LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
cve recordhighzero dayexploit reported

CVE-2024-58374

Published
CVSS7.5
Severityhigh
WeaknessCWE-89
EPSS0.47%39.7th percentile
Exploited1 KEV source

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

patch window

Called exploited the same day it was disclosed.

Measured from the CVE publication date to the earliest of 1 KEV catalogue that list it.

The life of this vulnerability

  1. CVE published
  2. First KEV listingsame day
  3. Last sighting20d

Gaps are compressed to equal steps. The elapsed time is printed under each.

Which catalogues call it exploited

Sources1 of 3
Listings differ by
Strongest claimconfirmed

This rests on a single catalogue. No second catalogue corroborates the claim that it is being exploited. CIRCL is an aggregator and is not counted.

Public exploitation evidence

3 public reports collected from VulnCheck and CIRCL, first on Aug 13, 2026. Each links to its original source. We have not verified them.

Description

Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attackers to access protected resources by supplying a path traversal sequence in the request URI to bypass the oauthservlet authentication filter. Attackers can inject UNION-based SQL payloads through the unsanitized codeitemid parameter into the underlying Microsoft SQL Server query to retrieve sensitive database contents including user credentials. Exploitation evidence was first observed by the Shadowserver Foundation on 2024-07-30 (UTC).

References

← Back to the CVE Tracker

Our coverage of CVE-2024-58374

CVE-2024-58374high

CVE-2024-58374: Hongjing e-HR SQL Injection Exploited on Disclosure Day

A critical SQL injection vulnerability in Hongjing Century e-HR was exploited on the same day it was publicly disclosed, leaving no patch window for affected organizations.