lenve has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 6.3 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Weakness classes
Products
- vhr 5
Worst active — by depth score
CVE-2026-90498High· 7.3A vulnerability was identified in lenve vhr 1.0-SNAPSHOT52CVE-2026-90501Medium· 6.3A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT47CVE-2026-90500Medium· 6.3A weakness has been identified in lenve vhr 1.0-SNAPSHOT47CVE-2026-90490Medium· 6.3A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT47CVE-2026-90499Medium· 5.4A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT42
lenve vulnerabilities
CVEs affecting lenve, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-90498High· 7.3PoCA vulnerability was identified in lenve vhr 1.0-SNAPSHOT
A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the file vhr.sql. The manipulation leads to use of default credentials. Remote exploitation of the attack is possible. The …
CVE-2026-90490Medium· 6.3PoCA security flaw has been discovered in lenve vhr 1.0-SNAPSHOT
A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization. The attack is possible to be carried out remot…
CVE-2026-90501Medium· 6.3PoCA security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT
A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. …
CVE-2026-90500Medium· 6.3PoCA weakness has been identified in lenve vhr 1.0-SNAPSHOT
A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upl…
CVE-2026-90499Medium· 5.4PoCA security flaw has been discovered in lenve vhr 1.0-SNAPSHOT
A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. This affects the function HrInfoController.updatePass of the file /hr/pass of the component Password Update Handler. The manipulation of the argument hrid results in improper…