aenrich CVE Vulnerabilities & Metrics

Focus on aenrich vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About aenrich Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with aenrich. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total aenrich CVEs: 11
Earliest CVE date: 07 Apr 2022, 19:15 UTC
Latest CVE date: 27 Apr 2023, 02:15 UTC

Latest CVE reference: CVE-2023-20853

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical aenrich CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 1.14

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 9
4.0-6.9 1
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS aenrich CVEs

These are the five CVEs with the highest CVSS scores for aenrich, sorted by severity first and recency.

All CVEs for aenrich

CVE-2023-20853 aenrich vulnerability CVSS: 0 27 Apr 2023, 02:15 UTC

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.

CVE-2023-20852 aenrich vulnerability CVSS: 0 27 Apr 2023, 02:15 UTC

aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands to perform arbitrary system operation or disrupt service.

CVE-2022-39042 aenrich vulnerability CVSS: 0 03 Jan 2023, 03:15 UTC

aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perform arbitrary system command or disrupt service.

CVE-2022-39041 aenrich vulnerability CVSS: 0 03 Jan 2023, 03:15 UTC

aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands to access, modify and delete database.

CVE-2022-39040 aenrich vulnerability CVSS: 0 03 Jan 2023, 03:15 UTC

aEnrich a+HRD log read function has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.

CVE-2022-39039 aenrich vulnerability CVSS: 0 03 Jan 2023, 03:15 UTC

aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch Server-Side Request Forgery (SSRF) attack, to perform arbitrary system command or disrupt service.

CVE-2022-28742 aenrich vulnerability CVSS: 0 09 Sep 2022, 16:15 UTC

aEnrich eHRD Learning Management Key Performance Indicator System 5+ has Improper Access Control. The web application does not validate user session when accessing many application pages. This can allow an attacker to gain unauthenticated access to sensitive functionalities in the application

CVE-2022-28741 aenrich vulnerability CVSS: 0 09 Sep 2022, 16:15 UTC

aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x

CVE-2022-28740 aenrich vulnerability CVSS: 0 09 Sep 2022, 16:15 UTC

aEnrich eHRD Learning Management Key Performance Indicator System 5+ exposes Sensitive Information to an Unauthorized Actor.

CVE-2022-26676 aenrich vulnerability CVSS: 7.5 07 Apr 2022, 19:15 UTC

aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or disrupt service.

CVE-2022-26675 aenrich vulnerability CVSS: 5.0 07 Apr 2022, 19:15 UTC

aEnrich a+HRD has inadequate filtering for special characters in URLs. An unauthenticated remote attacker can bypass authentication and perform path traversal attacks to access arbitrary files under website root directory.