Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2026-25127
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the server does not …
Openemr
8.0.0+
MEDIUM 6.1
CVE-2026-24847
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form mo…
Openemr
8.0.0+
HIGH 8.1
CVE-2025-67752
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP clien…
Openemr
7.0.4+
MEDIUM 6.1
CVE-2026-21443
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the `xl()` translati…
Openemr
8.0.0+
MEDIUM 5.4
CVE-2025-69231
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a stored cross-site …
Openemr
8.0.0+
MEDIUM 5.0
CVE-2025-68277
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, when a link is sent …
Openemr
7.0.4+
MEDIUM 5.4
CVE-2025-67491
OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0.5 through 7.0.3.4 have a stor…
Openemr
7.0.4+
HIGH 8.8
CVE-2025-67645
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access…
Openemr
Patch available
MEDIUM 6.5
CVE-2025-54373
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability…
Openemr
Patch available
MEDIUM 5.4
CVE-2021-47817
OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to…
Openemr
Patch available
HIGH 8.8
CVE-2013-10044
An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator creden…
Openemr
after 4.1.1
HIGH 7.6
CVE-2025-32794EPSS 9%
OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerab…
Openemr
7.0.3.4+
HIGH 7.6
CVE-2025-43860EPSS 9%
OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerab…
Openemr
7.0.3.4+
MEDIUM 5.4
CVE-2025-32967
OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions prior to 7.0…
Openemr
7.0.3.4+
CRITICAL 9.8
CVE-2024-22611EPSS 6%
OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controll…
Openemr
No fix yet
MEDIUM 5.4
CVE-2025-31121EPSS 15%
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature …
Openemr
7.0.3.1+
HIGH 7.5
CVE-2025-31117
OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (…
Openemr
7.0.3.1+
MEDIUM 5.4
CVE-2025-30161EPSS 10%
OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis…
Openemr
7.0.3+
MEDIUM 6.1
CVE-2025-29772
OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is out…
Openemr
7.0.3+
HIGH 7.5
CVE-2025-29789
OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Di…
Openemr
7.0.3+
CRITICAL 9.8
CVE-2024-37734
An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter.
Openemr
Patch available
HIGH 8.1
CVE-2023-2950
Improper Authorization in GitHub repository openemr/openemr prior to 7.0.1.
Openemr
7.0.1+
MEDIUM 6.1
CVE-2023-2949
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.1.
Openemr
7.0.1+
MEDIUM 6.1
CVE-2023-2948EPSS 97%
Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.1.
Openemr
7.0.1+
HIGH 8.1
CVE-2023-2946
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
Openemr
7.0.1+
HIGH 8.8
CVE-2023-2943
Code Injection in GitHub repository openemr/openemr prior to 7.0.1.
Openemr
7.0.1+
MEDIUM 5.4
CVE-2023-2944
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.1.
Openemr
7.0.1+
MEDIUM 5.4
CVE-2023-2945
Missing Authorization in GitHub repository openemr/openemr prior to 7.0.1.
Openemr
7.0.1+
HIGH 8.1
CVE-2023-2942
Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.1.
Openemr
7.0.1+
HIGH 8.8
CVE-2023-22973
A Local File Inclusion (LFI) vulnerability in interface/forms/LBF/new.php in OpenEMR < 7.0.0 allows remote authenticated users to execute code via th…
Openemr
7.0.0+