Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ehrd Ctms HIGH 8.8
CVE-2026-7489

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify,…

Mitigation only
Fix from $1,950 2026-05-02
Ehrd Cpas HIGH 7.2
CVE-2026-7490

CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell ba…

Mitigation only
Fix from $1,950 2026-05-02
Ehrd Ctms MEDIUM 6.1
CVE-2025-9567

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaS…

Mitigation only
Fix from $1,600 2025-09-01
Ehrd Ctms MEDIUM 6.1
CVE-2025-9568

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaS…

Mitigation only
Fix from $1,600 2025-09-01
Ehrd Ctms MEDIUM 6.1
CVE-2025-9569

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaS…

Mitigation only
Fix from $1,600 2025-09-01
Wmpro HIGH 7.5
CVE-2023-35851

SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands t…

Mitigation only
Fix from $1,950 2023-09-18
Wmpro HIGH 7.2
CVE-2023-35850

SUNNET WMPro portal's file management function has a vulnerability of insufficient filtering for user input. A remote attacker with administrator pri…

Mitigation only
Fix from $1,950 2023-09-18
Ehrd Ctms HIGH 8.8
CVE-2023-24836

SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can …

Mitigation only
Fix from $1,950 2023-04-27
Wmpro CRITICAL 9.8
CVE-2019-11062EPSS 6%

The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be explo…

No fix yet
Fix from $2,300 2019-07-11