Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-54347 OpenEMR 7.0.1 contains an authentication brute force vulnerability that allows attackers to bypass rate limiting protections by sending repeated logi… Openemr No fix yet Fix from $1,9502026-05-05 CRITICAL 9.8 CVE-2024-22611EPSS 6% OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controll… Openemr No fix yet Fix from $2,3002025-04-03 CRITICAL 9.8 CVE-2020-13567 Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an … Openemr No fix yet Fix from $2,3002022-04-18 MEDIUM 5.4 CVE-2022-24643 A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0. Openemr No fix yet Fix from $1,6002022-03-25 HIGH 8.1 CVE-2022-25471 An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas v… Openemr Mitigation only Fix from $1,9502022-03-03 MEDIUM 6.5 CVE-2021-41843EPSS 14% An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables … Openemr No fix yet Fix from $1,6002021-12-17 MEDIUM 6.5 CVE-2021-40352EPSS 10% OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users. Openemr No fix yet Fix from $1,6002021-09-01 HIGH 8.2 CVE-2021-32101 The Patient Portal of OpenEMR 5.0.2.1 is affected by a incorrect access control system in portal/patient/_machine_config.php. To exploit the vulnerab… Openemr Mitigation only Fix from $1,9502021-05-07 HIGH 8.8 CVE-2020-13566 SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP requ… Openemr No fix yet Fix from $1,9502021-04-13 HIGH 8.8 CVE-2020-13568EPSS 30% SQL injection vulnerability exists in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP reque… Openemr No fix yet Fix from $1,9502021-04-13 MEDIUM 6.1 CVE-2020-13565 An open redirect vulnerability exists in the return_page redirection functionality of phpGACL 3.3.7, OpenEMR 5.0.2 and OpenEMR development version 6.… Openemr No fix yet Fix from $1,6002021-02-10 HIGH 8.8 CVE-2020-13569 A cross-site request forgery vulnerability exists in the GACL functionality of OpenEMR 5.0.2 and development version 6.0.0 (commit babec93f600ff1394f… Openemr No fix yet Fix from $1,9502021-01-28 HIGH 8.8 CVE-2020-19364EPSS 71% OpenEMR 5.0.1 allows an authenticated attacker to upload and execute malicious PHP scripts through /controller.php. Openemr No fix yet Fix from $1,9502021-01-20 HIGH 8.8 CVE-2018-16795 OpenEMR 5.0.1.3 allows Cross-Site Request Forgery (CSRF) via library/ajax and interface/super, as demonstrated by use of interface/super/manage_site_… Openemr No fix yet Fix from $1,9502020-12-31 MEDIUM 6.1 CVE-2019-8368EPSS 47% OpenEMR v5.0.1-6 allows XSS. Openemr No fix yet Fix from $1,6002019-09-16 HIGH 7.2 CVE-2019-8371 OpenEMR v5.0.1-6 allows code execution. Openemr No fix yet Fix from $1,9502019-09-16 MEDIUM 5.4 CVE-2018-1000218 OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'file' parameter in line #43 of interface/fax/fax_view.php that c… Openemr No fix yet Fix from $1,6002018-08-20 MEDIUM 5.4 CVE-2018-1000219 OpenEMR version v5_0_1_4 contains a Cross Site Scripting (XSS) vulnerability in The 'scan' parameter in line #41 of interface/fax/fax_view.php that c… Openemr No fix yet Fix from $1,6002018-08-20 MEDIUM 6.1 CVE-2017-6394 Multiple Cross-Site Scripting (XSS) issues were discovered in OpenEMR 5.0.0 and 5.0.1-dev. The vulnerabilities exist due to insufficient filtration o… Openemr No fix yet Fix from $1,6002017-03-02 MEDIUM 6.8 CVE-2011-5161 Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by … Openemr No fix yet Fix from $1,6002012-09-09