Skip to content
Noroxi

openmicroscopy records

18 published records for vendor openmicroscopy.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
50%
Median publish → KEV
No record has entered KEV

All records

18 records
  • OMERO.server before 5.6.1 allows attackers to bypass the security filters and access hidden objects via a crafted query.

    CriticalCVSS 9.8No exploitEPSS 1%

    openmicroscopy · omero.serverJul 22, 2020

  • CVE-2014-7198
    35Monitor

    OMERO before 5.0.6 has multiple CSRF vulnerabilities because the framework for OMERO's web interface lacks CSRF protection.

    HighCVSS 8.8No exploitEPSS 1%

    openmicroscopy · omeroMar 31, 2019

  • In OMERO 5.3.3 or earlier a user could create an OriginalFile and adjust its path such that it now points to another user's file on the unde

    HighCVSS 8.3No exploitEPSS 1%

    openmicroscopy · omeroJan 2, 2018

  • CVE-2019-9944
    30Monitor

    In Open Microscopy Environment OMERO.server 5.0.0 through 5.6.0, the reading of files from imported image filesets may circumvent OMERO perm

    HighCVSS 7.5No exploitEPSS 1%

    openmicroscopy · omero.serverJun 17, 2020

  • CVE-2019-9943
    30Monitor

    In ome.services.graphs.GraphTraversal.findObjectDetails in Open Microscopy Environment OMERO.server 5.1.0 through 5.6.0, permissions on OMER

    HighCVSS 7.5No exploitEPSS 1%

    openmicroscopy · omero.serverJun 17, 2020

  • The Open Microscopy Environment OMERO.web version prior to 5.4.7 contains an Information Exposure Through Log Files vulnerability in the log

    HighCVSS 7.2No exploitEPSS 1%

    openmicroscopy · omeroAug 20, 2018

  • The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains an Improper Access Control vulnerability in User management tha

    HighCVSS 7.2No exploitEPSS 1%

    openmicroscopy · omeroAug 20, 2018

  • Bio-Formats <= 8.3.0 Memoizer Unsafe Deserialization via .bfmemo Cache Files

    MediumCVSS 6.8Proof of conceptEPSS 1%

    openmicroscopy · bio-formatsJan 7, 2026

  • Information Exposure in OMERO.web

    MediumCVSS 6.5No exploitEPSS 1%

    openmicroscopy · omero.webMar 23, 2021

  • The Open Microscopy Environment OMERO.server version 5.4.0 to 5.4.6 contains a Information Exposure Through Sent Data vulnerability in OMERO

    MediumCVSS 6.7No exploitEPSS 0%

    openmicroscopy · omeroAug 20, 2018

  • Inconsistent input sanitisation leads to XSS vectors

    MediumCVSS 6.1No exploitEPSS 1%

    openmicroscopy · omero-figureOct 14, 2021

  • OMERO.web JSONP callback vulnerability

    MediumCVSS 6.1No exploitEPSS 0%

    openmicroscopy · omero-webMay 21, 2024

  • CVE-2020-7932
    22Monitor

    OMERO.web before 5.6.3 optionally allows sensitive data elements (e.g., a session key) to be passed as URL query parameters.

    MediumCVSS 5.7No exploitEPSS 1%

    openmicroscopy · omero.webJun 17, 2020

  • OMERO before 5.6.1 makes the details of each user available to all users.

    MediumCVSS 5.3No exploitEPSS 1%

    openmicroscopy · omeroJun 17, 2020

  • Open Redirect in OMERO.web

    MediumCVSS 5.4No exploitEPSS 1%

    openmicroscopy · omero.webMar 23, 2021

  • OMERO.web displays unecessary user information when requesting to reset the password

    MediumCVSS 5.3No exploitEPSS 0%

    openmicroscopy · omero-webAug 13, 2025

  • Bio-Formats <= 8.3.0 XXE in Leica XLEF Metadata Parser

    MediumCVSS 4.6No exploitEPSS 0%

    openmicroscopy · bio-formatsJan 7, 2026

  • CVE-2020-6752
    15Monitor

    In OMERO before 5.6.1, group owners can access members' data in other groups.

    LowCVSS 3.8No exploitEPSS 1%

    openmicroscopy · omeroJun 17, 2020