Vanderbilt records
42 published records for vendor vanderbilt.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 2.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')26
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-203 Observable Discrepancy1
- CWE-330 Use of Insufficiently Random Values1
- CWE-264 Permissions, Privileges, and Access Controls1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
42 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2013-4611No exploit | Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the Oproject-redcap · redcap | Critical10.0 | — | 2.9% | Jun 17, 2013 |
41Plan | CVE-2013-4610No exploit | Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact anproject-redcap · redcap | Critical10.0 | — | 1.7% | Jun 17, 2013 |
40Plan | CVE-2020-26712No exploit | REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter.vanderbilt · redcap · CWE-89 | Critical9.8 | — | 2.1% | Jan 12, 2021 |
40Plan | CVE-2014-6311No exploit | generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated pvanderbilt · adaptive communication environment · CWE-330 | Critical9.8 | — | 1.7% | Nov 22, 2019 |
37Monitor | CVE-2021-42136Proof of concept | A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers tovanderbilt · redcap · CWE-79 | Critical9.0 | — | 4.7% | Apr 13, 2022 |
35Monitor | CVE-2017-7351No exploit | A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.vanderbilt · redcap · CWE-89 | High8.8 | — | 1.2% | Feb 8, 2018 |
35Monitor | CVE-2017-10961No exploit | REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.vanderbilt · redcap · CWE-352 | High8.8 | — | 0.6% | Jul 18, 2017 |
35Monitor | CVE-2024-56311No exploit | REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attvanderbilt · redcap · CWE-352 | High8.8 | — | 0.3% | Dec 22, 2024 |
35Monitor | CVE-2024-56310No exploit | REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack.vanderbilt · redcap · CWE-352 | High8.8 | — | 0.3% | Dec 22, 2024 |
35Monitor | CVE-2025-23113No exploit | An issue was discovered in REDCap 14.9.6.vanderbilt · redcap · CWE-352 | High8.8 | — | 0.2% | Jan 10, 2025 |
30Monitor | CVE-2019-14937No exploit | REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Cvanderbilt · redcap · CWE-89 | High7.5 | — | 1.4% | Aug 17, 2019 |
26Monitor | CVE-2013-4609No exploit | REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allowsproject-redcap · redcap · CWE-264 | Medium6.5 | — | 1.5% | Jun 17, 2013 |
26Monitor | CVE-2023-38825No exploit | SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password rvanderbilt · redcap · CWE-89 | Medium6.5 | — | 1.0% | Mar 20, 2024 |
24Monitor | CVE-2020-26713No exploit | REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort.vanderbilt · redcap · CWE-79 | Medium6.1 | — | 1.2% | Jan 12, 2021 |
24Monitor | CVE-2022-42715No exploit | A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature.vanderbilt · redcap · CWE-79 | Medium6.1 | — | 0.8% | Oct 12, 2022 |
24Monitor | CVE-2017-10962No exploit | REDCap before 7.5.1 has XSS via the query string.vanderbilt · redcap · CWE-79 | Medium6.1 | — | 0.6% | Jul 18, 2017 |
24Monitor | CVE-2025-23112No exploit | An issue was discovered in REDCap 14.9.6.vanderbilt · redcap · CWE-79 | Medium6.1 | — | 0.3% | Jan 10, 2025 |
24Monitor | CVE-2025-23110No exploit | An issue was discovered in REDCap 14.9.6.vanderbilt · redcap · CWE-79 | Medium6.1 | — | 0.3% | Jan 10, 2025 |
24Monitor | CVE-2025-23111No exploit | An issue was discovered in REDCap 14.9.6.vanderbilt · redcap · CWE-79 | Medium6.1 | — | 0.3% | Jan 10, 2025 |
24Monitor | CVE-2024-45527No exploit | REDCap 14.7.0 allows HTML injection via the project title of a New Project action.vanderbilt · redcap · CWE-352 | Medium6.1 | — | 0.2% | Sep 2, 2024 |
21Monitor | CVE-2022-24127No exploit | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11.vanderbilt · redcap · CWE-79 | Medium5.4 | — | 0.7% | Jun 15, 2022 |
21Monitor | CVE-2022-24004No exploit | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11.vanderbilt · redcap · CWE-79 | Medium5.4 | — | 0.7% | Jun 15, 2022 |
21Monitor | CVE-2019-17121No exploit | REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.vanderbilt · redcap · CWE-79 | Medium5.4 | — | 0.6% | Oct 3, 2019 |
21Monitor | CVE-2019-15127No exploit | REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.vanderbilt · redcap · CWE-79 | Medium5.4 | — | 0.5% | Aug 21, 2019 |
21Monitor | CVE-2024-37394No exploit | A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitraryvanderbilt · redcap · CWE-79 | Medium5.4 | — | 0.5% | Jun 10, 2025 |
- CVE-2013-461141Plan
Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the O
CriticalCVSS 10.0No exploitEPSS 3%project-redcap · redcapJun 17, 2013
- CVE-2013-461041Plan
Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact an
CriticalCVSS 10.0No exploitEPSS 2%project-redcap · redcapJun 17, 2013
- CVE-2020-2671240Plan
REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter.
