Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

a+HRD — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in a+HRD, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for the a+HRD human resource management system, focusing on common weakness types and associated security tags. It collects a comprehensive dataset of known vulnerabilities affecting this specific product, encompassing flaws reported over the past five years from initial disclosure to recent patch releases. The data includes issues ranging from cross-site scripting and SQL injection to authentication bypasses and improper access control mechanisms. Readers can use this centralized view to track vendor advisories and monitor the release timeline of security updates issued by the software provider. The page allows users to understand the prevalence and characteristics of a specific weakness class within the context of this application, providing context on how these flaws typically manifest. Additionally, one can look up the a+HRD product’s vulnerability history to analyze trends in code quality or security hygiene over time. This resource serves as a reference for security analysts, auditors, and IT administrators who need to assess the current risk posture of systems running this software. By aggregating information from various sources, it simplifies the process of identifying unpatched risks and understanding the attack surface. The content is curated to provide factual technical details without speculation, ensuring that users have access to verified data regarding known exploits and mitigation strategies. This structured approach helps stakeholders make informed decisions regarding upgrades, compensating controls, and risk acceptance.

Vendor: aEnrich

CVE IDTitleCVSSSeverityPublished
CVE-2026-6834 aEnrich|a+HRD - Missing Authorization CWE-862 6.5 Medium2026-04-22
CVE-2026-6833 aEnrich|a+HRD - SQL Injection CWE-89 6.5 Medium2026-04-22
CVE-2025-12872 aEnrich|eHRD - Stored Cross-Site Scripting CWE-79 5.4 Medium2025-11-12
CVE-2025-12871 aEnrich|a+HRD - Authentication Abuse CWE-1390 9.8 Critical2025-11-12
CVE-2025-12870 aEnrich|eHRD - Authentication Abuse CWE-1390 9.8 Critical2025-11-12
CVE-2025-12869 aEnrich|eHRD - Stored Cross-Site Scripting CWE-79 4.8 Medium2025-11-12
CVE-2025-0586 aEnrich Technology a+HRD - Insecure Deserialization CWE-502 7.2 High2025-01-20
CVE-2025-0585 aEnrich Technology a+HRD - SQL Injection CWE-89 9.8 Critical2025-01-20
CVE-2025-0584 aEnrich Technology a+HRD - Server-Side Request Forgery (SSRF) CWE-918 5.3 Medium2025-01-20
CVE-2025-0583 aEnrich Technology a+HRD - Reflected Cross-site Scripting(XSS) CWE-79 6.1 Medium2025-01-20
CVE-2024-3775 aEnrich Technology a+HRD - Argument Injection CWE-88 5.3 Medium2024-04-15
CVE-2024-3774 aEnrich Technology a+HRD - Exposure of Sensitive Data CWE-306 5.3 Medium2024-04-15
CVE-2023-20853 aEnrich a+HRD - Deserialization of Untrusted Data CWE-502 9.8 Critical2023-04-27
CVE-2023-20852 aEnrich a+HRD - Deserialization of Untrusted Data CWE-502 9.8 Critical2023-04-27
CVE-2022-39042 aEnrich a+HRD - Improper Authentication CWE-287 9.8 Critical2023-01-03
CVE-2022-39041 aEnrich a+HRD - SQL Injection CWE-89 9.8 Critical2023-01-03
CVE-2022-39040 aEnrich a+HRD - Path Traversal CWE-22 7.5 High2023-01-03
CVE-2022-39039 aEnrich a+HRD - Server-Side Request Forgery (SSRF) CWE-918 9.8 Critical2023-01-03
CVE-2022-26676 aEnrich a+HRD - Broken Access Control CWE-269 9.8 Critical2022-04-07
CVE-2022-26675 aEnrich a+HRD - Path Traversal CWE-22 7.5 High2022-04-07

All 20 known CVE vulnerabilities affecting a+HRD with full Chinese analysis, references, and POCs where available.