Vanderbilt kayıtları
vanderbilt üreticisine ait 42 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %2,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')26
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-203 Observable Discrepancy1
- CWE-330 Use of Insufficiently Random Values1
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
42 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2013-4611İstismar yok | Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the Oproject-redcap · redcap | Kritik10,0 | — | %2,9 | 17 Haz 2013 |
41Planlayın | CVE-2013-4610İstismar yok | Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact anproject-redcap · redcap | Kritik10,0 | — | %1,7 | 17 Haz 2013 |
40Planlayın | CVE-2020-26712İstismar yok | REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter.vanderbilt · redcap · CWE-89 | Kritik9,8 | — | %2,1 | 12 Oca 2021 |
40Planlayın | CVE-2014-6311İstismar yok | generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated pvanderbilt · adaptive communication environment · CWE-330 | Kritik9,8 | — | %1,7 | 22 Kas 2019 |
37İzleyin | CVE-2021-42136Kavram kanıtı | A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers tovanderbilt · redcap · CWE-79 | Kritik9,0 | — | %4,7 | 13 Nis 2022 |
35İzleyin | CVE-2017-7351İstismar yok | A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.vanderbilt · redcap · CWE-89 | Yüksek8,8 | — | %1,2 | 8 Şub 2018 |
35İzleyin | CVE-2017-10961İstismar yok | REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.vanderbilt · redcap · CWE-352 | Yüksek8,8 | — | %0,6 | 18 Tem 2017 |
35İzleyin | CVE-2024-56311İstismar yok | REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) attvanderbilt · redcap · CWE-352 | Yüksek8,8 | — | %0,3 | 22 Ara 2024 |
35İzleyin | CVE-2024-56310İstismar yok | REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack.vanderbilt · redcap · CWE-352 | Yüksek8,8 | — | %0,3 | 22 Ara 2024 |
35İzleyin | CVE-2025-23113İstismar yok | An issue was discovered in REDCap 14.9.6.vanderbilt · redcap · CWE-352 | Yüksek8,8 | — | %0,2 | 10 Oca 2025 |
30İzleyin | CVE-2019-14937İstismar yok | REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Cvanderbilt · redcap · CWE-89 | Yüksek7,5 | — | %1,4 | 17 Ağu 2019 |
26İzleyin | CVE-2013-4609İstismar yok | REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allowsproject-redcap · redcap · CWE-264 | Orta6,5 | — | %1,5 | 17 Haz 2013 |
26İzleyin | CVE-2023-38825İstismar yok | SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password rvanderbilt · redcap · CWE-89 | Orta6,5 | — | %1,0 | 20 Mar 2024 |
24İzleyin | CVE-2020-26713İstismar yok | REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort.vanderbilt · redcap · CWE-79 | Orta6,1 | — | %1,2 | 12 Oca 2021 |
24İzleyin | CVE-2022-42715İstismar yok | A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature.vanderbilt · redcap · CWE-79 | Orta6,1 | — | %0,8 | 12 Eki 2022 |
24İzleyin | CVE-2017-10962İstismar yok | REDCap before 7.5.1 has XSS via the query string.vanderbilt · redcap · CWE-79 | Orta6,1 | — | %0,6 | 18 Tem 2017 |
24İzleyin | CVE-2025-23112İstismar yok | An issue was discovered in REDCap 14.9.6.vanderbilt · redcap · CWE-79 | Orta6,1 | — | %0,3 | 10 Oca 2025 |
24İzleyin | CVE-2025-23110İstismar yok | An issue was discovered in REDCap 14.9.6.vanderbilt · redcap · CWE-79 | Orta6,1 | — | %0,3 | 10 Oca 2025 |
24İzleyin | CVE-2025-23111İstismar yok | An issue was discovered in REDCap 14.9.6.vanderbilt · redcap · CWE-79 | Orta6,1 | — | %0,3 | 10 Oca 2025 |
24İzleyin | CVE-2024-45527İstismar yok | REDCap 14.7.0 allows HTML injection via the project title of a New Project action.vanderbilt · redcap · CWE-352 | Orta6,1 | — | %0,2 | 2 Eyl 2024 |
21İzleyin | CVE-2022-24127İstismar yok | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11.vanderbilt · redcap · CWE-79 | Orta5,4 | — | %0,7 | 15 Haz 2022 |
21İzleyin | CVE-2022-24004İstismar yok | A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11.vanderbilt · redcap · CWE-79 | Orta5,4 | — | %0,7 | 15 Haz 2022 |
21İzleyin | CVE-2019-17121İstismar yok | REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.vanderbilt · redcap · CWE-79 | Orta5,4 | — | %0,6 | 3 Eki 2019 |
21İzleyin | CVE-2019-15127İstismar yok | REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.vanderbilt · redcap · CWE-79 | Orta5,4 | — | %0,5 | 21 Ağu 2019 |
21İzleyin | CVE-2024-37394İstismar yok | A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitraryvanderbilt · redcap · CWE-79 | Orta5,4 | — | %0,5 | 10 Haz 2025 |
- CVE-2013-461141Planlayın
Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the O
KritikCVSS 10,0İstismar yokEPSS %3project-redcap · redcap17 Haz 2013
- CVE-2013-461041Planlayın
Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact an
KritikCVSS 10,0İstismar yokEPSS %2project-redcap · redcap17 Haz 2013
- CVE-2020-2671240Planlayın
REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter.
