5 | 2026-02-22 13:18:25 | Deep Dive |
| CVE-2012-10059 | Dolibarr ERP/CRM Post-Auth OS Command Injection | Dolibarr Project | ERP/CRM | - | - | 2025-08-13 20:33:51 | Deep Dive |
| CVE-2025-49987 | WordPress CRM ERP Business Solution plugin <= 1.13 - Broken Access Control Vulnerability | WPFactory | CRM ERP Business Solution | Medium | 5.3 | 2025-06-20 15:04:10 | Deep Dive |
| CVE-2024-12812 | WP ERP < 1.13.4 - Custom+ Unauthorized Access to Terminated Employee Information | Unknown | WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting | - | - | 2025-05-15 20:06:58 | Deep Dive |
| CVE-2024-12808 | WP ERP | Complete HR solution with recruitment < 1.13.4 - Admin+ Stored XSS | Unknown | WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting | - | - | 2025-05-15 20:06:57 | Deep Dive |
| CVE-2025-30582 | WordPress DyaPress ERP/CRM plugin <= 18.0.2.0 - Local File Inclusion Vulnerability | aytechnet | DyaPress ERP/CRM | High | 8.1 | 2025-04-10 08:09:41 | Deep Dive |
| CVE-2024-12146 | SQLi in Finder Fire Safety's Finder ERP/CRM (New System) | Finder Fire Safety | Finder ERP/CRM (New System) | High | 7.5 | 2025-03-06 14:08:34 | Deep Dive |
| CVE-2024-12144 | SQLi in Finder Fire Safety's Finder ERP/CRM (Old System) | Finder Fire Safety | Finder ERP/CRM (Old System) | Critical | 9.8 | 2025-03-06 14:05:09 | Deep Dive |
| CVE-2024-47769 | IDURAR has a Path Traversal (unauthenticated user can read sensitive data) | idurar | idurar-erp-crm | High | 7.5 | 2024-10-04 14:45:41 | Deep Dive |
| CVE-2024-6666 | WP ERP <= 1.13.0 - Authenticated (Accounting Manager+) SQL Injection via vendor_id | wedevs | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | High | 8.8 | 2024-07-11 06:43:14 | Deep Dive |
| CVE-2024-1173 | WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated (AccountingManager+) SQL Injection | wedevs | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | High | 7.2 | 2024-05-02 16:52:26 | Deep Dive |
| CVE-2024-0952 | WP ERP <= 1.12.9 - Authenticated (Accounting Manager+) SQL Injection via id | wedevs | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | High | 7.2 | 2024-04-09 18:59:33 | Deep Dive |
| CVE-2024-0956 | WP ERP <= 1.13.0 - Authenticated (AccountingManager+) SQL Injection | wedevs | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | Medium | 4.9 | 2024-03-29 06:44:03 | Deep Dive |
| CVE-2024-0609 | WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Unauthenticated Stored Cross-Site Scripting | wedevs | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | High | 7.2 | 2024-03-29 06:44:02 | Deep Dive |
| CVE-2024-0608 | WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting <= 1.13.1 - Authenticated (Subscriber+) SQL Injection | wedevs | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | Medium | 6.5 | 2024-03-29 06:44:01 | Deep Dive |
| CVE-2024-0913 | WP ERP <= 1.13.0 - Authenticated (Accounting Manager+) SQL Injection | wedevs | ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support | High | 7.2 | 2024-03-29 06:44:00 | Deep Dive |
| CVE-2024-21747 | WordPress WP ERP Plugin <= 1.12.8 is vulnerable to SQL Injection | weDevs | WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting | High | 7.6 | 2024-01-08 16:48:10 | Deep Dive |