Huntflow's vulnerability footprint centers on its enterprise recruitment and talent-management platform, with the observed weakness classes reflecting risks common to web-based business applications: exposure of sensitive information, injection flaws, and improper authentication controls. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Huntflow over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-37934CRITICAL Due to insufficient server-side login-attempt limit enforcement, a vulnerability in /account/login in Huntflow Enterprise before 3.10.14 could allow an unauthenticated, remote user | Dec 10, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-37935HIGH An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name | Dec 10, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-37933HIGH An LDAP injection vulnerability in /account/login in Huntflow Enterprise before 3.10.6 could allow an unauthenticated, remote user to modify the logic of an LDAP query and bypass a | Oct 14, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Huntflow.
Media articles that mention a CVE ID that affects a product developed by Huntflow — matched by CVE ID, not by vendor name.