Redcap
Vendor:
First CVE: Jun 17, 2013 · Active for 13 years
6
Total CVEs
More Total CVEs than 80% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Redcap over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 17, 2013
13 years ago
Most Recent CVE
Jun 17, 2013
4,786 days ago
CVE Severity & Scoring
Redcap6 CVEs
67%
33%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4610HIGH Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact and remote attack vectors. | Jun 17, 2013 | 10.0 | 28 | NO | NO |
CVE-2013-4611HIGH Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the Online Designer page or (2) the Manage Su | Jun 17, 2013 | 10.0 | 25 | NO | NO |
CVE-2012-6567MEDIUM REDCap before 4.14.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the logic of a custom rule. | Jun 17, 2013 | 6.5 | 20 | NO | NO |
CVE-2013-4609MEDIUM REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass in | Jun 17, 2013 | 6.5 | 18 | NO | NO |
CVE-2013-4612MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in REDCap before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving different | Jun 17, 2013 | 4.3 | 14 | NO | NO |
CVE-2013-4608MEDIUM Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving the Graphical Data View & Descr | Jun 17, 2013 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Redcap
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.1.2 | 1 | 6.5 | 1.5% | 0 | 0 |
| 5.1.1 | 2 | 8.3 | 1.6% | 0 | 0 |
| 5.1.0 | 2 | 8.3 | 1.6% | 0 | 0 |
| 5.0.6 | 2 | 10.0 | 2.3% | 0 | 0 |
| 5.0.5 | 2 | 7.2 | 2.2% | 0 | 0 |
| 5.0.4 | 3 | 6.2 | 1.8% | 0 | 0 |
| 5.0.3 | 3 | 6.2 | 1.8% | 0 | 0 |
| 5.0.2 | 4 | 6.3 | 1.8% | 0 | 0 |
| 5.0.1 | 5 | 7.0 | 1.8% | 0 | 0 |
| 5.0.0 | 5 | 7.0 | 1.8% | 0 | 0 |
| 4.15.4 | 5 | 7.0 | 1.8% | 0 | 0 |
| 4.15.3 | 5 | 7.0 | 1.8% | 0 | 0 |
| 4.15.2 | 5 | 7.0 | 1.8% | 0 | 0 |
| 4.15.1 | 5 | 7.0 | 1.8% | 0 | 0 |
| 4.15.0 | 5 | 7.0 | 1.8% | 0 | 0 |
| 4.14.6 | 5 | 7.0 | 1.8% | 0 | 0 |
| 4.14.5 | 5 | 7.0 | 1.8% | 0 | 0 |
| 4.13.18 | 5 | 7.0 | 1.8% | 0 | 0 |