Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vanderbilt redcap vulnerabilities and exploits
(subscribe to this query)
890
VMScore
CVE-2020-26712
REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the addition of a string of information from the submitted user that is not validated well in the database query, resulting in an SQL injection vulnerability whe...
Vanderbilt Redcap 10.3.4
Vanderbilt Redcap 10.0.20
890
VMScore
CVE-2013-4610
Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap prior to 5.0.3 and 5.1.x prior to 5.1.2 has unknown impact and remote attack vectors.
Project-redcap Redcap 5.1.0
Project-redcap Redcap 5.1.1
Project-redcap Redcap 4.15.4
Project-redcap Redcap 4.15.2
Project-redcap Redcap 4.14.6
Project-redcap Redcap 4.14.5
Project-redcap Redcap 5.0.1
Project-redcap Redcap 5.0.6
Project-redcap Redcap 4.13.18
Project-redcap Redcap 4.15.3
Project-redcap Redcap 4.15.1
Project-redcap Redcap 4.15.0
Project-redcap Redcap 5.0.0
Vanderbilt Redcap 4.14.4
Vanderbilt Redcap
Vanderbilt Redcap 4.14.3
Vanderbilt Redcap 4.14.0
Vanderbilt Redcap 4.14.2
Vanderbilt Redcap 4.14.1
890
VMScore
CVE-2013-4611
Multiple unspecified vulnerabilities in REDCap prior to 5.1.1 allow remote malicious users to have an unknown impact via vectors involving (1) the Online Designer page or (2) the Manage Survey Participants page.
Project-redcap Redcap 5.0.5
Project-redcap Redcap 4.15.4
Project-redcap Redcap 4.15.2
Project-redcap Redcap 4.14.6
Project-redcap Redcap 5.0.3
Project-redcap Redcap 4.14.5
Project-redcap Redcap 5.0.1
Project-redcap Redcap 5.0.6
Project-redcap Redcap 5.0.4
Project-redcap Redcap 4.13.18
Project-redcap Redcap 4.15.3
Project-redcap Redcap 4.15.1
Project-redcap Redcap 4.15.0
Project-redcap Redcap 5.0.0
Project-redcap Redcap 5.0.2
Vanderbilt Redcap 4.14.4
Vanderbilt Redcap
Vanderbilt Redcap 4.14.3
Vanderbilt Redcap 4.14.0
Vanderbilt Redcap 4.14.2
Vanderbilt Redcap 4.14.1
605
VMScore
CVE-2017-10961
REDCap prior to 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components.
Vanderbilt Redcap
578
VMScore
CVE-2013-4609
REDCap prior to 5.0.4 and 5.1.x prior to 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as dem...
Project-redcap Redcap 5.1.0
Project-redcap Redcap 5.1.1
Project-redcap Redcap 4.15.4
Project-redcap Redcap 4.15.2
Project-redcap Redcap 4.14.6
Project-redcap Redcap 4.14.5
Project-redcap Redcap 5.0.1
Project-redcap Redcap 5.1.2
Project-redcap Redcap 4.13.18
Project-redcap Redcap 4.15.3
Project-redcap Redcap 4.15.1
Project-redcap Redcap 4.15.0
Project-redcap Redcap 5.0.0
Project-redcap Redcap 5.0.2
Vanderbilt Redcap 4.14.4
Vanderbilt Redcap
Vanderbilt Redcap 4.14.3
Vanderbilt Redcap 4.14.0
Vanderbilt Redcap 4.14.2
Vanderbilt Redcap 4.14.1
534
VMScore
CVE-2019-14937
REDCap prior to 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 and sleep(3) to Calendar/calendar_popup_ajax.php. The attacker can obtain a user's login sessionid from the database, and then re-login into REDCap to...
Vanderbilt Redcap
383
VMScore
CVE-2020-26713
REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the user is immediately returned in the response and not escaped leading to the reflected XSS vulnerability. Attackers can exploit vulnerabilities to steal login ...
Vanderbilt Redcap 10.3.4
Vanderbilt Redcap 10.0.20
383
VMScore
CVE-2017-10962
REDCap prior to 7.5.1 has XSS via the query string.
Vanderbilt Redcap
383
VMScore
CVE-2012-6564
Cross-site scripting (XSS) vulnerability in REDCap prior to 4.14.5 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Vanderbilt Redcap
Vanderbilt Redcap 4.14.3
Vanderbilt Redcap 4.14.0
Vanderbilt Redcap 4.14.2
Vanderbilt Redcap 4.14.1
383
VMScore
CVE-2012-6566
Cross-site scripting (XSS) vulnerability in REDCap prior to 4.14.2 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Vanderbilt Redcap
Vanderbilt Redcap 4.14.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
SSRF
server-side request forgery
CVE-2024-30067
CVE-2024-5553
CVE-2024-30095
IDOR
CVE-2024-35252
CVE-2024-23692
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »