Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Rockoa CRITICAL 9.8
CVE-2025-63742

SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers gain…

Mitigation only
Fix from $2,300 2025-12-09
Rockoa MEDIUM 6.1
CVE-2025-63737

Cross-site scripting (XSS) vulnerability in function urltestAction in file cliAction.php in Xinhu Rainrock RockOA 2.7.0 allows remote attackers to in…

No fix yet
Fix from $1,600 2025-12-09
Xinhu HIGH 8.8
CVE-2024-7327

A vulnerability classified as critical was found in Xinhu RockOA 2.6.2. This vulnerability affects the function dataAction of the file /webmain/task/…

No fix yet
Fix from $1,950 2024-07-31
Xinhu MEDIUM 6.1
CVE-2024-37622

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the num parameter at /flow/flow.php.

No fix yet
Fix from $1,600 2024-06-17
Xinhu MEDIUM 6.1
CVE-2024-37623

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /kaoqin/tpl_kaoqin_locationchange.html com…

No fix yet
Fix from $1,600 2024-06-17
Xinhu MEDIUM 6.1
CVE-2024-37624

Xinhu RockOA v2.6.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the /chajian/inputChajian.php. component.

No fix yet
Fix from $1,600 2024-06-17
Xinhu CRITICAL 9.8
CVE-2023-48930

xinhu xinhuoa 2.2.1 contains a File upload vulnerability.

No fix yet
Fix from $2,300 2023-12-06
Rockoa HIGH 7.5
CVE-2023-5296

A vulnerability was found in Xinhu RockOA 1.1/2.3.2/15.X3amdi and classified as problematic. Affected by this issue is some unknown functionality of …

No fix yet
Fix from $1,950 2023-09-29
Rockoa HIGH 7.5
CVE-2023-5297

A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of the file task.php?m=sys|ru…

No fix yet
Fix from $1,950 2023-09-29
Rockoa CRITICAL 9.8
CVE-2023-1773

A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the file webmainConfig.php of…

Mitigation only
Fix from $2,300 2023-03-31
Rockoa HIGH 8.8
CVE-2023-1501

A vulnerability, which was classified as critical, was found in RockOA 2.3.2. This affects the function runAction of the file acloudCosAction.php.SQL…

No fix yet
Fix from $1,950 2023-03-19
Rockoa HIGH 8.0
CVE-2020-20593

A cross-site request forgery (CSRF) in Rockoa v1.9.8 allows an authenticated attacker to arbitrarily add an administrator account.

No fix yet
Fix from $1,950 2021-12-22
Rockoa CRITICAL 9.8
CVE-2020-18713

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in customerAction.php

No fix yet
Fix from $2,300 2021-02-05
Rockoa CRITICAL 9.8
CVE-2020-18714

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordModel.php's getdata function.

No fix yet
Fix from $2,300 2021-02-05
Rockoa CRITICAL 9.8
CVE-2020-18716

SQL Injection in Rockoa v1.8.7 allows remote attackers to gain privileges due to loose filtering of parameters in wordAction.php.

No fix yet
Fix from $2,300 2021-02-05
Xinhu HIGH 7.5
CVE-2020-35388

rainrocka xinhu 2.1.9 allows remote attackers to obtain sensitive information via an index.php?a=gettotal request in which the ajaxbool value is mani…

No fix yet
Fix from $1,950 2020-12-26