漏洞列表 358424
CVE ID 标题 严重程度 CVSS 发布时间 受影响产品 数据源 操作
CVE-2026-25131
OpenEMR has Broken Access Control in Procedures Configuration
HIGH 8.8 2026-02-25
openemr openemr open-emr openemr
CVE NVD
CVE-2026-25127
OpenEMR has Broken Access Control on Care Coordination Module
HIGH 7.0 2026-02-25
openemr openemr open-emr openemr
CVE NVD
CVE-2026-25124
OpenEMR has Broken Access Control in Report/Clients/Message List CSV Export
MEDIUM 6.5 2026-02-25
openemr openemr open-emr openemr
CVE NVD
CVE-2026-24896
OpenEMR has Broken Access Control that allows unauthorized access to EDI Logs
MEDIUM 6.5 2026-02-25
openemr openemr open-emr openemr
CVE NVD
CVE-2026-24849
OpenEMR Arbitrary File Read Vulnerability
CRITICAL 10.0 2026-02-25
openemr openemr open-emr openemr
CVE NVD
CVE-2026-24847
OpenEMR has Open Redirect in Eye Exam Form
MEDIUM 6.1 2026-02-25
openemr openemr open-emr openemr
CVE NVD
CVE-2026-2914
CyberArk Endpoint Privilege Manager Agent versions 25.10.0 and lower allow potential unauthorized pr...
HIGH 8.5 2026-02-25
CyberArk Software, a Palo Alto Networks Company Endpoint Privilege Manager Agent cyberark endpoint_privilege_manager
CVE NVD
CVE-2026-21443
OpenEMR allows inconsistent escaping of translation function output
LOW 1.2 2026-02-25
openemr openemr open-emr openemr
CVE NVD
CVE-2025-69231
OpenEMR has a Stored XSS in GAD-7 Form that Enables Session Hijacking and Privilege Escalation
HIGH 8.7 2026-02-25
openemr openemr open-emr openemr
CVE NVD
CVE-2025-68277
OpenEMR allows links sent via Secure Messaging to be opened in OpenEMR and Portal
HIGH 7.2 2026-02-25
openemr openemr open-emr openemr
CVE NVD
CVE-2025-67752
OpenEMR Has Disabled SSL Certificate Verification in HTTP Client
HIGH 8.1 2026-02-25
openemr openemr open-emr openemr
CVE NVD
CVE-2026-3137
CodeAstro Food Ordering System food_ordering.exe stack-based overflow
MEDIUM 4.8 2026-02-25
CodeAstro Food Ordering System codeastro food_ordering_system
CVE NVD
CVE-2025-67491
OpenEMR has Stored XSS in ub04 helper
HIGH 8.5 2026-02-25
openemr openemr open-emr openemr
CVE NVD
CVE-2026-27598
Dagu: Path traversal in DAG creation allows arbitrary YAML file write outside DAGs directory
HIGH 7.1 2026-02-25
dagu-org dagu dagu dagu
CVE NVD
CVE-2026-3135
itsourcecode News Portal Project add-category.php sql injection
MEDIUM 6.9 2026-02-25
itsourcecode News Portal Project clive_21 news_portal_project
CVE NVD
CVE-2025-69771
An arbitrary file upload vulnerability in the subtitle loading function of asbplayer v1.13.0 allows ...
CRITICAL 9.6 2026-02-25
killergerbah asbplayer
CVE NVD
CVE-2026-26717
An issue in OpenFUN Richie (LMS) in src/richie/apps/courses/api.py. The application used the non-con...
MEDIUM 4.8 2026-02-25
未知
CVE NVD
CVE-2026-3134
itsourcecode News Portal Project edit-category.php sql injection
MEDIUM 6.9 2026-02-24
itsourcecode News Portal Project clive_21 news_portal_project
CVE NVD
CVE-2026-3133
itsourcecode Document Management System Login loging.php sql injection
MEDIUM 6.9 2026-02-24
itsourcecode Document Management System admerc document_management_system
CVE NVD
CVE-2026-26351
GetSimpleCMS-CE < 3.3.22 Stored XSS via components.php
MEDIUM 4.8 2026-02-24
GetSimpleCMS-CE GetSimpleCMS-CE getsimple-ce getsimple_cms
CVE NVD