Export CSV

Products

1 vendor
VendorProductsCVEsKEVAvg EPSSWorst Severity
111033.3%CRITICAL

Related CVEs

11
CVE IDDescriptionSeverityCVSSKEVEPSSPublished
CVE-2025-13771WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit Relative Path Traversal to download arbitrary system files.HIGH7.131.4%Nov 28, 2025
CVE-2025-13770WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.HIGH7.120.0%Nov 28, 2025
CVE-2025-13769WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrary SQL commands to read database contents.HIGH7.120.0%Nov 28, 2025
CVE-2025-13768WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log into the system as any user by modifying a specific parameter. Attackers must first obtain a user ID to exploit this vulnerability.HIGH7.727.7%Nov 28, 2025
CVE-2025-9259WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.HIGH7.139.1%Aug 22, 2025
CVE-2025-9258WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.HIGH7.139.1%Aug 22, 2025
CVE-2025-9257WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.HIGH7.139.1%Aug 22, 2025
CVE-2025-9256WebITR developed by Uniong has an Arbitrary File Reading vulnerability, allowing remote attackers with regular privileges to exploit Absolute Path Traversal to download arbitrary system files.HIGH7.139.1%Aug 22, 2025
CVE-2025-9255WebITR developed by Uniong has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.HIGH8.738.3%Aug 22, 2025
CVE-2025-9254WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log into the system as arbitrary users by exploiting a specific functionality.CRITICAL9.344.6%Aug 22, 2025
CVE-2024-8586WebITR from Uniong has an Open Redirect vulnerability, which allows unauthorized remote attackers to exploit this vulnerability to forge URLs. Users, believing they are accessing a trusted domain, can be redirected to another page, potentially leading to phishing attacks.MEDIUM6.128.1%Sep 9, 2024