Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

The HISP Centre at the University of Oslo

First CVE: Jun 24, 2021Active for: 5 yearsTotal CVEs: 10
39.3
VTI Score
Medium

The HISP Centre at the University of Oslo maintains DHIS 2, a health information management platform widely deployed across public health systems in resource-limited settings, which despite a narrow product focus carries significance within its epidemiological and surveillance domain. The recurring vulnerability patterns center on application-layer input handling and access control, with disclosures clustering around SQL injection, cross-site scripting, improper authorization, and privilege management weaknesses that are characteristic of web-facing data-collection systems. Current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by The HISP Centre at the University of Oslo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2021
5 years ago
Most Recent CVE
May 9, 2023
1,173 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-24848HIGH
DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability affects the `/api/programs/orgUnits?pro
Jun 1, 20228.828NONO
CVE-2021-41187HIGH
DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of
Nov 1, 20218.827NONO
CVE-2021-39179HIGH
DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection vulnerability in the Tracker component in DHIS2 Server allows
Oct 29, 20218.827NONO
CVE-2022-41948HIGH
DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Affected versions are subject to a privilege escalation vulnerabi
Dec 8, 20227.224NONO
CVE-2021-32704HIGH
DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of
Jun 24, 20218.824NONO
CVE-2023-31139HIGH
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.37 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39.
May 9, 20237.523NONO
CVE-2023-32060MEDIUM
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to versions 2.36.13, 2.37.8, 2.38.2, and
May 9, 20236.521NONO
CVE-2023-31138MEDIUM
DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.36 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39.
May 9, 20236.521NONO
CVE-2022-41947MEDIUM
DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Through various features of DHIS2, an authenticated user may be a
Dec 8, 20225.420NONO
CVE-2022-41949MEDIUM
DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. In affected versions an authenticated DHIS2 user can craft a requ
Dec 8, 20224.318NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
40%
60%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low8 (80.0%)
High1 (10.0%)
None1 (10.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by The HISP Centre at the University of Oslo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by The HISP Centre at the University of Oslo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For The HISP Centre at the University of Oslo's Products

View all 1 CNAs →

Top CWEs