Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 10 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-39349 OrangeHRM Uses AES-ECB for Sensitive Data Encryption Enables Pattern Disclosure orangehrmorangehrm--2026-04-07 18:22:38 Deep Dive
CVE-2026-39348 OrangeHRM is Missing Authorization Checks in AbstractFileController Subclasses Expose Job Specification and Vacancy Attachments orangehrmorangehrm 中危 -2026-04-07 18:21:30 Deep Dive
CVE-2026-39347 OrangeHRM's Self‑Appraisal Submission of Admin Users Can Be Modified After Completion orangehrmorangehrm--2026-04-07 18:20:36 Deep Dive
CVE-2026-39346 OrangeHRM has Improper Access Control Allowing Access to Disabled Modules via URL Encoding orangehrmorangehrm--2026-04-07 18:19:24 Deep Dive
CVE-2026-39345 OrangeHRM Affected by Arbitrary File Read via Path Traversal in Email Template Loader orangehrmorangehrm--2026-04-07 18:17:35 Deep Dive
CVE-2025-66291 OrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Interview Attachments orangehrmorangehrm 中危 -2025-11-29 03:08:01 Deep Dive
CVE-2025-66290 OrangeHRM is Vulnerable to Improper Authorization Allowing Unauthorized Access to Candidate Attachments orangehrmorangehrm 中危 -2025-11-29 03:06:56 Deep Dive
CVE-2025-66289 OrangeHRM is Vulnerable to Persistent Session Access Due to Missing Invalidation After User Disable and Password Change orangehrmorangehrm 中危 -2025-11-29 03:06:26 Deep Dive
CVE-2025-66225 OrangeHRM is Vulnerable to Account Takeover Through Unvalidated Username in Password Reset Workflow orangehrmorangehrm 中危 -2025-11-29 03:05:46 Deep Dive
CVE-2025-66224 OrangeHRM is Vulnerable to Code Execution Through Arbitrary File Write from Sendmail Parameter Injection orangehrmorangehrm 中危 -2025-11-29 03:04:42 Deep Dive