Перейти к содержимому
Noroxi

Записи Vanderbilt

42 опубликованных записей вендора vanderbilt.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
0
С записью об исправлении
2,4 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 17
  2. 18
  3. 19
  4. 20
  5. 21
  6. 22
  7. 23
  8. 24
  9. 25
  10. 26

Столбик: всего · тёмная часть: CISA KEV.

Все записи

42 записей
  • CVE-2013-4611
    41В плане

    Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the O

    КритическаяCVSS 10,0Эксплойта нетEPSS 3 %

    project-redcap · redcap17 июн. 2013 г.

  • CVE-2013-4610
    41В плане

    Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact an

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    project-redcap · redcap17 июн. 2013 г.

  • CVE-2020-26712
    40В плане

    REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    vanderbilt · redcap12 янв. 2021 г.

  • CVE-2014-6311
    40В плане

    generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated p

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    vanderbilt · adaptive communication environment22 нояб. 2019 г.

  • CVE-2021-42136
    37Наблюдать

    A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to

    КритическаяCVSS 9,0Proof of conceptEPSS 5 %

    vanderbilt · redcap13 апр. 2022 г.

  • CVE-2017-7351
    35Наблюдать

    A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    vanderbilt · redcap8 февр. 2018 г.

  • CVE-2017-10961
    35Наблюдать

    REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    vanderbilt · redcap18 июл. 2017 г.

  • CVE-2024-56311
    35Наблюдать

    REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) att

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    vanderbilt · redcap22 дек. 2024 г.

  • CVE-2024-56310
    35Наблюдать

    REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    vanderbilt · redcap22 дек. 2024 г.

  • CVE-2025-23113
    35Наблюдать

    An issue was discovered in REDCap 14.9.6.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    vanderbilt · redcap10 янв. 2025 г.

  • CVE-2019-14937
    30Наблюдать

    REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to C

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    vanderbilt · redcap17 авг. 2019 г.

  • CVE-2013-4609
    26Наблюдать

    REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    project-redcap · redcap17 июн. 2013 г.

  • CVE-2023-38825
    26Наблюдать

    SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password r

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    vanderbilt · redcap20 мар. 2024 г.

  • CVE-2020-26713
    24Наблюдать

    REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    vanderbilt · redcap12 янв. 2021 г.

  • CVE-2022-42715
    24Наблюдать

    A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    vanderbilt · redcap12 окт. 2022 г.

  • CVE-2017-10962
    24Наблюдать

    REDCap before 7.5.1 has XSS via the query string.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    vanderbilt · redcap18 июл. 2017 г.

  • CVE-2025-23112
    24Наблюдать

    An issue was discovered in REDCap 14.9.6.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    vanderbilt · redcap10 янв. 2025 г.

  • CVE-2025-23110
    24Наблюдать

    An issue was discovered in REDCap 14.9.6.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    vanderbilt · redcap10 янв. 2025 г.

  • CVE-2025-23111
    24Наблюдать

    An issue was discovered in REDCap 14.9.6.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    vanderbilt · redcap10 янв. 2025 г.

  • CVE-2024-45527
    24Наблюдать

    REDCap 14.7.0 allows HTML injection via the project title of a New Project action.

    СредняяCVSS 6,1Эксплойта нетEPSS 0 %

    vanderbilt · redcap2 сент. 2024 г.

  • CVE-2022-24127
    21Наблюдать

    A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    vanderbilt · redcap15 июн. 2022 г.

  • CVE-2022-24004
    21Наблюдать

    A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    vanderbilt · redcap15 июн. 2022 г.

  • CVE-2019-17121
    21Наблюдать

    REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    vanderbilt · redcap3 окт. 2019 г.

  • CVE-2019-15127
    21Наблюдать

    REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    vanderbilt · redcap21 авг. 2019 г.

  • CVE-2024-37394
    21Наблюдать

    A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    vanderbilt · redcap10 июн. 2025 г.