vciy

CVEs we hold for Cgm

Records whose assigning authority named Cgm as the affected vendor. Newest identifiers first, capped at 200.

CVE-2025-58406Lack of HTTP Response HeadersCGM CLININET
CVE-2025-58405Lack of protection mechanisms against Clickjacking attacksCGM CLININET
CVE-2025-58402Insecure Direct Object Reference Message IDCGM CLININET
CVE-2025-30064Possibility to generate a session for any user via the "ex:action" parameter after obtaining access to the JWT keyCGM CLININET
CVE-2025-30063Excessive permissions on configuration files containing database logins and passwordsCGM CLININET
CVE-2025-30062SQL injection in CheckUnitCodeAndKey.plCGM CLININET
CVE-2025-30061SQL injection in utils/Reporter/OpenReportWindow.pl via the UserID parameterCGM CLININET
CVE-2025-30060SQL injection in ReturnUserUnitsXML.pl via the UserID parameterCGM CLININET
CVE-2025-30059Authenticated SQL injection in PrepareCDExportJSON.plCGM CLININET
CVE-2025-30058SQL injection in getPatientIdentifier function of PatientService.plCGM CLININET
CVE-2025-30057Authenticated RCE with uhcapache privileges in ConvertToPDFCGM CLININET
CVE-2025-30056Calling system commands via RunCommandCGM CLININET
CVE-2025-30055Conditional RCE via the "system" functionCGM CLININET
CVE-2025-30048Unauthenticated access to module configuration endpointCGM CLININET
CVE-2025-30044RCE on uhcapache user permissionsCGM CLININET
CVE-2025-30042Session generation possible with certificate number onlyCGM CLININET
CVE-2025-30041Missing authentication in APIs returning statistical data along with session IDsCGM CLININET
CVE-2025-30040Missing authentication in API returning request logs containing session IDsCGM CLININET
CVE-2025-30039Missing authentication in API returning a list of all active sessionsCGM CLININET
CVE-2025-30038Session ID leakage in Zone.Identifier of downloaded filesCGM CLININET
CVE-2025-30037Missing authentication in APIs allowing data retrieval and modificationCGM CLININET
CVE-2025-30036Stored XSS permitting session takeover of arbitrary userCGM CLININET
CVE-2025-30035Lack of API authentication allowing session generation for any userCGM CLININET
CVE-2025-2313RCE via Print.pl in uhcPrintServerPrintCGM CLININET
CVE-2025-10350SQL injection in CGM NETRAADCGM NETRAAD

25 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.