Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.6
CVE-2025-67102
A SQL injection vulnerability in the alldayoffs feature in Jorani up to v1.0.4, allows an authenticated attacker to execute arbitrary SQL commands vi…
Jorani
after 1.0.4
MEDIUM 5.3
CVE-2023-48205
Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.
Leave Management System
No fix yet
MEDIUM 6.5
CVE-2023-45540
An issue in Jorani Leave Management System 1.0.3 allows a remote attacker to execute arbitrary HTML code via a crafted script to the comment field of…
Leave Management System
No fix yet
HIGH 8.8
CVE-2023-2681
An SQL Injection vulnerability has been found on Jorani version 1.0.0. This vulnerability allows an authenticated remote user, with low privileges, t…
Jorani
Mitigation only
CRITICAL 9.8
CVE-2023-26469EPSS 83%
In Jorani 1.0.0, an attacker could leverage path traversal to access files and execute code on the server.
Jorani
No fix yet
MEDIUM 6.1
CVE-2022-48118
Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Acronym parameter.
Jorani
No fix yet
CRITICAL 9.8
CVE-2022-34132
Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leaves.php.
Jorani
Patch available
HIGH 8.8
CVE-2022-34134
Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Users.php.
Jorani
Patch available
MEDIUM 6.1
CVE-2022-34133
Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at application/controllers/Leaves.php.
Jorani
Patch available