Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-7489 CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify,… Ehrd Ctms Mitigation only Fix from $1,9502026-05-02 HIGH 7.2 CVE-2026-7490 CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell ba… Ehrd Cpas Mitigation only Fix from $1,9502026-05-02 CRITICAL 9.8 CVE-2025-15226 WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdo… Wmpro after 5.2 Fix from $2,3002025-12-29 HIGH 7.5 CVE-2025-15225 WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to r… Wmpro after 5.2 Fix from $1,9502025-12-29 MEDIUM 6.1 CVE-2025-9567 The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaS… Ehrd Ctms Mitigation only Fix from $1,6002025-09-01 MEDIUM 6.1 CVE-2025-9568 The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaS… Ehrd Ctms Mitigation only Fix from $1,6002025-09-01 MEDIUM 6.1 CVE-2025-9569 The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaS… Ehrd Ctms Mitigation only Fix from $1,6002025-09-01 CRITICAL 9.8 CVE-2025-54945 An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute… Ehrd Ctms 10.11+ Fix from $2,3002025-08-30 CRITICAL 9.8 CVE-2025-54946 A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands. Ehrd Ctms 10.11+ Fix from $2,3002025-08-30 CRITICAL 9.8 CVE-2025-54944 An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers … Ehrd Ctms 10.11+ Fix from $2,3002025-08-30 CRITICAL 9.8 CVE-2025-54943 A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized app… Ehrd Ctms 10.11+ Fix from $2,3002025-08-30 CRITICAL 9.8 CVE-2025-54942 A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to a… Ehrd Ctms 10.11+ Fix from $2,3002025-08-30 MEDIUM 6.5 CVE-2025-3707 The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to rea… Ehrd Ctms after 10.13 Fix from $1,6002025-05-02 CRITICAL 9.8 CVE-2024-10440 The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modif… Ehrd Ctms 10.0+ Fix from $2,3002024-10-28 HIGH 7.5 CVE-2024-10438 The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfyin… Ehrd Ctms 10.14+ Fix from $1,9502024-10-28 HIGH 7.5 CVE-2024-10439 The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specifi… Ehrd Ctms 10.8+ Fix from $1,9502024-10-28 HIGH 7.5 CVE-2023-35851 SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands t… Wmpro Mitigation only Fix from $1,9502023-09-18 HIGH 7.2 CVE-2023-35850 SUNNET WMPro portal's file management function has a vulnerability of insufficient filtering for user input. A remote attacker with administrator pri… Wmpro Mitigation only Fix from $1,9502023-09-18 HIGH 8.8 CVE-2023-24836 SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can … Ehrd Ctms Mitigation only Fix from $1,9502023-04-27 CRITICAL 9.8 CVE-2019-11062EPSS 6% The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be explo… Wmpro No fix yet Fix from $2,3002019-07-11