Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Rockoa MEDIUM 6.1
CVE-2026-0588

A weakness has been identified in Xinhu Rainrock RockOA up to 2.7.1. Affected by this vulnerability is an unknown functionality of the file rockfun.p…

Fix: after 2.7.1
Fix from $1,600 2026-01-05
Rockoa MEDIUM 5.4
CVE-2026-0587

A security flaw has been discovered in Xinhu Rainrock RockOA up to 2.7.1. Affected is an unknown function of the file rock_page_gong.php of the compo…

Fix: after 2.7.1
Fix from $1,600 2026-01-05
Rockoa CRITICAL 9.8
CVE-2025-63742

SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain…

Mitigation only
Fix from $2,300 2025-12-09
Rockoa MEDIUM 6.1
CVE-2025-63737

Cross-site scripting (XSS) vulnerability in function urltestAction in file cliAction.php in Xinhu Rainrock RockOA 2.7.0 allows remote attackers to in…

No fix yet
Fix from $1,600 2025-12-09
Rockoa MEDIUM 6.5
CVE-2025-9602

A vulnerability was found in Xinhu RockOA up to 2.6.9. Impacted is the function publicsaveAjax of the file /index.php. Performing manipulation result…

Fix: after 2.6.9
Fix from $1,600 2025-08-29
Xinhu MEDIUM 6.8
CVE-2024-57151

SQL Injection vulnerability in rainrocka xinhu v.2.6.5 and before allows a remote attacker to execute arbitrary code via the inputAction.php file and…

Fix: after 2.6.5
Fix from $1,600 2025-03-18
Xinhu HIGH 8.8
CVE-2024-7327

A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataAction of the file /webmain/task/…

No fix yet
Fix from $1,950 2024-07-31
Xinhu MEDIUM 6.1
CVE-2024-37622

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.

No fix yet
Fix from $1,600 2024-06-17
Xinhu MEDIUM 6.1
CVE-2024-37623

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_kaoqin_locationchange.html com…

No fix yet
Fix from $1,600 2024-06-17
Xinhu MEDIUM 6.1
CVE-2024-37624

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inputChajian.php. component.

No fix yet
Fix from $1,600 2024-06-17
Rockoa CRITICAL 9.8
CVE-2023-49363

Rockoa <2.3.3 is vulnerable to SQL Injection. The problem exists in the indexAction method in reimpAction.php.

Fix: 2.3.3+
Fix from $2,300 2023-12-13
Xinhu CRITICAL 9.8
CVE-2023-48930

xinhu xinhuoa 2.2.1 contains a File upload vulnerability.

No fix yet
Fix from $2,300 2023-12-06
Rockoa HIGH 7.5
CVE-2023-5296

A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some unknown functionality of …

No fix yet
Fix from $1,950 2023-09-29
Rockoa HIGH 7.5
CVE-2023-5297

A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of the file task.php?m=sys|ru…

No fix yet
Fix from $1,950 2023-09-29
Rockoa CRITICAL 9.8
CVE-2023-1773

A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the file webmainConfig.php of…

Mitigation only
Fix from $2,300 2023-03-31
Rockoa HIGH 8.8
CVE-2023-1501

A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the file acloudCosAction.php.SQL…

No fix yet
Fix from $1,950 2023-03-19
Xinhu HIGH 7.5
CVE-2022-45041

SQL Injection exits in xinhu < 2.5.0

Fix: 2.5.0+
Fix from $1,950 2022-12-19
Rockoa HIGH 8.0
CVE-2020-20593

A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.

No fix yet
Fix from $1,950 2021-12-22
Rockoa CRITICAL 9.8
CVE-2020-18713

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php

No fix yet
Fix from $2,300 2021-02-05
Rockoa CRITICAL 9.8
CVE-2020-18714

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.

No fix yet
Fix from $2,300 2021-02-05
Rockoa CRITICAL 9.8
CVE-2020-18716

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.

No fix yet
Fix from $2,300 2021-02-05
Xinhu HIGH 7.5
CVE-2020-35388

rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is mani…

No fix yet
Fix from $1,950 2020-12-26
Rockoa HIGH 8.8
CVE-2019-9846

RockOA 1.8.7 allows remote attackers to obtain sensitive information because the webmain/webmainAction.php publictreestore method constructs a SQL WH…

Fix: 1.8.7+
Fix from $1,950 2019-06-28