Skip to content
Noroxi

Vanderbilt records

42 published records for vendor vanderbilt.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
2.4%
Median publish → KEV
No record has entered KEV

All records

42 records
  • Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the O

    CriticalCVSS 10.0No exploitEPSS 3%

    project-redcap · redcapJun 17, 2013

  • Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact an

    CriticalCVSS 10.0No exploitEPSS 2%

    project-redcap · redcapJun 17, 2013

  • REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter.

    CriticalCVSS 9.8No exploitEPSS 2%

    vanderbilt · redcapJan 12, 2021

  • generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated p

    CriticalCVSS 9.8No exploitEPSS 2%

    vanderbilt · adaptive communication environmentNov 22, 2019

  • A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to

    CriticalCVSS 9.0Proof of conceptEPSS 5%

    vanderbilt · redcapApr 13, 2022

  • CVE-2017-7351
    35Monitor

    A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.

    HighCVSS 8.8No exploitEPSS 1%

    vanderbilt · redcapFeb 8, 2018

  • REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.

    HighCVSS 8.8No exploitEPSS 1%

    vanderbilt · redcapJul 18, 2017

  • REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) att

    HighCVSS 8.8No exploitEPSS 0%

    vanderbilt · redcapDec 22, 2024

  • REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack.

    HighCVSS 8.8No exploitEPSS 0%

    vanderbilt · redcapDec 22, 2024

  • An issue was discovered in REDCap 14.9.6.

    HighCVSS 8.8No exploitEPSS 0%

    vanderbilt · redcapJan 10, 2025

  • REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to C

    HighCVSS 7.5No exploitEPSS 1%

    vanderbilt · redcapAug 17, 2019

  • CVE-2013-4609
    26Monitor

    REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows

    MediumCVSS 6.5No exploitEPSS 2%

    project-redcap · redcapJun 17, 2013

  • SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password r

    MediumCVSS 6.5No exploitEPSS 1%

    vanderbilt · redcapMar 20, 2024

  • REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort.

    MediumCVSS 6.1No exploitEPSS 1%

    vanderbilt · redcapJan 12, 2021

  • A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature.

    MediumCVSS 6.1No exploitEPSS 1%

    vanderbilt · redcapOct 12, 2022

  • REDCap before 7.5.1 has XSS via the query string.

    MediumCVSS 6.1No exploitEPSS 1%

    vanderbilt · redcapJul 18, 2017

  • An issue was discovered in REDCap 14.9.6.

    MediumCVSS 6.1No exploitEPSS 0%

    vanderbilt · redcapJan 10, 2025

  • An issue was discovered in REDCap 14.9.6.

    MediumCVSS 6.1No exploitEPSS 0%

    vanderbilt · redcapJan 10, 2025

  • An issue was discovered in REDCap 14.9.6.

    MediumCVSS 6.1No exploitEPSS 0%

    vanderbilt · redcapJan 10, 2025

  • REDCap 14.7.0 allows HTML injection via the project title of a New Project action.

    MediumCVSS 6.1No exploitEPSS 0%

    vanderbilt · redcapSep 2, 2024

  • A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11.

    MediumCVSS 5.4No exploitEPSS 1%

    vanderbilt · redcapJun 15, 2022

  • A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11.

    MediumCVSS 5.4No exploitEPSS 1%

    vanderbilt · redcapJun 15, 2022

  • REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.

    MediumCVSS 5.4No exploitEPSS 1%

    vanderbilt · redcapOct 3, 2019

  • REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.

    MediumCVSS 5.4No exploitEPSS 1%

    vanderbilt · redcapAug 21, 2019

  • A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary

    MediumCVSS 5.4No exploitEPSS 0%

    vanderbilt · redcapJun 10, 2025