Home/Product/learningdigital orca hcm
Product

learningdigital orca hcm

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-1389
< 11.0
Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary S
8.8HIGH
CVE-2025-1388
< 11.0
Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to up
8.8HIGH
CVE-2025-1387
< 11.0
Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in t
9.8CRITICAL
CVE-2024-8585
< 11.0
Orca HCM from LEARNING DIGITA does not properly restrict a specific parameter of the file download functionality, allowing a remot
6.5MEDIUM
CVE-2024-8584
< 11.0
Orca HCM from LEARNING DIGITAL has an Missing Authentication vulnerability, allowing unauthenticated remote attacker to exploit th
9.8CRITICAL
CVE-2021-35968
<= 10.0
The directory list page parameter of the Orca HCM digital learning platform fails to filter special characters properly. Remote at
4.3MEDIUM
CVE-2021-35967
<= 10.0
The directory page parameter of the Orca HCM digital learning platform does not filter special characters. Remote attackers can ac
5.3MEDIUM
CVE-2021-35966
<= 10.0
The specific function of the Orca HCM digital learning platform does not filter input parameters properly, which causing the URL c
6.1MEDIUM
CVE-2021-35965
<= 10.0
The Orca HCM digital learning platform uses a weak factory default administrator password, which is hard-coded in the source code
9.8CRITICAL
CVE-2021-35964
<= 10.0
The management page of the Orca HCM digital learning platform does not perform identity verification, which allows remote attacker
7.3HIGH
CVE-2021-35963
<= 10.0
The specific parameter of upload function of the Orca HCM digital learning platform does not filter file format, which allows remo
9.8CRITICAL
threatengine.sh