Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opencrx MEDIUM 6.1
CVE-2023-27151

openCRX 5.2.0 was discovered to contain an HTML injection vulnerability for Search Criteria-Activity Number (in the Saved Search Activity) via the Na…

No fix yet
Fix from $1,600 2024-02-29
Opencrx MEDIUM 5.4
CVE-2023-27150

openCRX 5.2.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Name field after creation of a Tracker in Manage Activity.

No fix yet
Fix from $1,600 2023-12-26
Opencrx MEDIUM 6.1
CVE-2023-40809

OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.

No fix yet
Fix from $1,600 2023-11-18
Opencrx MEDIUM 6.1
CVE-2023-40810

OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field.

No fix yet
Fix from $1,600 2023-11-18
Opencrx MEDIUM 6.1
CVE-2023-40812

OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field.

No fix yet
Fix from $1,600 2023-11-18
Opencrx MEDIUM 6.1
CVE-2023-40813

OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation.

No fix yet
Fix from $1,600 2023-11-18
Opencrx MEDIUM 6.1
CVE-2023-40814

OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Name Field.

No fix yet
Fix from $1,600 2023-11-18
Opencrx MEDIUM 6.1
CVE-2023-40815

OpenCRX version 5.2.0 is vulnerable to HTML injection via the Category Creation Name Field.

No fix yet
Fix from $1,600 2023-11-18
Opencrx MEDIUM 6.1
CVE-2023-40816

OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Milestone Name Field.

No fix yet
Fix from $1,600 2023-11-18
Opencrx MEDIUM 6.1
CVE-2023-40817

OpenCRX version 5.2.0 is vulnerable to HTML injection via the Product Configuration Name Field.

No fix yet
Fix from $1,600 2023-11-18
Opencrx CRITICAL 9.8
CVE-2023-46502

An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuild…

Patch available
Fix from $2,300 2023-10-30
Opencrx MEDIUM 5.3
CVE-2022-40084

OpenCRX before v5.2.2 was discovered to be vulnerable to password enumeration due to the difference in error messages received during a password rese…

Fix: after 5.2.2
Fix from $1,600 2022-10-20
Opencrx MEDIUM 6.1
CVE-2021-25959

In OpenCRX, versions v4.0.0 through v5.1.0 are vulnerable to reflected Cross-site Scripting (XSS), due to unsanitized parameters in the password rese…

Fix: after 5.1.0
Fix from $1,600 2021-09-29
Opencrx CRITICAL 9.1
CVE-2020-7378

CRIXP OpenCRX version 4.30 and 5.0-20200717 and prior suffers from an unverified password change vulnerability. An attacker who is able to connect to…

Fix: after 4.3.0
Fix from $2,300 2020-11-24