Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2024-55374 REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts. Redcap Mitigation only Fix from $1,6002026-01-02 MEDIUM 5.4 CVE-2024-37394 A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web scri… Redcap 14.2.1+ Fix from $1,6002025-06-10 MEDIUM 5.4 CVE-2024-37395 A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web … Redcap 14.2.1+ Fix from $1,6002025-06-10 MEDIUM 5.4 CVE-2024-37396 A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web scrip… Redcap 14.2.1+ Fix from $1,6002025-06-10 HIGH 8.8 CVE-2025-23113 An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file… Redcap Mitigation only Fix from $1,9502025-01-10 MEDIUM 6.1 CVE-2025-23110 An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject field exists while performing an … Redcap Mitigation only Fix from $1,6002025-01-10 MEDIUM 6.1 CVE-2025-23111 An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. … Redcap Mitigation only Fix from $1,6002025-01-10 MEDIUM 6.1 CVE-2025-23112 An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts in… Redcap Mitigation only Fix from $1,6002025-01-10 MEDIUM 5.4 CVE-2024-56377 A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the S… Redcap No fix yet Fix from $1,6002025-01-09 MEDIUM 5.4 CVE-2024-56376 A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts i… Redcap No fix yet Fix from $1,6002025-01-09 MEDIUM 5.4 CVE-2024-56313 A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated users to inject malicious scr… Redcap after 14.9.6 Fix from $1,6002024-12-22 MEDIUM 5.4 CVE-2024-56314 A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts… Redcap after 14.9.6 Fix from $1,6002024-12-22 MEDIUM 5.4 CVE-2024-56312 A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenticated users to inject malicio… Redcap after 14.9.6 Fix from $1,6002024-12-22 HIGH 8.8 CVE-2024-56310 REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker c… Redcap after 14.9.6 Fix from $1,9502024-12-22 HIGH 8.8 CVE-2024-56311 REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attack. An a… Redcap after 14.9.6 Fix from $1,9502024-12-22 MEDIUM 6.1 CVE-2024-45527 REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and… Redcap No fix yet Fix from $1,6002024-09-02 MEDIUM 6.5 CVE-2023-38825 SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mech… Redcap 13.8.0+ Fix from $1,6002024-03-21 MEDIUM 5.4 CVE-2023-37798 A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execut… Redcap after 13.1.35 Fix from $1,6002023-09-07 MEDIUM 6.1 CVE-2022-42715 A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, … Redcap 12.4.18 / 12.5.11+ Fix from $1,6002022-10-12 MEDIUM 5.4 CVE-2022-24004 A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11. This issue allows any authenticat… Redcap No fix yet Fix from $1,6002022-06-15 MEDIUM 5.4 CVE-2022-24127 A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue allows any… Redcap No fix yet Fix from $1,6002022-06-15 CRITICAL 9.0 CVE-2021-42136 A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute … Redcap 11.4.0+ Fix from $2,3002022-04-13 CRITICAL 9.8 CVE-2020-26712 REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of in… Redcap No fix yet Fix from $2,3002021-01-12 MEDIUM 6.1 CVE-2020-26713 REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the user is immediately returne… Redcap No fix yet Fix from $1,6002021-01-12 MEDIUM 5.4 CVE-2019-17121 REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values. Redcap 9.3.4+ Fix from $1,6002019-10-04 MEDIUM 5.4 CVE-2019-15127 REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file. Redcap 9.3.0+ Fix from $1,6002019-08-21 HIGH 7.5 CVE-2019-14937 REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/c… Redcap 9.3.0+ Fix from $1,9502019-08-17 HIGH 8.8 CVE-2017-7351 A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload. Redcap 7.0.11+ Fix from $1,9502018-02-08 HIGH 8.8 CVE-2017-10961 REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components. Redcap after 7.5.0 Fix from $1,9502017-07-18 MEDIUM 6.1 CVE-2017-10962 REDCap before 7.5.1 has XSS via the query string. Redcap after 7.5.0 Fix from $1,6002017-07-18