Vulnerability index

Browse CVEs

17 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bio Formats HIGH 7.8
CVE-2026-22187

Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during im…

Fix: after 8.3.0
Fix from $1,950 2026-01-07
Bio Formats HIGH 7.1
CVE-2026-22186

Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing componen…

Fix: after 8.3.0
Fix from $1,950 2026-01-07
Omero Web MEDIUM 5.3
CVE-2025-54791

OMERO.web provides a web based client and plugin infrastructure. Prior to version 5.29.2, if an error occurred when resetting a user's password using…

Fix: 5.29.2+
Fix from $1,600 2025-08-13
Omero Web MEDIUM 6.1
CVE-2024-35180

OMERO.web provides a web based client and plugin infrastructure. There is currently no escaping or validation of the `callback` parameter that can be…

Fix: 5.26.0+
Fix from $1,600 2024-05-21
Omero Figure MEDIUM 6.1
CVE-2021-41132

OMERO.web provides a web based client and plugin infrastructure. In versions prior to 5.11.0, a variety of templates do not perform proper sanitizati…

Fix: 4.4.1 / 5.11.0+
Fix from $1,600 2021-10-14
Omero.web MEDIUM 6.5
CVE-2021-21376

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 loads various information about the cu…

Fix: 5.9.0+
Fix from $1,600 2021-03-23
Omero.web MEDIUM 5.4
CVE-2021-21377

OMERO.web is open source Django-based software for managing microscopy imaging. OMERO.web before version 5.9.0 supports redirection to a given URL af…

Fix: 5.9.0+
Fix from $1,600 2021-03-23
Omero.server CRITICAL 9.8
CVE-2019-16244

OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.

Fix: 5.6.1+
Fix from $2,300 2020-07-22
Omero.server HIGH 7.5
CVE-2019-9943

In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERO model o…

Fix: after 5.6.0
Fix from $1,950 2020-06-17
Omero.server HIGH 7.5
CVE-2019-9944

In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permissions r…

Fix: after 5.6.0
Fix from $1,950 2020-06-17
Omero.web MEDIUM 5.7
CVE-2020-7932

OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters. If an attacker tricks a …

Fix: 5.6.3+
Fix from $1,600 2020-06-17
Omero MEDIUM 5.3
CVE-2019-16245

OMERO before 5.6.1 makes the details of each user available to all users.

Fix: 5.6.1+
Fix from $1,600 2020-06-17
Omero HIGH 8.8
CVE-2014-7198

OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.

Fix: 5.0.6+
Fix from $1,950 2019-04-01
Omero MEDIUM 6.7
CVE-2018-1000635

The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains a Information Exposure Through Sent Data vulnerability in OMERO.server t…

Fix: after 5.4.6
Fix from $1,600 2018-08-20
Omero HIGH 7.2
CVE-2018-1000633

The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vulnerability in the login form a…

Fix: 5.4.7+
Fix from $1,950 2018-08-20
Omero HIGH 7.2
CVE-2018-1000634

The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management that can res…

Fix: after 5.4.6
Fix from $1,950 2018-08-20
Omero HIGH 8.3
CVE-2017-1000438

In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the underlying fi…

Fix: after 5.3.3
Fix from $1,950 2018-01-02