Aenrich's vulnerability footprint concentrates in its A+HRD human resources and recruitment platform, which despite a narrow product scope has achieved prominence among internet-exposed business applications. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes across a pattern of server-side attack surfaces: untrusted deserialization, path traversal, cross-site scripting, SQL injection, and server-side request forgery. These weakness classes are characteristic of web applications that handle user input, file operations, and backend system integration with insufficient validation and isolation boundaries. Defenders should treat patches for this vendor as urgent given the critical severity tendency and the sensitive personnel data that HR platforms typically retain; live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aenrich over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12871CRITICAL The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to craft administrator access tokens and use them to access the | Nov 12, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-12870CRITICAL The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to send crafted packets to obtain administrator access tokens an | Nov 12, 2025 | 9.8 | 32 | NO | NO |
CVE-2022-39042CRITICAL aEnrich a+HRD has improper validation for login function. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access API function to perf | Jan 3, 2023 | 9.8 | 31 | NO | NO |
CVE-2022-26676CRITICAL aEnrich a+HRD has inadequate privilege restrictions, an unauthenticated remote attacker can use the API function to upload and execute malicious scripts to control the system or di | Apr 7, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-39041CRITICAL aEnrich a+HRD has insufficient user input validation for specific API parameter. An unauthenticated remote attacker can exploit this vulnerability to inject arbitrary SQL commands | Jan 3, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-39039CRITICAL aEnrich’s a+HRD has inadequate filtering for specific URL parameter. An unauthenticated remote attacker can exploit this vulnerability to send arbitrary HTTP(s) request to launch S | Jan 3, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-20852CRITICAL aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ interpreter. An unauthenticated remote attacker can exploit this vulnerability to | Apr 27, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-20853CRITICAL aEnrich Technology a+HRD has a vulnerability of Deserialization of Untrusted Data within its MSMQ asynchronized message process. An unauthenticated remote attacker can exploit this | Apr 27, 2023 | 9.8 | 28 | NO | NO |
CVE-2025-0585CRITICAL The a+HRD from aEnrich Technology has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database | Jan 20, 2025 | 9.8 | 26 | NO | NO |
CVE-2022-28741HIGH aEnrich a+HRD 5.x Learning Management Key Performance Indicator System has a local file inclusion (LFI) vulnerability that occurs due to missing input validation in v5.x | Sep 9, 2022 | 8.1 | 25 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aenrich.
Media articles that mention a CVE ID that affects a product developed by Aenrich — matched by CVE ID, not by vendor name.