Перейти к содержимому
Noroxi

Записи OpenMRS

31 опубликованных записей вендора openmrs.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
1 · 3,2 %
Pre-auth RCE
1
С записью об исправлении
29 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

31 записей
  • CVE-2018-19276
    69На этой неделе

    OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitra

    КритическаяCVSS 9,8Готовый эксплойтEPSS 99 %

    openmrs · openmrs21 мар. 2019 г.

  • CVE-2017-12796
    40В плане

    The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenti

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    openmrs · openmrs23 окт. 2017 г.

  • CVE-2017-12795
    40В плане

    OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    openmrs · openmrs-module-htmlformentry10 мая 2019 г.

  • CVE-2018-16521
    40В плане

    An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    openmrs · html form entry5 сент. 2018 г.

  • CVE-2021-43094
    39Наблюдать

    An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    openmrs · openmrs10 мая 2022 г.

  • CVE-2026-40076
    37Наблюдать

    OpenMRS Core arbitrary file write and code execution via Zip Slip in module upload

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    openmrs · openmrs6 мая 2026 г.

  • CVE-2020-24621
    36Наблюдать

    A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    openmrs · htmlformentry25 сент. 2020 г.

  • CVE-2017-7990
    35Наблюдать

    The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    openmrs · openmrs module reporting20 апр. 2017 г.

  • CVE-2026-40075
    32Наблюдать

    OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet

    ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %

    openmrs · openmrs5 мая 2026 г.

  • CVE-2025-25928
    32Наблюдать

    A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitr

    ВысокаяCVSS 8,0Эксплойта нетEPSS 0 %

    openmrs · openmrs11 мар. 2025 г.

  • CVE-2022-23612
    31Наблюдать

    Directory Traversal in OpenMRS Startup Filter

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    openmrs · openmrs22 февр. 2022 г.

  • CVE-2014-8073
    27Наблюдать

    Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the authentication of ad

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    openmrs · openmrs23 окт. 2014 г.

  • CVE-2025-25927
    27Наблюдать

    A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    openmrs · openmrs11 мар. 2025 г.

  • CVE-2020-5732
    24Наблюдать

    In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthentic

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · openmrs17 апр. 2020 г.

  • CVE-2020-5733
    24Наблюдать

    In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenti

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · openmrs17 апр. 2020 г.

  • CVE-2020-5731
    24Наблюдать

    In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · openmrs17 апр. 2020 г.

  • CVE-2020-5730
    24Наблюдать

    In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · openmrs17 апр. 2020 г.

  • CVE-2020-5729
    24Наблюдать

    In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · openmrs17 апр. 2020 г.

  • CVE-2020-5728
    24Наблюдать

    OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm).

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · openmrs17 апр. 2020 г.

  • CVE-2021-4289
    24Наблюдать

    OpenMRS openmrs-module-referenceapplication User App Page UserAppPageController.java post cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · reference application27 дек. 2022 г.

  • CVE-2021-4284
    24Наблюдать

    OpenMRS HTML Form Entry UI Framework Integration Module cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · htmlformentryui27 дек. 2022 г.

  • CVE-2020-36636
    24Наблюдать

    OpenMRS Admin UI Module Account Setup AccountPageController.java sendErrorMessage cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · admin ui module27 дек. 2022 г.

  • CVE-2022-4727
    24Наблюдать

    OpenMRS Appointment Scheduling Module Notes AppointmentRequest.java getNotes cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · appointment scheduling module27 дек. 2022 г.

  • CVE-2021-4288
    24Наблюдать

    OpenMRS openmrs-module-referenceapplication userApp.gsp cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · reference application27 дек. 2022 г.

  • CVE-2021-4291
    24Наблюдать

    OpenMRS Admin UI Module location.gsp cross site scripting

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    openmrs · admin ui module27 дек. 2022 г.