Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

A\+hrd CRITICAL 9.8
CVE-2025-12870

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain…

Fix: after 7.5
Fix from $2,300 2025-11-12
A\+hrd CRITICAL 9.8
CVE-2025-12871

The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tok…

Fix: after 7.5
Fix from $2,300 2025-11-12
A\+hrd CRITICAL 9.8
CVE-2025-0585

The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to re…

Fix: after 7.5
Fix from $2,300 2025-01-20
A\+hrd HIGH 7.2
CVE-2025-0586

The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and …

Fix: after 7.5
Fix from $1,950 2025-01-20
A\+hrd MEDIUM 5.3
CVE-2025-0584

The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe…

Fix: after 7.5
Fix from $1,600 2025-01-20
A\+hrd MEDIUM 6.1
CVE-2025-0583

The a+HRD from aEnrich Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary …

Fix: after 7.5
Fix from $1,600 2025-01-20
A\+hrd HIGH 7.5
CVE-2024-3775

aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to p…

Mitigation only
Fix from $1,950 2024-04-15
A\+hrd MEDIUM 5.3
CVE-2024-3774

aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, al…

Mitigation only
Fix from $1,600 2024-04-15
A\+hrd CRITICAL 9.8
CVE-2023-20852

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can…

Mitigation only
Fix from $2,300 2023-04-27
A\+hrd CRITICAL 9.8
CVE-2023-20853

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated r…

Mitigation only
Fix from $2,300 2023-04-27
A\+hrd CRITICAL 9.8
CVE-2022-39039

aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitr…

Mitigation only
Fix from $2,300 2023-01-03
A\+hrd CRITICAL 9.8
CVE-2022-39041

aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to…

Mitigation only
Fix from $2,300 2023-01-03
A\+hrd CRITICAL 9.8
CVE-2022-39042

aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication …

Mitigation only
Fix from $2,300 2023-01-03
A\+hrd HIGH 7.5
CVE-2022-39040

aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authe…

Mitigation only
Fix from $1,950 2023-01-03
A\+hrd HIGH 8.1
CVE-2022-28741

aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing inpu…

Fix: 5.4.1125v112 / 5.5.1098v156+
Fix from $1,950 2022-09-09
A\+hrd HIGH 7.5
CVE-2022-28740

aEnrich eHRD Learning Management Key Performance Indicator System 5+ exposes Sensitive Information to an Unauthorized Actor.

Fix: 5.4.1125v112 / 5.5.1098v156+
Fix from $1,950 2022-09-09
A\+hrd HIGH 7.5
CVE-2022-28742

aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session …

Fix: 5.4.1125v112 / 5.5.1098v156+
Fix from $1,950 2022-09-09
A\+hrd CRITICAL 9.8
CVE-2022-26676

aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scri…

Mitigation only
Fix from $2,300 2022-04-07
A\+hrd HIGH 7.5
CVE-2022-26675

aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path …

Mitigation only
Fix from $1,950 2022-04-07