Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Redcap MEDIUM 5.3
CVE-2024-55374

REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts.

Mitigation only
Fix from $1,600 2026-01-02
Redcap MEDIUM 5.4
CVE-2024-37394

A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary web scri…

Fix: 14.2.1+
Fix from $1,600 2025-06-10
Redcap MEDIUM 5.4
CVE-2024-37395

A stored cross-site scripting (XSS) vulnerability in the Public Survey function of REDCap 13.1.9 allows authenticated users to execute arbitrary web …

Fix: 14.2.1+
Fix from $1,600 2025-06-10
Redcap MEDIUM 5.4
CVE-2024-37396

A stored cross-site scripting (XSS) vulnerability in the Calendar function of REDCap 13.1.9 allows authenticated users to execute arbitrary web scrip…

Fix: 14.2.1+
Fix from $1,600 2025-06-10
Redcap HIGH 8.8
CVE-2025-23113

An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the alert-title while performing an upload of a CSV file…

Mitigation only
Fix from $1,950 2025-01-10
Redcap MEDIUM 6.1
CVE-2025-23110

An issue was discovered in REDCap 14.9.6. A Reflected cross-site scripting (XSS) vulnerability in the email-subject field exists while performing an …

Mitigation only
Fix from $1,600 2025-01-10
Redcap MEDIUM 6.1
CVE-2025-23111

An issue was discovered in REDCap 14.9.6. It allows HTML Injection via the Survey field name, exposing users to a redirection to a phishing website. …

Mitigation only
Fix from $1,600 2025-01-10
Redcap MEDIUM 6.1
CVE-2025-23112

An issue was discovered in REDCap 14.9.6. A stored cross-site scripting (XSS) vulnerability allows authenticated users to inject malicious scripts in…

Mitigation only
Fix from $1,600 2025-01-10
Redcap MEDIUM 5.4
CVE-2024-56377

A stored cross-site scripting (XSS) vulnerability in survey titles of REDCap 14.9.6 allows authenticated users to inject malicious scripts into the S…

No fix yet
Fix from $1,600 2025-01-09
Redcap MEDIUM 5.4
CVE-2024-56376

A stored cross-site scripting (XSS) vulnerability in the built-in messenger of REDCap 14.9.6 allows authenticated users to inject malicious scripts i…

No fix yet
Fix from $1,600 2025-01-09
Redcap MEDIUM 5.4
CVE-2024-56313

A stored cross-site scripting (XSS) vulnerability in the Calendar feature of REDCap through 14.9.6 allows authenticated users to inject malicious scr…

Fix: after 14.9.6
Fix from $1,600 2024-12-22
Redcap MEDIUM 5.4
CVE-2024-56314

A stored cross-site scripting (XSS) vulnerability in the Project name of REDCap through 14.9.6 allows authenticated users to inject malicious scripts…

Fix: after 14.9.6
Fix from $1,600 2024-12-22
Redcap MEDIUM 5.4
CVE-2024-56312

A stored cross-site scripting (XSS) vulnerability in the Project Dashboard name of REDCap through 14.9.6 allows authenticated users to inject malicio…

Fix: after 14.9.6
Fix from $1,600 2024-12-22
Redcap HIGH 8.8
CVE-2024-56310

REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack. An attacker c…

Fix: after 14.9.6
Fix from $1,950 2024-12-22
Redcap HIGH 8.8
CVE-2024-56311

REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attack. An a…

Fix: after 14.9.6
Fix from $1,950 2024-12-22
Redcap MEDIUM 6.1
CVE-2024-45527

REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and…

No fix yet
Fix from $1,600 2024-09-02
Redcap MEDIUM 6.5
CVE-2023-38825

SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password reset mech…

Fix: 13.8.0+
Fix from $1,600 2024-03-21
Redcap MEDIUM 5.4
CVE-2023-37798

A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 allows attackers to execut…

Fix: after 13.1.35
Fix from $1,600 2023-09-07
Redcap MEDIUM 6.1
CVE-2022-42715

A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV file will, when uploaded, …

Fix: 12.4.18 / 12.5.11+
Fix from $1,600 2022-10-12
Redcap MEDIUM 5.4
CVE-2022-24004

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11. This issue allows any authenticat…

No fix yet
Fix from $1,600 2022-06-15
Redcap MEDIUM 5.4
CVE-2022-24127

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11. This issue allows any…

No fix yet
Fix from $1,600 2022-06-15
Redcap CRITICAL 9.0
CVE-2021-42136

A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to execute …

Fix: 11.4.0+
Fix from $2,300 2022-04-13
Redcap CRITICAL 9.8
CVE-2020-26712

REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of in…

No fix yet
Fix from $2,300 2021-01-12
Redcap MEDIUM 6.1
CVE-2020-26713

REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the user is immediately returne…

No fix yet
Fix from $1,600 2021-01-12
Redcap MEDIUM 5.4
CVE-2019-17121

REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.

Fix: 9.3.4+
Fix from $1,600 2019-10-04
Redcap MEDIUM 5.4
CVE-2019-15127

REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.

Fix: 9.3.0+
Fix from $1,600 2019-08-21
Redcap HIGH 7.5
CVE-2019-14937

REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/c…

Fix: 9.3.0+
Fix from $1,950 2019-08-17
Redcap HIGH 8.8
CVE-2017-7351

A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.

Fix: 7.0.11+
Fix from $1,950 2018-02-08
Redcap HIGH 8.8
CVE-2017-10961

REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.

Fix: after 7.5.0
Fix from $1,950 2017-07-18
Redcap MEDIUM 6.1
CVE-2017-10962

REDCap before 7.5.1 has XSS via the query string.

Fix: after 7.5.0
Fix from $1,600 2017-07-18