İçeriğe atla
Noroxi

Vanderbilt kayıtları

vanderbilt üreticisine ait 42 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%2,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

42 kayıt
  • CVE-2013-4611
    41Planlayın

    Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the O

    KritikCVSS 10,0İstismar yokEPSS %3

    project-redcap · redcap17 Haz 2013

  • CVE-2013-4610
    41Planlayın

    Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact an

    KritikCVSS 10,0İstismar yokEPSS %2

    project-redcap · redcap17 Haz 2013

  • CVE-2020-26712
    40Planlayın

    REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter.

    KritikCVSS 9,8İstismar yokEPSS %2

    vanderbilt · redcap12 Oca 2021

  • CVE-2014-6311
    40Planlayın

    generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to gain elevated p

    KritikCVSS 9,8İstismar yokEPSS %2

    vanderbilt · adaptive communication environment22 Kas 2019

  • CVE-2021-42136
    37İzleyin

    A stored Cross-Site Scripting (XSS) vulnerability in the Missing Data Codes functionality of REDCap before 11.4.0 allows remote attackers to

    KritikCVSS 9,0Kavram kanıtıEPSS %5

    vanderbilt · redcap13 Nis 2022

  • CVE-2017-7351
    35İzleyin

    A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.

    YüksekCVSS 8,8İstismar yokEPSS %1

    vanderbilt · redcap8 Şub 2018

  • CVE-2017-10961
    35İzleyin

    REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.

    YüksekCVSS 8,8İstismar yokEPSS %1

    vanderbilt · redcap18 Tem 2017

  • CVE-2024-56311
    35İzleyin

    REDCap through 14.9.6 has a security flaw in the Notes section of calendar events, exposing users to a Cross-Site Request Forgery (CSRF) att

    YüksekCVSS 8,8İstismar yokEPSS %0

    vanderbilt · redcap22 Ara 2024

  • CVE-2024-56310
    35İzleyin

    REDCap through 14.9.6 has a security flaw in the Project Dashboards name, exposing users to a Cross-Site Request Forgery (CSRF) attack.

    YüksekCVSS 8,8İstismar yokEPSS %0

    vanderbilt · redcap22 Ara 2024

  • CVE-2025-23113
    35İzleyin

    An issue was discovered in REDCap 14.9.6.

    YüksekCVSS 8,8İstismar yokEPSS %0

    vanderbilt · redcap10 Oca 2025

  • CVE-2019-14937
    30İzleyin

    REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to C

    YüksekCVSS 7,5İstismar yokEPSS %1

    vanderbilt · redcap17 Ağu 2019

  • CVE-2013-4609
    26İzleyin

    REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows

    OrtaCVSS 6,5İstismar yokEPSS %2

    project-redcap · redcap17 Haz 2013

  • CVE-2023-38825
    26İzleyin

    SQL injection vulnerability in Vanderbilt REDCap before v.13.8.0 allows a remote attacker to obtain sensitive information via the password r

    OrtaCVSS 6,5İstismar yokEPSS %1

    vanderbilt · redcap20 Mar 2024

  • CVE-2020-26713
    24İzleyin

    REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort.

    OrtaCVSS 6,1İstismar yokEPSS %1

    vanderbilt · redcap12 Oca 2021

  • CVE-2022-42715
    24İzleyin

    A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature.

    OrtaCVSS 6,1İstismar yokEPSS %1

    vanderbilt · redcap12 Eki 2022

  • CVE-2017-10962
    24İzleyin

    REDCap before 7.5.1 has XSS via the query string.

    OrtaCVSS 6,1İstismar yokEPSS %1

    vanderbilt · redcap18 Tem 2017

  • CVE-2025-23112
    24İzleyin

    An issue was discovered in REDCap 14.9.6.

    OrtaCVSS 6,1İstismar yokEPSS %0

    vanderbilt · redcap10 Oca 2025

  • CVE-2025-23110
    24İzleyin

    An issue was discovered in REDCap 14.9.6.

    OrtaCVSS 6,1İstismar yokEPSS %0

    vanderbilt · redcap10 Oca 2025

  • CVE-2025-23111
    24İzleyin

    An issue was discovered in REDCap 14.9.6.

    OrtaCVSS 6,1İstismar yokEPSS %0

    vanderbilt · redcap10 Oca 2025

  • CVE-2024-45527
    24İzleyin

    REDCap 14.7.0 allows HTML injection via the project title of a New Project action.

    OrtaCVSS 6,1İstismar yokEPSS %0

    vanderbilt · redcap2 Eyl 2024

  • CVE-2022-24127
    21İzleyin

    A Stored Cross-Site Scripting (XSS) vulnerability was discovered in ProjectGeneral/edit_project_settings.php in REDCap 12.0.11.

    OrtaCVSS 5,4İstismar yokEPSS %1

    vanderbilt · redcap15 Haz 2022

  • CVE-2022-24004
    21İzleyin

    A Stored Cross-Site Scripting (XSS) vulnerability was discovered in Messenger/messenger_ajax.php in REDCap 12.0.11.

    OrtaCVSS 5,4İstismar yokEPSS %1

    vanderbilt · redcap15 Haz 2022

  • CVE-2019-17121
    21İzleyin

    REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values.

    OrtaCVSS 5,4İstismar yokEPSS %1

    vanderbilt · redcap3 Eki 2019

  • CVE-2019-15127
    21İzleyin

    REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import file.

    OrtaCVSS 5,4İstismar yokEPSS %1

    vanderbilt · redcap21 Ağu 2019

  • CVE-2024-37394
    21İzleyin

    A stored cross-site scripting (XSS) vulnerability in the Project Dashboards of REDCap 13.1.9 allows authenticated users to execute arbitrary

    OrtaCVSS 5,4İstismar yokEPSS %0

    vanderbilt · redcap10 Haz 2025