Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2023-54347
OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated logi…
Openemr
No fix yet
CRITICAL 9.8
CVE-2024-22611EPSS 6%
OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controll…
Openemr
No fix yet
CRITICAL 9.8
CVE-2020-13567
Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an …
Openemr
No fix yet
MEDIUM 5.4
CVE-2022-24643
A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0.
Openemr
No fix yet
HIGH 8.1
CVE-2022-25471
An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas v…
Openemr
Mitigation only
MEDIUM 6.5
CVE-2021-41843EPSS 14%
An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables …
Openemr
No fix yet
MEDIUM 6.5
CVE-2021-40352EPSS 10%
OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.
Openemr
No fix yet
HIGH 8.2
CVE-2021-32101
The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerab…
Openemr
Mitigation only
HIGH 8.8
CVE-2020-13566
SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP requ…
Openemr
No fix yet
HIGH 8.8
CVE-2020-13568EPSS 30%
SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP reque…
Openemr
No fix yet
MEDIUM 6.1
CVE-2020-13565
An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.…
Openemr
No fix yet
HIGH 8.8
CVE-2020-13569
A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f…
Openemr
No fix yet
HIGH 8.8
CVE-2020-19364EPSS 71%
OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php.
Openemr
No fix yet
HIGH 8.8
CVE-2018-16795
OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_…
Openemr
No fix yet
MEDIUM 6.1
CVE-2019-8368EPSS 47%
OpenEMR v5.0.1-6 allows XSS.
Openemr
No fix yet
HIGH 7.2
CVE-2019-8371
OpenEMR v5.0.1-6 allows code execution.
Openemr
No fix yet
MEDIUM 5.4
CVE-2018-1000218
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that c…
Openemr
No fix yet
MEDIUM 5.4
CVE-2018-1000219
OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that c…
Openemr
No fix yet
MEDIUM 6.1
CVE-2017-6394
Multiple Cross-Site Scripting (XSS) issues were discovered in OpenEMR 5.0.0 and 5.0.1-dev. The vulnerabilities exist due to insufficient filtration o…
Openemr
No fix yet
MEDIUM 6.8
CVE-2011-5161
Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by …
Openemr
No fix yet