İçeriğe atla
Noroxi

OpenMRS kayıtları

openmrs üreticisine ait 31 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %3,2
Pre-auth RCE
1
Düzeltme kaydı olan
%29
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

31 kayıt
  • CVE-2018-19276
    69Bu hafta

    OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitra

    KritikCVSS 9,8SilahlaştırılmışEPSS %99

    openmrs · openmrs21 Mar 2019

  • CVE-2017-12796
    40Planlayın

    The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenti

    KritikCVSS 9,8İstismar yokEPSS %4

    openmrs · openmrs23 Eki 2017

  • CVE-2017-12795
    40Planlayın

    OpenMRS openmrs-module-htmlformentry 3.3.2 is affected by: (Improper Input Validation).

    KritikCVSS 9,8İstismar yokEPSS %2

    openmrs · openmrs-module-htmlformentry10 May 2019

  • CVE-2018-16521
    40Planlayın

    An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.

    KritikCVSS 9,8İstismar yokEPSS %2

    openmrs · html form entry5 Eyl 2018

  • CVE-2021-43094
    39İzleyin

    An SQL Injection vulnerability exists in OpenMRS Reference Application Standalone Edition <=2.11 and Platform Standalone Edition <=2.4.0 via

    KritikCVSS 9,8İstismar yokEPSS %1

    openmrs · openmrs10 May 2022

  • CVE-2026-40076
    37İzleyin

    OpenMRS Core arbitrary file write and code execution via Zip Slip in module upload

    KritikCVSS 9,4İstismar yokEPSS %1

    openmrs · openmrs6 May 2026

  • CVE-2020-24621
    36İzleyin

    A remote code execution (RCE) vulnerability was discovered in the htmlformentry (aka HTML Form Entry) module before 3.11.0 for OpenMRS.

    YüksekCVSS 8,8İstismar yokEPSS %3

    openmrs · htmlformentry25 Eyl 2020

  • CVE-2017-7990
    35İzleyin

    The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert

    YüksekCVSS 8,8İstismar yokEPSS %1

    openmrs · openmrs module reporting20 Nis 2017

  • CVE-2026-40075
    32İzleyin

    OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet

    YüksekCVSS 8,2İstismar yokEPSS %1

    openmrs · openmrs5 May 2026

  • CVE-2025-25928
    32İzleyin

    A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitr

    YüksekCVSS 8,0İstismar yokEPSS %0

    openmrs · openmrs11 Mar 2025

  • CVE-2022-23612
    31İzleyin

    Directory Traversal in OpenMRS Startup Filter

    YüksekCVSS 7,5İstismar yokEPSS %2

    openmrs · openmrs22 Şub 2022

  • CVE-2014-8073
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in OpenMRS 2.1 Standalone Edition allows remote attackers to hijack the authentication of ad

    OrtaCVSS 6,8İstismar yokEPSS %1

    openmrs · openmrs23 Eki 2014

  • CVE-2025-25927
    27İzleyin

    A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted GET request

    OrtaCVSS 6,8İstismar yokEPSS %0

    openmrs · openmrs11 Mar 2025

  • CVE-2020-5732
    24İzleyin

    In OpenMRS 2.9 and prior, he import functionality of the Data Exchange Module does not properly redirect to a login page when an unauthentic

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · openmrs17 Nis 2020

  • CVE-2020-5733
    24İzleyin

    In OpenMRS 2.9 and prior, the export functionality of the Data Exchange Module does not properly redirect to a login page when an unauthenti

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · openmrs17 Nis 2020

  • CVE-2020-5731
    24İzleyin

    In OpenMRS 2.9 and prior, the app parameter for the ActiveVisit's page is vulnerable to cross-site scripting.

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · openmrs17 Nis 2020

  • CVE-2020-5730
    24İzleyin

    In OpenMRS 2.9 and prior, the sessionLocation parameter for the login page is vulnerable to cross-site scripting.

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · openmrs17 Nis 2020

  • CVE-2020-5729
    24İzleyin

    In OpenMRS 2.9 and prior, the UI Framework Error Page reflects arbitrary, user-supplied input back to the browser, which can result in XSS.

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · openmrs17 Nis 2020

  • CVE-2020-5728
    24İzleyin

    OpenMRS 2.9 and prior copies "Referrer" header values into an html element named "redirectUrl" within many webpages (such as login.htm).

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · openmrs17 Nis 2020

  • CVE-2021-4289
    24İzleyin

    OpenMRS openmrs-module-referenceapplication User App Page UserAppPageController.java post cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · reference application27 Ara 2022

  • CVE-2021-4284
    24İzleyin

    OpenMRS HTML Form Entry UI Framework Integration Module cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · htmlformentryui27 Ara 2022

  • CVE-2020-36636
    24İzleyin

    OpenMRS Admin UI Module Account Setup AccountPageController.java sendErrorMessage cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · admin ui module27 Ara 2022

  • CVE-2021-4288
    24İzleyin

    OpenMRS openmrs-module-referenceapplication userApp.gsp cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · reference application27 Ara 2022

  • CVE-2021-4292
    24İzleyin

    OpenMRS Admin UI Module Manage Privilege Page privilege.gsp cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · admin ui module27 Ara 2022

  • CVE-2021-4291
    24İzleyin

    OpenMRS Admin UI Module location.gsp cross site scripting

    OrtaCVSS 6,1İstismar yokEPSS %1

    openmrs · admin ui module27 Ara 2022