Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2026-40076
OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the module …
Openmrs
after 2.8.5
HIGH 7.5
CVE-2026-40075
OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openm…
Openmrs
after 2.8.5
HIGH 8.0
CVE-2025-25928
A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary opera…
Openmrs
No fix yet
MEDIUM 6.8
CVE-2025-25927
A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request.
Openmrs
No fix yet
MEDIUM 5.4
CVE-2025-25929
A reflected cross-site scripting (XSS) vulnerability in the component /legacyui/quickReportServlet of Openmrs 2.4.3 Build 0ff0ed allows attackers to …
Openmrs
No fix yet
MEDIUM 6.1
CVE-2020-36636
A vulnerability classified as problematic has been found in OpenMRS Admin UI Module up to 1.4.x. Affected is the function sendErrorMessage of the fil…
Admin Ui Module
1.5.0+
MEDIUM 6.1
CVE-2021-4291
A vulnerability was found in OpenMRS Admin UI Module up to 1.5.x. It has been declared as problematic. This vulnerability affects unknown code of the…
Admin Ui Module
1.6.0+
MEDIUM 6.1
CVE-2021-4292
A vulnerability was found in OpenMRS Admin UI Module up to 1.4.x. It has been rated as problematic. This issue affects some unknown processing of the…
Admin Ui Module
1.5.0+
MEDIUM 5.4
CVE-2020-36635
A vulnerability was found in OpenMRS Appointment Scheduling Module up to 1.12.x. It has been classified as problematic. This affects the function val…
Appointment Scheduling Module
1.13.0+
MEDIUM 6.1
CVE-2022-4727
A vulnerability, which was classified as problematic, was found in OpenMRS Appointment Scheduling Module up to 1.16.x. This affects the function getN…
Appointment Scheduling Module
1.17.0+
MEDIUM 6.1
CVE-2021-4288
A vulnerability was found in OpenMRS openmrs-module-referenceapplication up to 2.11.x. It has been rated as problematic. This issue affects some unkn…
Reference Application
2.12.0+
MEDIUM 6.1
CVE-2021-4289
A vulnerability classified as problematic was found in OpenMRS openmrs-module-referenceapplication up to 2.11.x. Affected by this vulnerability is th…
Reference Application
2.12.0+
MEDIUM 6.1
CVE-2021-4284
A vulnerability classified as problematic has been found in OpenMRS HTML Form Entry UI Framework Integration Module up to 1.x. This affects an unknow…
Htmlformentryui
2.0.0+
CRITICAL 9.8
CVE-2021-43094
An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via GET requ…
Openmrs
after 2.11
HIGH 7.5
CVE-2022-23612
OpenMRS is a patient-based medical record system focusing on giving providers a free customizable electronic medical record system. Affected versions…
Openmrs
2.1.5 / 2.2.1+
HIGH 8.8
CVE-2020-24621
A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS. By leveraging…
Htmlformentry
3.11.0+
MEDIUM 6.1
CVE-2020-5732
In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated user…
Openmrs
after 2.9.0
MEDIUM 6.1
CVE-2020-5733
In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenticated use…
Openmrs
after 2.9.0
MEDIUM 6.1
CVE-2020-5728
OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm). There is ins…
Openmrs
after 2.9.0
MEDIUM 6.1
CVE-2020-5729
In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS. Any page …
Openmrs
after 2.9.0
MEDIUM 6.1
CVE-2020-5730
In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.
Openmrs
after 2.9.0
MEDIUM 6.1
CVE-2020-5731
In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.
Openmrs
after 2.9.0
CRITICAL 9.8
CVE-2017-12795
OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).
Openmrs Module Htmlformentry
Patch available
CRITICAL 9.8
CVE-2018-19276EPSS 99%
OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary comman…
Openmrs
1.12.1 / 2.0.8+
CRITICAL 9.8
CVE-2018-16521
An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.
Html Form Entry
Patch available
CRITICAL 9.8
CVE-2017-12796
The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate user…
Openmrs
2.6.1+
HIGH 8.8
CVE-2017-7990
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScri…
Openmrs Module Reporting
Patch available
MEDIUM 6.8
CVE-2014-8073
Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the authentication of administrat…
Openmrs
No fix yet