CVEs we hold for Cgm
Records whose assigning authority named Cgm as the affected vendor. Newest identifiers first, capped at 200.
CVE-2025-58405Lack of protection mechanisms against Clickjacking attacksCGM CLININET CVE-2025-30064Possibility to generate a session for any user via the "ex:action" parameter after obtaining access to the JWT keyCGM CLININET CVE-2025-30063Excessive permissions on configuration files containing database logins and passwordsCGM CLININET CVE-2025-30061SQL injection in utils/Reporter/OpenReportWindow.pl via the UserID parameterCGM CLININET CVE-2025-30060SQL injection in ReturnUserUnitsXML.pl via the UserID parameterCGM CLININET CVE-2025-30059Authenticated SQL injection in PrepareCDExportJSON.plCGM CLININET CVE-2025-30058SQL injection in getPatientIdentifier function of PatientService.plCGM CLININET CVE-2025-30057Authenticated RCE with uhcapache privileges in ConvertToPDFCGM CLININET CVE-2025-30048Unauthenticated access to module configuration endpointCGM CLININET CVE-2025-30042Session generation possible with certificate number onlyCGM CLININET CVE-2025-30041Missing authentication in APIs returning statistical data along with session IDsCGM CLININET CVE-2025-30040Missing authentication in API returning request logs containing session IDsCGM CLININET CVE-2025-30039Missing authentication in API returning a list of all active sessionsCGM CLININET CVE-2025-30038Session ID leakage in Zone.Identifier of downloaded filesCGM CLININET CVE-2025-30037Missing authentication in APIs allowing data retrieval and modificationCGM CLININET CVE-2025-30036Stored XSS permitting session takeover of arbitrary userCGM CLININET CVE-2025-30035Lack of API authentication allowing session generation for any userCGM CLININET 25 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.