Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openemr HIGH 7.5
CVE-2023-22974

A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attack…

Fix: 7.0.0+
Fix from $1,950 2023-02-22
Openemr MEDIUM 5.4
CVE-2023-22972

A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7.0.0 allows remote authentica…

Fix: 7.0.0+
Fix from $1,600 2023-02-22
Openemr MEDIUM 6.1
CVE-2022-4615

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.

Fix: 7.0.0.2+
Fix from $1,600 2022-12-19
Openemr HIGH 8.1
CVE-2022-4567

Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.

Fix: 7.0.0.2+
Fix from $1,950 2022-12-17
Openemr HIGH 8.8
CVE-2022-4506

Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2.

Fix: 7.0.0.2+
Fix from $1,950 2022-12-15
Openemr HIGH 7.5
CVE-2022-4504

Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2.

Fix: 7.0.0.2+
Fix from $1,950 2022-12-15
Openemr MEDIUM 6.1
CVE-2022-4502

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.

Fix: 7.0.0.2+
Fix from $1,600 2022-12-15
Openemr MEDIUM 6.1
CVE-2022-4503

Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.0.2.

Fix: 7.0.0.2+
Fix from $1,600 2022-12-15
Openemr MEDIUM 5.4
CVE-2022-2824

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

Fix: 7.0.0.1+
Fix from $1,600 2022-08-15
Openemr MEDIUM 5.4
CVE-2022-2734

Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.

Fix: 7.0.0.1+
Fix from $1,600 2022-08-09
Openemr HIGH 8.3
CVE-2022-2732

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.

Fix: 7.0.0.1+
Fix from $1,950 2022-08-09
Openemr MEDIUM 6.5
CVE-2022-2730

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1.

Fix: 7.0.0.1+
Fix from $1,600 2022-08-09
Openemr MEDIUM 6.1
CVE-2022-2731

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

Fix: 7.0.0.1+
Fix from $1,600 2022-08-09
Openemr MEDIUM 6.1
CVE-2022-2733EPSS 96%

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

Fix: 7.0.0.1+
Fix from $1,600 2022-08-09
Openemr MEDIUM 5.4
CVE-2022-2729

Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1.

Fix: 7.0.0.1+
Fix from $1,600 2022-08-09
Openemr HIGH 8.1
CVE-2022-2493

Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0.

Fix: 7.0.0+
Fix from $1,950 2022-07-22
Openemr MEDIUM 5.4
CVE-2022-2494

Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0.

Fix: 7.0.0+
Fix from $1,600 2022-07-22
Openemr MEDIUM 6.5
CVE-2022-1461

Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1.

Fix: 6.1.0.1+
Fix from $1,600 2022-04-25
Openemr HIGH 8.3
CVE-2022-1459

Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1.

Fix: 6.1.0.1+
Fix from $1,950 2022-04-25
Openemr MEDIUM 5.4
CVE-2022-1458

Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1.

Fix: 6.1.0.1+
Fix from $1,600 2022-04-25
Openemr CRITICAL 9.8
CVE-2020-13567

Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an …

No fix yet
Fix from $2,300 2022-04-18
Openemr MEDIUM 5.4
CVE-2022-1178EPSS 52%

Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

Fix: 6.0.0.4+
Fix from $1,600 2022-03-30
Openemr MEDIUM 5.4
CVE-2022-1179EPSS 77%

Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4.

Fix: 6.0.0.4+
Fix from $1,600 2022-03-30
Openemr MEDIUM 5.4
CVE-2022-1181EPSS 51%

Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2.

Fix: 6.0.0.2+
Fix from $1,600 2022-03-30
Openemr MEDIUM 5.4
CVE-2022-24643

A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0.

No fix yet
Fix from $1,600 2022-03-25
Openemr HIGH 8.1
CVE-2022-25471

An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas v…

Mitigation only
Fix from $1,950 2022-03-03
Openemr MEDIUM 6.5
CVE-2021-41843EPSS 14%

An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables …

No fix yet
Fix from $1,600 2021-12-17
Openemr MEDIUM 6.5
CVE-2021-40352EPSS 10%

OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users.

No fix yet
Fix from $1,600 2021-09-01
Openemr HIGH 8.1
CVE-2021-25923

In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malic…

Fix: after 6.0.0.1
Fix from $1,950 2021-06-24
Openemr HIGH 8.8
CVE-2021-32102

A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1.

Patch available
Fix from $1,950 2021-05-07