x
xinhu
Security Risk Profile
35
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 10 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from June 17, 2024 to present
10
Total CVEs
1
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
5.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
35/100
low
Severity Distribution
Critical
1High
0Medium
9Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
3Age Distribution
Common Weaknesses (CWE)
1
XSS
5
2
SQL Injection
2
3
Code Injection
1
Most Affected Products
1. Rockoa RockOA7
2. Xinhu Rainrock RockOA6
3. Xinhu RockOA4
4. Rockoa Xinhu2
Recent Vulnerabilities
See more →CVE-2026-0587
CVSS 5.4EPSS 0%medium
Xinhu Rainrock RockOA Cover Image rock_page_gong.php cross site scripting
Jan 5, 2026🔧 No Patch
CVE-2025-63738
CVSS 4.3medium
Dec 9, 2025🔧 No Patch
CVE-2025-63740
CVSS 4.3medium
Dec 9, 2025🔧 No Patch
CVE-2025-63742
CVSS 9.8critical
Dec 9, 2025🔧 No Patch
CVE-2025-63739
CVSS 4.3medium
Dec 9, 2025🔧 No Patch
CVE-2025-63737
CVSS 6.1medium
Dec 9, 2025🔧 No Patch
CVE-2025-9602
CVSS 6.5EPSS 0%medium
Xinhu RockOA index.php publicsaveAjax improper authorization
Aug 29, 2025🔧 No Patch
CVE-2024-6939
CVSS 5.3EPSS 0%medium
Xinhu RockOA tpl_upload.html okla cross site scripting
Jul 21, 2024🔧 No Patch
CVE-2024-37623
CVSS 6.1medium
Jun 17, 2024🔧 No Patch
CVE-2024-37622
CVSS 6.1medium
Jun 17, 2024🔧 No Patch
Monitor xinhu in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.