Vulnerability index

Browse CVEs

192 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2023-22974 A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read arbitrary files by controlling a connection to an attack… Openemr 7.0.0+ Fix from $1,9502023-02-22 MEDIUM 5.4 CVE-2023-22972 A Reflected Cross-site scripting (XSS) vulnerability in interface/forms/eye_mag/php/eye_mag_functions.php in OpenEMR < 7.0.0 allows remote authentica… Openemr 7.0.0+ Fix from $1,6002023-02-22 MEDIUM 6.1 CVE-2022-4615 Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2. Openemr 7.0.0.2+ Fix from $1,6002022-12-19 HIGH 8.1 CVE-2022-4567 Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2. Openemr 7.0.0.2+ Fix from $1,9502022-12-17 HIGH 8.8 CVE-2022-4506 Unrestricted Upload of File with Dangerous Type in GitHub repository openemr/openemr prior to 7.0.0.2. Openemr 7.0.0.2+ Fix from $1,9502022-12-15 HIGH 7.5 CVE-2022-4504 Improper Input Validation in GitHub repository openemr/openemr prior to 7.0.0.2. Openemr 7.0.0.2+ Fix from $1,9502022-12-15 MEDIUM 6.1 CVE-2022-4502 Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2. Openemr 7.0.0.2+ Fix from $1,6002022-12-15 MEDIUM 6.1 CVE-2022-4503 Cross-site Scripting (XSS) - Generic in GitHub repository openemr/openemr prior to 7.0.0.2. Openemr 7.0.0.2+ Fix from $1,6002022-12-15 MEDIUM 5.4 CVE-2022-2824 Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1. Openemr 7.0.0.1+ Fix from $1,6002022-08-15 MEDIUM 5.4 CVE-2022-2734 Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1. Openemr 7.0.0.1+ Fix from $1,6002022-08-09 HIGH 8.3 CVE-2022-2732 Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1. Openemr 7.0.0.1+ Fix from $1,9502022-08-09 MEDIUM 6.5 CVE-2022-2730 Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.1. Openemr 7.0.0.1+ Fix from $1,6002022-08-09 MEDIUM 6.1 CVE-2022-2731 Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1. Openemr 7.0.0.1+ Fix from $1,6002022-08-09 MEDIUM 6.1 CVE-2022-2733EPSS 96% Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1. Openemr 7.0.0.1+ Fix from $1,6002022-08-09 MEDIUM 5.4 CVE-2022-2729 Cross-site Scripting (XSS) - DOM in GitHub repository openemr/openemr prior to 7.0.0.1. Openemr 7.0.0.1+ Fix from $1,6002022-08-09 HIGH 8.1 CVE-2022-2493 Data Access from Outside Expected Data Manager Component in GitHub repository openemr/openemr prior to 7.0.0. Openemr 7.0.0+ Fix from $1,9502022-07-22 MEDIUM 5.4 CVE-2022-2494 Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.0. Openemr 7.0.0+ Fix from $1,6002022-07-22 MEDIUM 6.5 CVE-2022-1461 Non Privilege User can Enable or Disable Registered in GitHub repository openemr/openemr prior to 6.1.0.1. Openemr 6.1.0.1+ Fix from $1,6002022-04-25 HIGH 8.3 CVE-2022-1459 Non-Privilege User Can View Patient’s Disclosures in GitHub repository openemr/openemr prior to 6.1.0.1. Openemr 6.1.0.1+ Fix from $1,9502022-04-25 MEDIUM 5.4 CVE-2022-1458 Stored XSS Leads To Session Hijacking in GitHub repository openemr/openemr prior to 6.1.0.1. Openemr 6.1.0.1+ Fix from $1,6002022-04-25 CRITICAL 9.8 CVE-2020-13567 Multiple SQL injection vulnerabilities exist in phpGACL 3.3.7. A specially crafted HTTP request can lead to a SQL injection. An attacker can send an … Openemr No fix yet Fix from $2,3002022-04-18 MEDIUM 5.4 CVE-2022-1178EPSS 52% Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. Openemr 6.0.0.4+ Fix from $1,6002022-03-30 MEDIUM 5.4 CVE-2022-1179EPSS 77% Non-Privilege User Can Created New Rule and Lead to Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.4. Openemr 6.0.0.4+ Fix from $1,6002022-03-30 MEDIUM 5.4 CVE-2022-1181EPSS 51% Stored Cross Site Scripting in GitHub repository openemr/openemr prior to 6.0.0.2. Openemr 6.0.0.2+ Fix from $1,6002022-03-30 MEDIUM 5.4 CVE-2022-24643 A stored cross-site scripting (XSS) issue was discovered in the OpenEMR Hospital Information Management System version 6.0.0. Openemr No fix yet Fix from $1,6002022-03-25 HIGH 8.1 CVE-2022-25471 An Insecure Direct Object Reference (IDOR) vulnerability in OpenEMR 6.0.0 allows any authenticated attacker to access and modify unauthorized areas v… Openemr Mitigation only Fix from $1,9502022-03-03 MEDIUM 6.5 CVE-2021-41843EPSS 14% An authenticated SQL injection issue in the calendar search function of OpenEMR 6.0.0 before patch 3 allows an attacker to read data from all tables … Openemr No fix yet Fix from $1,6002021-12-17 MEDIUM 6.5 CVE-2021-40352EPSS 10% OpenEMR 6.0.0 has a pnotes_print.php?noteid= Insecure Direct Object Reference vulnerability via which an attacker can read the messages of all users. Openemr No fix yet Fix from $1,6002021-09-01 HIGH 8.1 CVE-2021-25923 In OpenEMR, versions 5.0.0 to 6.0.0.1 are vulnerable to weak password requirements as it does not enforce a maximum password length limit. If a malic… Openemr after 6.0.0.1 Fix from $1,9502021-06-24 HIGH 8.8 CVE-2021-32102 A SQL injection vulnerability exists (with user privileges) in library/custom_template/ajax_code.php in OpenEMR 5.0.2.1. Openemr Patch available Fix from $1,9502021-05-07