KritikCVSS 9,8İstismar yokEPSS %2vanderbilt · redcap12 Oca 2021
- CVE-2014-631140Planlayın
generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated p
KritikCVSS 9,8İstismar yokEPSS %2vanderbilt · adaptive communication environment22 Kas 2019
- CVE-2021-4213637İzleyin
A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to
KritikCVSS 9,0Kavram kanıtıEPSS %5vanderbilt · redcap13 Nis 2022
- CVE-2017-735135İzleyin
A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.
YüksekCVSS 8,8İstismar yokEPSS %1vanderbilt · redcap8 Şub 2018
- CVE-2017-1096135İzleyin
REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.
YüksekCVSS 8,8İstismar yokEPSS %1vanderbilt · redcap18 Tem 2017
- CVE-2024-5631135İzleyin
REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) att
YüksekCVSS 8,8İstismar yokEPSS %0vanderbilt · redcap22 Ara 2024
- CVE-2024-5631035İzleyin
REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack.
YüksekCVSS 8,8İstismar yokEPSS %0vanderbilt · redcap22 Ara 2024
- CVE-2025-2311335İzleyin
An issue was discovered in REDCap 14.9.6.
YüksekCVSS 8,8İstismar yokEPSS %0vanderbilt · redcap10 Oca 2025
- CVE-2019-1493730İzleyin
REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to C
YüksekCVSS 7,5İstismar yokEPSS %1vanderbilt · redcap17 Ağu 2019
- CVE-2013-460926İzleyin
REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows
OrtaCVSS 6,5İstismar yokEPSS %2project-redcap · redcap17 Haz 2013
- CVE-2023-3882526İzleyin
SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password r
OrtaCVSS 6,5İstismar yokEPSS %1vanderbilt · redcap20 Mar 2024
- CVE-2020-2671324İzleyin
REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort.
OrtaCVSS 6,1İstismar yokEPSS %1vanderbilt · redcap12 Oca 2021
- CVE-2022-4271524İzleyin
A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature.
OrtaCVSS 6,1İstismar yokEPSS %1vanderbilt · redcap12 Eki 2022
- CVE-2017-1096224İzleyin
REDCap before 7.5.1 has XSS via the query string.
OrtaCVSS 6,1İstismar yokEPSS %1vanderbilt · redcap18 Tem 2017
- CVE-2025-2311224İzleyin
An issue was discovered in REDCap 14.9.6.
OrtaCVSS 6,1İstismar yokEPSS %0vanderbilt · redcap10 Oca 2025
- CVE-2025-2311024İzleyin
An issue was discovered in REDCap 14.9.6.
OrtaCVSS 6,1İstismar yokEPSS %0vanderbilt · redcap10 Oca 2025
- CVE-2025-2311124İzleyin
An issue was discovered in REDCap 14.9.6.
OrtaCVSS 6,1İstismar yokEPSS %0vanderbilt · redcap10 Oca 2025
- CVE-2024-4552724İzleyin
REDCap 14.7.0 allows HTML injection via the project title of a New Project action.
OrtaCVSS 6,1İstismar yokEPSS %0vanderbilt · redcap2 Eyl 2024
- CVE-2022-2412721İzleyin
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11.
OrtaCVSS 5,4İstismar yokEPSS %1vanderbilt · redcap15 Haz 2022
- CVE-2022-2400421İzleyin
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11.
OrtaCVSS 5,4İstismar yokEPSS %1vanderbilt · redcap15 Haz 2022
- CVE-2019-1712121İzleyin
REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.
OrtaCVSS 5,4İstismar yokEPSS %1vanderbilt · redcap3 Eki 2019
- CVE-2019-1512721İzleyin
REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.
OrtaCVSS 5,4İstismar yokEPSS %1vanderbilt · redcap21 Ağu 2019
- CVE-2024-3739421İzleyin
A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary
OrtaCVSS 5,4İstismar yokEPSS %0vanderbilt · redcap10 Haz 2025