Known Vulnerabilities for products from Vanderbilt
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Vanderbilt".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2024-55374 json | REDCap 14.3.13 allows an attacker to enumerate usernames due to an observable discrepancy between login attempts. | Not Provided | 2026-01-02 | 2026-07-05 |
| CVE-2023-37798 json | A stored cross-site scripting (XSS) vulnerability in the new REDCap project creation function of Vanderbilt REDCap 13.1.35 al... | Not Provided | 2023-09-07 | 2026-07-09 |
| CVE-2023-37361 json | REDCap 12.0.26 LTS and 12.3.2 Standard allows SQL Injection via scheduling, repeatforms, purpose, app_title, or randomization... | 2.7 - LOW | 2023-07-25 | 2023-07-31 |
| CVE-2022-42715 json | A reflected XSS vulnerability exists in REDCap before 12.04.18 in the Alerts & Notifications upload feature. A crafted CSV fi... | 6.1 - MEDIUM | 2022-10-12 | 2022-10-14 |
| CVE-2022-24127 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.4 - MEDIUM | 2022-06-15 | 2022-06-24 |
| CVE-2022-24004 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 5.4 - MEDIUM | 2022-06-15 | 2022-06-24 |
| CVE-2021-42136 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 9 - CRITICAL | 2022-04-13 | 2022-04-21 |
| CVE-2020-27358 json | An issue was discovered in REDCap 8.11.6 through 9.x before 10. The messenger's CSV feature (that allows users to export thei... | 4.3 - MEDIUM | 2020-11-02 | 2021-07-01 |
| CVE-2020-26713 json | REDCap 10.3.4 contains a XSS vulnerability in the ToDoList function with parameter sort. The information submitted by the use... | 6.1 - MEDIUM | 2021-01-12 | 2021-07-01 |
| CVE-2020-26712 json | REDCap 10.3.4 contains a SQL injection vulnerability in the ToDoList function via sort parameter. The application uses the ad... | 9.8 - CRITICAL | 2021-01-12 | 2021-07-01 |
| CVE-2019-17121 json | REDCap before 9.3.4 has XSS on the Customize & Manage Locking/E-signatures page via Lock Record Custom Text values. | 5.4 - MEDIUM | 2019-10-04 | 2019-10-08 |
| CVE-2019-15127 json | REDCap before 9.3.0 allows XSS attacks against non-administrator accounts on the Data Import Tool page via a CSV data import ... | 5.4 - MEDIUM | 2019-08-21 | 2019-08-23 |
| CVE-2019-14937 json | REDCap before 9.3.0 allows time-based SQL injection in the edit calendar event via the cal_id parameter, such as cal_id=55 an... | 7.5 - HIGH | 2019-08-17 | 2019-08-27 |
| CVE-2019-13029 json | Multiple stored Cross-site scripting (XSS) issues in the admin panel and survey system in REDCap 8 before 8.10.20 and 9 befor... | 4.8 - MEDIUM | 2019-07-11 | 2019-07-24 |
| CVE-2017-10962 json | REDCap before 7.5.1 has XSS via the query string. | Not Provided | 2017-07-18 | 2025-04-20 |
| CVE-2017-10961 json | REDCap before 7.5.1 has CSRF in the deletion feature of the File Repository and File Upload components. | Not Provided | 2017-07-18 | 2025-04-20 |
| CVE-2017-7351 json | A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITControlle... | 8.8 - HIGH | 2018-02-08 | 2021-07-01 |
| CVE-2014-6311 json | generate_doygen.pl in ace before 6.2.7+dfsg-2 creates predictable file names in the /tmp directory which allows attackers to ... | 9.8 - CRITICAL | 2019-11-22 | 2020-08-18 |
| CVE-2013-4612 json | Multiple cross-site scripting (XSS) vulnerabilities in REDCap before 5.1.0 allow remote attackers to inject arbitrary web scr... | Not Provided | 2013-06-17 | 2026-04-29 |
| CVE-2013-4611 json | Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors invo... | Not Provided | 2013-06-17 | 2026-04-29 |
Known software with vulnerabilities from Vanderbilt
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Vanderbilt | Adaptive Communication Environment | 6.2.6 |
| Application | Vanderbilt | Redcap | 8.0 |