Total CVEs

126,114

Critical Severity

2,290

High Severity

7,923

Last 7 Days

1,176
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 61 - 80 of 157 CVEs
CVE-2026-33911 MEDIUM - 5.4

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter `title` is reflected back in a JSON response built with `json_encode()`. Because the response is served with a `text/html` Content-Type, the browser i...

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD
CVE-2026-33910 HIGH - 7.2

OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL injection vulnerability in the patient selection feature that can be exploited by authenticated attackers. The vulnerability exists due to insuf...

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD
CVE-2026-33909 MEDIUM - 5.9

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, several variables in the MedEx recall/reminder processing code are concatenated directly into SQL queries without parameterization or type casting, enabling SQL injectio...

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD
CVE-2026-33348 HIGH - 8.7

OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form are displayed on the encounter page and in the visit history for the users with ...

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD
CVE-2026-32120 MEDIUM - 6.5

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the fee sheet product save logic (`library/FeeSheet.class.php`) allows any authenticated user with fee sheet ...

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD
CVE-2026-29187 HIGH - 8.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a Blind SQL Injection vulnerability exists in the Patient Search functionality (/interface/new/new_search_popup.php). The vulnerability allows an authenticated attacker ...

Vendor: openemr
Product: openemr
Published: Mar 25, 2026
Source: NVD
CVE-2026-33336 HIGH - 8.8

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the main BrowserWindow and does not restrict same-window navigations. An attacker who can place a link in user-gene...

Vendor: go-vikunja
Product: vikunja
Published: Mar 24, 2026
Source: NVD
CVE-2026-33335 HIGH - 8.0

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper passes URLs from `window.open()` calls directly to `shell.openExternal()` without any validation or protocol allowlisting. An attacker who can p...

Vendor: go-vikunja
Product: vikunja
Published: Mar 24, 2026
Source: NVD
CVE-2026-33334 CRITICAL - 9.6

Vikunja is an open-source self-hosted task management platform. Starting in version 0.21.0 and prior to version 2.2.0, the Vikunja Desktop Electron wrapper enables `nodeIntegration` in the renderer process without `contextIsolation` or `sandbox`. This means any cross-site scripting (XSS) vulnerabili...

Vendor: go-vikunja
Product: vikunja
Published: Mar 24, 2026
Source: NVD
CVE-2026-33346 HIGH - 8.7

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, a stored cross-site scripting (XSS) vulnerability in the patient portal payment flow allows a patient portal user to persist arbitrary JavaScript that executes in the browser of...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-33321 HIGH - 7.6

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An Out-of-Band Server-Side Req...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-33305 MEDIUM - 5.4

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the optional FaxSMS module (`oe-module-faxsms`) allows any authenticated OpenEMR user to invoke controller methods — including `getNotificationLog()`,...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-33304 MEDIUM - 6.5

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the dated reminders log allows any authenticated non-admin user to view reminder messages belonging to other users, including associated patient names...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-33303 MEDIUM - 5.4

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 are vulnerable to stored cross-site scripting (XSS) via unescaped `portal_login_username` in the portal credential print view. A patient portal user can set their login ...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-33302 HIGH - 8.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the module ACL function `AclMain::zhAclCheck()` only checks for the presence of any "allow" (user or group). It never checks for explicit "deny" (allowed=0)....

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-33301 HIGH - 8.1

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An arbitrary file read vulner...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-33299 MEDIUM - 5.4

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill **Eye Exam** forms in patient encounters. The answers to the form are displayed on the encounter page and in the visit histo...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-32238 CRITICAL - 9.1

OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers. The vulnerability exists due to insufficient inpu...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-32119 MEDIUM - 4.4

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, DOM-based stored XSS in the jQuery SearchHighlight plugin (`library/js/SearchHighlight.js`) allows an authenticated user with encounter form write access to inject arbitrary Jav...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD
CVE-2026-25928 MEDIUM - 6.5

OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export feature uses a user-supplied destination or path component when creating the zip file, without sanitizing path traversal sequences (e.g. `../`). An attacker...

Vendor: openemr
Product: openemr
Published: Mar 19, 2026
Source: NVD