CriticalCVSS 9.8No exploitEPSS 2%vanderbilt · redcapJan 12, 2021
- CVE-2014-631140Plan
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated p
CriticalCVSS 9.8No exploitEPSS 2%vanderbilt · adaptive communication environmentNov 22, 2019
- CVE-2021-4213637Monitor
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to
CriticalCVSS 9.0Proof of conceptEPSS 5%vanderbilt · redcapApr 13, 2022
- CVE-2017-735135Monitor
A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.
HighCVSS 8.8No exploitEPSS 1%vanderbilt · redcapFeb 8, 2018
- CVE-2017-1096135Monitor
REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.
HighCVSS 8.8No exploitEPSS 1%vanderbilt · redcapJul 18, 2017
- CVE-2024-5631135Monitor
REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) att
HighCVSS 8.8No exploitEPSS 0%vanderbilt · redcapDec 22, 2024
- CVE-2024-5631035Monitor
REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack.
HighCVSS 8.8No exploitEPSS 0%vanderbilt · redcapDec 22, 2024
- CVE-2025-2311335Monitor
An issue was discovered in REDCap 14.9.6.
HighCVSS 8.8No exploitEPSS 0%vanderbilt · redcapJan 10, 2025
- CVE-2019-1493730Monitor
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to C
HighCVSS 7.5No exploitEPSS 1%vanderbilt · redcapAug 17, 2019
- CVE-2013-460926Monitor
REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows
MediumCVSS 6.5No exploitEPSS 2%project-redcap · redcapJun 17, 2013
- CVE-2023-3882526Monitor
SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password r
MediumCVSS 6.5No exploitEPSS 1%vanderbilt · redcapMar 20, 2024
- CVE-2020-2671324Monitor
REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort.
MediumCVSS 6.1No exploitEPSS 1%vanderbilt · redcapJan 12, 2021
- CVE-2022-4271524Monitor
A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature.
MediumCVSS 6.1No exploitEPSS 1%vanderbilt · redcapOct 12, 2022
- CVE-2017-1096224Monitor
REDCap before 7.5.1 has XSS via the query string.
MediumCVSS 6.1No exploitEPSS 1%vanderbilt · redcapJul 18, 2017
- CVE-2025-2311224Monitor
An issue was discovered in REDCap 14.9.6.
MediumCVSS 6.1No exploitEPSS 0%vanderbilt · redcapJan 10, 2025
- CVE-2025-2311024Monitor
An issue was discovered in REDCap 14.9.6.
MediumCVSS 6.1No exploitEPSS 0%vanderbilt · redcapJan 10, 2025
- CVE-2025-2311124Monitor
An issue was discovered in REDCap 14.9.6.
MediumCVSS 6.1No exploitEPSS 0%vanderbilt · redcapJan 10, 2025
- CVE-2024-4552724Monitor
REDCap 14.7.0 allows HTML injection via the project title of a New Project action.
MediumCVSS 6.1No exploitEPSS 0%vanderbilt · redcapSep 2, 2024
- CVE-2022-2412721Monitor
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11.
MediumCVSS 5.4No exploitEPSS 1%vanderbilt · redcapJun 15, 2022
- CVE-2022-2400421Monitor
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11.
MediumCVSS 5.4No exploitEPSS 1%vanderbilt · redcapJun 15, 2022
- CVE-2019-1712121Monitor
REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.
MediumCVSS 5.4No exploitEPSS 1%vanderbilt · redcapOct 3, 2019
- CVE-2019-1512721Monitor
REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.
MediumCVSS 5.4No exploitEPSS 1%vanderbilt · redcapAug 21, 2019
- CVE-2024-3739421Monitor
A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary
MediumCVSS 5.4No exploitEPSS 0%vanderbilt · redcapJun 10, 2025