openmicroscopy records
18 published records for vendor openmicroscopy.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-209 Generation of Error Message Containing Sensitive Information1
- CWE-269 Improper Privilege Management1
- CWE-276 Incorrect Default Permissions1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-502 Deserialization of Untrusted Data1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2019-16244No exploit | OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.openmicroscopy · omero.server | Critical9.8 | — | 1.2% | Jul 22, 2020 |
35Monitor | CVE-2014-7198No exploit | OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.openmicroscopy · omero · CWE-352 | High8.8 | — | 0.6% | Mar 31, 2019 |
33Monitor | CVE-2017-1000438No exploit | In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the undeopenmicroscopy · omero | High8.3 | — | 0.9% | Jan 2, 2018 |
30Monitor | CVE-2019-9944No exploit | In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO permopenmicroscopy · omero.server | High7.5 | — | 1.1% | Jun 17, 2020 |
30Monitor | CVE-2019-9943No exploit | In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMERopenmicroscopy · omero.server · CWE-276 | High7.5 | — | 0.8% | Jun 17, 2020 |
28Monitor | CVE-2018-1000633No exploit | The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vulnerability in the logopenmicroscopy · omero · CWE-200 | High7.2 | — | 1.2% | Aug 20, 2018 |
28Monitor | CVE-2018-1000634No exploit | The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management thaopenmicroscopy · omero · CWE-269 | High7.2 | — | 1.0% | Aug 20, 2018 |
27Monitor | CVE-2026-22187Proof of concept | Bio-Formats <= 8.3.0 Memoizer Unsafe Deserialization via .bfmemo Cache Filesopenmicroscopy · bio-formats · CWE-502 | Medium6.8 | — | 0.5% | Jan 7, 2026 |
26Monitor | CVE-2021-21376No exploit | Information Exposure in OMERO.webopenmicroscopy · omero.web · CWE-200 | Medium6.5 | — | 1.5% | Mar 23, 2021 |
26Monitor | CVE-2018-1000635No exploit | The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains a Information Exposure Through Sent Data vulnerability in OMEROopenmicroscopy · omero · CWE-200 | Medium6.7 | — | 0.3% | Aug 20, 2018 |
24Monitor | CVE-2021-41132No exploit | Inconsistent input sanitisation leads to XSS vectorsopenmicroscopy · omero-figure · CWE-116 | Medium6.1 | — | 1.0% | Oct 14, 2021 |
24Monitor | CVE-2024-35180No exploit | OMERO.web JSONP callback vulnerabilityopenmicroscopy · omero-web · CWE-830 | Medium6.1 | — | 0.3% | May 21, 2024 |
22Monitor | CVE-2020-7932No exploit | OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters.openmicroscopy · omero.web · CWE-200 | Medium5.7 | — | 0.8% | Jun 17, 2020 |
21Monitor | CVE-2019-16245No exploit | OMERO before 5.6.1 makes the details of each user available to all users.openmicroscopy · omero | Medium5.3 | — | 0.9% | Jun 17, 2020 |
21Monitor | CVE-2021-21377No exploit | Open Redirect in OMERO.webopenmicroscopy · omero.web · CWE-601 | Medium5.4 | — | 0.8% | Mar 23, 2021 |
21Monitor | CVE-2025-54791No exploit | OMERO.web displays unecessary user information when requesting to reset the passwordopenmicroscopy · omero-web · CWE-209 | Medium5.3 | — | 0.3% | Aug 13, 2025 |
18Monitor | CVE-2026-22186No exploit | Bio-Formats <= 8.3.0 XXE in Leica XLEF Metadata Parseropenmicroscopy · bio-formats · CWE-611 | Medium4.6 | — | 0.2% | Jan 7, 2026 |
15Monitor | CVE-2020-6752No exploit | In OMERO before 5.6.1, group owners can access members' data in other groups.openmicroscopy · omero · CWE-863 | Low3.8 | — | 0.6% | Jun 17, 2020 |
- CVE-2019-1624439Monitor
OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.
CriticalCVSS 9.8No exploitEPSS 1%openmicroscopy · omero.serverJul 22, 2020
- CVE-2014-719835Monitor
OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.
HighCVSS 8.8No exploitEPSS 1%openmicroscopy · omeroMar 31, 2019
- CVE-2017-100043833Monitor
In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the unde
HighCVSS 8.3No exploitEPSS 1%openmicroscopy · omeroJan 2, 2018
- CVE-2019-994430Monitor
In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO perm
HighCVSS 7.5No exploitEPSS 1%openmicroscopy · omero.serverJun 17, 2020
- CVE-2019-994330Monitor
In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMER
HighCVSS 7.5No exploitEPSS 1%openmicroscopy · omero.serverJun 17, 2020
- CVE-2018-100063328Monitor
The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vulnerability in the log
HighCVSS 7.2No exploitEPSS 1%openmicroscopy · omeroAug 20, 2018
- CVE-2018-100063428Monitor
The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management tha
HighCVSS 7.2No exploitEPSS 1%openmicroscopy · omeroAug 20, 2018
- CVE-2026-2218727Monitor
Bio-Formats <= 8.3.0 Memoizer Unsafe Deserialization via .bfmemo Cache Files
MediumCVSS 6.8Proof of conceptEPSS 1%openmicroscopy · bio-formatsJan 7, 2026
- CVE-2021-2137626Monitor
Information Exposure in OMERO.web
MediumCVSS 6.5No exploitEPSS 1%openmicroscopy · omero.webMar 23, 2021
- CVE-2018-100063526Monitor
The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains a Information Exposure Through Sent Data vulnerability in OMERO
MediumCVSS 6.7No exploitEPSS 0%openmicroscopy · omeroAug 20, 2018
- CVE-2021-4113224Monitor
Inconsistent input sanitisation leads to XSS vectors
MediumCVSS 6.1No exploitEPSS 1%openmicroscopy · omero-figureOct 14, 2021
- CVE-2024-3518024Monitor
OMERO.web JSONP callback vulnerability
MediumCVSS 6.1No exploitEPSS 0%openmicroscopy · omero-webMay 21, 2024
- CVE-2020-793222Monitor
OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters.
MediumCVSS 5.7No exploitEPSS 1%openmicroscopy · omero.webJun 17, 2020
- CVE-2019-1624521Monitor
OMERO before 5.6.1 makes the details of each user available to all users.
MediumCVSS 5.3No exploitEPSS 1%openmicroscopy · omeroJun 17, 2020
- CVE-2021-2137721Monitor
Open Redirect in OMERO.web
MediumCVSS 5.4No exploitEPSS 1%openmicroscopy · omero.webMar 23, 2021
- CVE-2025-5479121Monitor
OMERO.web displays unecessary user information when requesting to reset the password
MediumCVSS 5.3No exploitEPSS 0%openmicroscopy · omero-webAug 13, 2025
- CVE-2026-2218618Monitor
Bio-Formats <= 8.3.0 XXE in Leica XLEF Metadata Parser
MediumCVSS 4.6No exploitEPSS 0%openmicroscopy · bio-formatsJan 7, 2026
- CVE-2020-675215Monitor
In OMERO before 5.6.1, group owners can access members' data in other groups.
LowCVSS 3.8No exploitEPSS 1%openmicroscopy · omeroJun 17, 2020