Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2024-55374 REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts. Redcap Mitigation only Fix from $1,6002026-01-02 HIGH 8.8 CVE-2025-23113 An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file… Redcap Mitigation only Fix from $1,9502025-01-10 MEDIUM 6.1 CVE-2025-23110 An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject field exists while performing an … Redcap Mitigation only Fix from $1,6002025-01-10 MEDIUM 6.1 CVE-2025-23111 An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. … Redcap Mitigation only Fix from $1,6002025-01-10 MEDIUM 6.1 CVE-2025-23112 An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts in… Redcap Mitigation only Fix from $1,6002025-01-10 MEDIUM 5.4 CVE-2024-56377 A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the S… Redcap No fix yet Fix from $1,6002025-01-09 MEDIUM 5.4 CVE-2024-56376 A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts i… Redcap No fix yet Fix from $1,6002025-01-09 MEDIUM 6.1 CVE-2024-45527 REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and… Redcap No fix yet Fix from $1,6002024-09-02 MEDIUM 5.4 CVE-2022-24004 A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11. This issue allows any authenticat… Redcap No fix yet Fix from $1,6002022-06-15 MEDIUM 5.4 CVE-2022-24127 A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue allows any… Redcap No fix yet Fix from $1,6002022-06-15 CRITICAL 9.8 CVE-2020-26712 REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of in… Redcap No fix yet Fix from $2,3002021-01-12 MEDIUM 6.1 CVE-2020-26713 REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the user is immediately returne… Redcap No fix yet Fix from $1,6002021-01-12