Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openemr MEDIUM 6.1
CVE-2018-1000020

OpenEMR version 5.0.0 contains a Cross Site Scripting (XSS) vulnerability in open-flash-chart.swf and _posteddata.php that can result in . This vulne…

Patch available
Fix from $1,600 2018-02-09
Openemr HIGH 8.1
CVE-2017-1000241

The application OpenEMR version 5.0.0, 5.0.1-dev and prior is affected by vertical privilege escalation vulnerability. This vulnerability can allow a…

Fix: after 5.0.1
Fix from $1,950 2017-11-17
Openemr MEDIUM 5.4
CVE-2017-1000240

The application OpenEMR is affected by multiple reflected & stored Cross-Site Scripting (XSS) vulnerabilities affecting version 5.0.0 and prior versi…

Fix: after 5.0.0
Fix from $1,600 2017-11-17
Openemr HIGH 7.5
CVE-2017-16540

OpenEMR before 5.0.0 Patch 5 allows unauthenticated remote database copying because setup.php exposes functionality for cloning an existing OpenEMR s…

Fix: 5.0.0+
Fix from $1,950 2017-11-04
Openemr HIGH 7.5
CVE-2017-12064

The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior allows attackers to bypass intended access restrictions v…

Patch available
Fix from $1,950 2017-08-01
Openemr HIGH 8.8
CVE-2017-9380EPSS 15%

OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context…

Fix: after 5.0.0
Fix from $1,950 2017-06-02
Openemr MEDIUM 6.1
CVE-2017-6394

Multiple Cross-Site Scripting (XSS) issues were discovered in OpenEMR 5.0.0 and 5.0.1-dev. The vulnerabilities exist due to insufficient filtration o…

No fix yet
Fix from $1,600 2017-03-02
Openemr MEDIUM 5.0
CVE-2015-4453

interface/globals.php in OpenEMR 2.x, 3.x, and 4.x before 4.2.0 patch 2 allows remote attackers to bypass authentication and obtain sensitive informa…

Patch available
Fix from $1,600 2015-07-05
Openemr MEDIUM 6.5
CVE-2014-5462

Multiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Patch 7) and earlier allow remote authenticated users to execute arbitrary SQL commands via …

Fix: after 4.1.2
Fix from $1,600 2014-12-08
Openemr MEDIUM 6.5
CVE-2013-4619

Multiple SQL injection vulnerabilities in OpenEMR 4.1.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) start or (2) e…

Patch available
Fix from $1,600 2013-08-09
Openemr HIGH 7.5
CVE-2012-2115

SQL injection vulnerability in interface/login/validateUser.php in OpenEMR 4.1.0 and possibly earlier allows remote attackers to execute arbitrary SQ…

Fix: after 4.1.0
Fix from $1,950 2012-09-09
Openemr MEDIUM 6.8
CVE-2011-5161

Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to execute arbitrary PHP code by …

No fix yet
Fix from $1,600 2012-09-09