Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 136 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-32118 OpenEMR has Stored XSS in Graphical Pain Map legend via unescaped annotation text openemropenemr Medium 5.4 2026-03-11 20:46:19 Deep Dive
CVE-2026-24898 OpenEMR has an Unauthenticated MedEx Token Disclosure openemropenemr Critical 10.0 2026-03-03 22:10:30 Deep Dive
CVE-2026-25146 OpenEMR's payments gateway_api_key secret rendered into client JS code openemropenemr Critical 9.6 2026-03-03 22:08:23 Deep Dive
CVE-2026-24848 OpenEMR Arbitrary File Write leading to Remote Code Execution openemropenemr--2026-03-03 22:04:03 Deep Dive
CVE-2026-25147 OpenEMR's Portal Payment Endpoint Trusts User-Controlled pid openemropenemr High 7.1 2026-02-27 16:44:41 Deep Dive
CVE-2026-24488 OpenEMR Vulnerable to Arbitrary File Exfiltration via Fax Endpoint openemropenemr Medium 6.5 2026-02-27 16:41:46 Deep Dive
CVE-2026-27943 OpenEMR's Eye Exam View Trusts form_id Without Verifying Patient/Encounter Ownership openemropenemr Medium 6.5 2026-02-26 01:30:31 Deep Dive
CVE-2026-25930 OpenEMR's Printable LBF Endpoint Leaks Arbitrary Patient Forms openemropenemr Medium 6.5 2026-02-25 18:48:10 Deep Dive
CVE-2026-25929 OpenEMR Patient Picture Context Allows Arbitrary Patient Photo Retrieval openemropenemr Medium 6.5 2026-02-25 18:46:45 Deep Dive
CVE-2026-25927 OpenEMR Missing Authorization Checks in DICOM Viewer State API openemropenemr High 7.1 2026-02-25 18:43:26 Deep Dive
CVE-2026-25746 OpenEMR has SQL Injection Vulnerability openemropenemr High 8.8 2026-02-25 18:39:25 Deep Dive
CVE-2026-25743 OpenEMR has Stored XSS in Questionnaire answers openemropenemr--2026-02-25 18:33:57 Deep Dive
CVE-2026-25476 OpenEMR has Session Timeout Bypass via skip_timeout_reset openemropenemr High 7.5 2026-02-25 18:28:30 Deep Dive
CVE-2026-25220 OpenEMR Messages "Show All" Not Restricted to Admins openemropenemr--2026-02-25 18:25:06 Deep Dive
CVE-2026-25164 OpenEMR's Document and Insurance REST Endpoints Skip ACL openemropenemr High 8.1 2026-02-25 18:22:41 Deep Dive
CVE-2026-24908 OpenEMR has SQL Injection in Patient API Sort Parameter openemropenemr Critical 9.9 2026-02-25 18:14:04 Deep Dive
CVE-2026-24890 OpenEMR Portal Users Can Forge Provider Signatures openemropenemr High 8.1 2026-02-25 18:10:23 Deep Dive
CVE-2026-24487 OpenEMR has FHIR Patient Compartment Bypass in CareTeam Resource openemropenemr--2026-02-25 17:45:25 Deep Dive
CVE-2026-23627 OpenEMR has SQL Injection in Immunization Search/Report openemropenemr--2026-02-25 17:39:21 Deep Dive
CVE-2026-25135 OpenEMR's location resource for Group.$export operation returns entire patient/user population contact information openemropenemr Medium 4.5 2026-02-25 02:02:14 Deep Dive