Dhis 2
Vendor:
First CVE: Jun 24, 2021 · Active for 5 years
10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dhis 2 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 24, 2021
5 years ago
Most Recent CVE
May 9, 2023
1,172 days ago
CVE Severity & Scoring
Dhis 210 CVEs
40%
60%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low8 (80.0%)
High1 (10.0%)
None1 (10.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24848HIGH DHIS2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability affects the `/api/programs/orgUnits?pro | Jun 1, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-41187HIGH DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of | Nov 1, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-39179HIGH DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL Injection vulnerability in the Tracker component in DHIS2 Server allows | Oct 29, 2021 | 8.8 | 27 | NO | NO |
CVE-2022-41948HIGH DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Affected versions are subject to a privilege escalation vulnerabi | Dec 8, 2022 | 7.2 | 24 | NO | NO |
CVE-2021-32704HIGH DHIS 2 is an information system for data capture, management, validation, analytics and visualization. A SQL injection security vulnerability has been found in specific versions of | Jun 24, 2021 | 8.8 | 24 | NO | NO |
CVE-2023-31139HIGH DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.37 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39. | May 9, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-32060MEDIUM DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to versions 2.36.13, 2.37.8, 2.38.2, and | May 9, 2023 | 6.5 | 21 | NO | NO |
CVE-2023-31138MEDIUM DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.36 branch and prior to versions 2.37.9.1, 2.38.3.1, and 2.39. | May 9, 2023 | 6.5 | 21 | NO | NO |
CVE-2022-41947MEDIUM DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. Through various features of DHIS2, an authenticated user may be a | Dec 8, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-41949MEDIUM DHIS 2 is an open source information system for data capture, management, validation, analytics and visualization. In affected versions an authenticated DHIS2 user can craft a requ | Dec 8, 2022 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Dhis 2
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.39.0 | 3 | 5.6 | 0.4% | 0 | 0 |