VYPR

a+HRD

by AEnrich Technology

CVEs (8)

  • CVE-2025-0585CriJan 20, 2025
    risk 0.64cvss 9.8epss 0.01

    The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.

  • CVE-2023-20853CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or…

  • CVE-2023-20852CriApr 27, 2023
    risk 0.64cvss 9.8epss 0.01

    aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.

  • CVE-2025-0586HigJan 20, 2025
    risk 0.47cvss 7.2epss 0.01

    The a+HRD from aEnrich Technology has an Insecure Deserialization vulnerability, allowing remote attackers with database modification privileges and regular system privileges to perform arbitrary code execution.

  • CVE-2025-0583MedJan 20, 2025
    risk 0.40cvss 6.1epss 0.00

    The a+HRD from aEnrich Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks.

  • CVE-2025-0584MedJan 20, 2025
    risk 0.34cvss 5.3epss 0.01

    The a+HRD from aEnrich Technology has a Server-side Request Forgery, allowing unauthenticated remote attackers to exploit this vulnerability to probe internal network.

  • CVE-2024-3775MedApr 15, 2024
    risk 0.34cvss 5.3epss 0.00

    aEnrich Technology a+HRD's functionality for downloading files using youtube-dl.exe does not properly restrict user input. This allows attackers to pass arbitrary arguments to youtube-dl.exe, leading to the download of partial unauthorized files.

  • CVE-2024-3774MedApr 15, 2024
    risk 0.34cvss 5.3epss 0.00

    aEnrich Technology a+HRD's functionality for front-end retrieval of system configuration values lacks proper restrictions on a specific parameter, allowing attackers to modify this parameter to access certain sensitive system configuration values.