Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ehrd Ctms HIGH 8.8
CVE-2026-7489

CTMS developed by Sunnet has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read, modify,…

Mitigation only
Fix from $1,950 2026-05-02
Ehrd Cpas HIGH 7.2
CVE-2026-7490

CTMS and CPAS developed by Sunnet has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell ba…

Mitigation only
Fix from $1,950 2026-05-02
Wmpro CRITICAL 9.8
CVE-2025-15226

WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdo…

Fix: after 5.2
Fix from $2,300 2025-12-29
Wmpro HIGH 7.5
CVE-2025-15225

WMPro developed by Sunnet has an Arbitrary File Read vulnerability, allowing unauthenticated remote attackers to exploit Relative Path Traversal to r…

Fix: after 5.2
Fix from $1,950 2025-12-29
Ehrd Ctms MEDIUM 6.1
CVE-2025-9567

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaS…

Mitigation only
Fix from $1,600 2025-09-01
Ehrd Ctms MEDIUM 6.1
CVE-2025-9568

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaS…

Mitigation only
Fix from $1,600 2025-09-01
Ehrd Ctms MEDIUM 6.1
CVE-2025-9569

The eHRD developed by Sunnet has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaS…

Mitigation only
Fix from $1,600 2025-09-01
Ehrd Ctms CRITICAL 9.8
CVE-2025-54945

An external control of file name or path vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute…

Fix: 10.11+
Fix from $2,300 2025-08-30
Ehrd Ctms CRITICAL 9.8
CVE-2025-54946

A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.

Fix: 10.11+
Fix from $2,300 2025-08-30
Ehrd Ctms CRITICAL 9.8
CVE-2025-54944

An unrestricted upload of file with dangerous type vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers …

Fix: 10.11+
Fix from $2,300 2025-08-30
Ehrd Ctms CRITICAL 9.8
CVE-2025-54943

A missing authorization vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to perform unauthorized app…

Fix: 10.11+
Fix from $2,300 2025-08-30
Ehrd Ctms CRITICAL 9.8
CVE-2025-54942

A missing authentication for critical function vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to a…

Fix: 10.11+
Fix from $2,300 2025-08-30
Ehrd Ctms MEDIUM 6.5
CVE-2025-3707

The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to rea…

Fix: after 10.13
Fix from $1,600 2025-05-02
Ehrd Ctms CRITICAL 9.8
CVE-2024-10440

The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL command to read, modif…

Fix: 10.0+
Fix from $2,300 2024-10-28
Ehrd Ctms HIGH 7.5
CVE-2024-10438

The eHRD CTMS from Sunnet has an Authentication Bypass vulnerability, allowing unauthenticated remote attackers to bypass authentication by satisfyin…

Fix: 10.14+
Fix from $1,950 2024-10-28
Ehrd Ctms HIGH 7.5
CVE-2024-10439

The eHRD CTMS from Sunnet has an Insecure Direct Object Reference (IDOR) vulnerability, allowing unauthenticated remote attackers to modify a specifi…

Fix: 10.8+
Fix from $1,950 2024-10-28
Wmpro HIGH 7.5
CVE-2023-35851

SUNNET WMPro portal's FAQ function has insufficient validation for user input. An unauthenticated remote attacker can inject arbitrary SQL commands t…

Mitigation only
Fix from $1,950 2023-09-18
Wmpro HIGH 7.2
CVE-2023-35850

SUNNET WMPro portal's file management function has a vulnerability of insufficient filtering for user input. A remote attacker with administrator pri…

Mitigation only
Fix from $1,950 2023-09-18
Ehrd Ctms HIGH 8.8
CVE-2023-24836

SUNNET CTMS has vulnerability of path traversal within its file uploading function. An authenticated remote attacker with general user privilege can …

Mitigation only
Fix from $1,950 2023-04-27
Wmpro CRITICAL 9.8
CVE-2019-11062EPSS 6%

The SUNNET WMPro v5.0 and v5.1 for eLearning system has OS Command Injection via "/teach/course/doajaxfileupload.php". The target server can be explo…

No fix yet
Fix from $2,300 2019-07-11