VYPR
Vendor

IRIS

Products
5
CVEs
13
Across products
13
Status
Private

Products

5

Recent CVEs

13
  • CVE-2013-1744CriJan 25, 2020
    risk 0.67cvss 9.8epss 0.05

    IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands.

  • CVE-2020-28405HigJan 29, 2021
    risk 0.57cvss 8.8epss 0.02

    An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to change the privileges of any user of the application. This can be used to grant himself the administrative role or remove all administrative…

  • CVE-2020-28403HigJan 29, 2021
    risk 0.52cvss 8.0epss 0.01

    A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privileges of any user of the application. This can be used to grant himself administrative role or remove the administrative account…

  • CVE-2020-28406MedJan 29, 2021
    risk 0.42cvss 6.5epss 0.01

    An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature.

  • CVE-2020-28404MedJan 29, 2021
    risk 0.42cvss 6.5epss 0.01

    An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access the Billing page without the appropriate privileges.

  • CVE-2020-28401MedJan 29, 2021
    risk 0.42cvss 6.5epss 0.01

    An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access WIP details about jobs he should not have access to.

  • CVE-2026-42538MedJun 4, 2026
    risk 0.41cvss 6.3epss 0.00

    IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 do not properly validate uploaded files. The application can therefore be misused to host phishing pages, amongst other things. This also…

  • CVE-2026-42547MedJun 4, 2026
    risk 0.35cvss 5.4epss 0.00

    IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, users can create alerts for customers that are not assigned to them. This can be abused to falsely attribute fake alerts to customers.…

  • CVE-2022-37028MedSep 27, 2022
    risk 0.35cvss 5.4epss 0.00

    ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker to store a JavaScript payload that will be executed when another user uses the application.

  • CVE-2020-28402MedJan 29, 2021
    risk 0.35cvss 5.4epss 0.01

    An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access Launcher Configuration Panel.

  • CVE-2026-42329MedJun 4, 2026
    risk 0.31cvss 4.7epss 0.00

    Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 contain a weakness where an attacker can misuse it to redirect the user to a malicious website controlled by an attacker. Version 2.4.28…

  • CVE-2026-42543MedJun 4, 2026
    risk 0.28cvss 4.3epss 0.00

    IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 are vulnerable to a cross-site request forgery attack, because they use the HTTP method `GET` to change state on the server. Version 2.4.28…

  • CVE-2026-42540MedJun 4, 2026
    risk 0.28cvss 4.3epss 0.00

    IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 allow a user to alter values in the database via manipulated API requests. Version 2.4.28 contains a patch.