Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.49% | — | Yottamark Inc. Shopwell - Healthy Diet & Grocery Food Scanner | 15/5/2017 | 17/6/2026 | The YottaMark ShopWell - Healthy Diet & Grocery Food Scanner app 5.3.7 through 5.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.9) | 0.49% | — | Zipongo Inc. Healthy Recipes AND Grocery Deals | 15/5/2017 | 17/6/2026 | The Zipongo - Healthy Recipes and Grocery Deals app before 6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.9) | 0.49% | — | Everyday Health INC Diabetes IN Check\ | 5/5/2017 | 17/6/2026 | The Everyday Health Diabetes in Check: Blood Glucose & Carb Tracker app 3.4.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Crítica (9.8) | 6.2% | 💥 Exploit | Eclinicalworks Population Health | 10/1/2017 | 17/6/2026 | eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID. | |
| Modificada | Alta (8.8) | 3.4% | 💥 Exploit | Eclinicalworks Population Health | 10/1/2017 | 17/6/2026 | eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote attackers to hijack the authentication of content administrators for requests that could lead to the creation, modification and deletion of users, appointments and… | |
| Modificada | Alta (8.8) | 3.3% | 💥 Exploit | Eclinicalworks Population Health | 10/1/2017 | 17/6/2026 | eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input. | |
| Modificada | Media (6.1) | 5.1% | 💥 Exploit | Eclinicalworks Population Health | 10/1/2017 | 17/6/2026 | eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter. | |
| Modificada | Alta (8.8) | 3.4% | — | Broadcom EhealthCA Ehealth | 26/7/2016 | 17/6/2026 | CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors. | |
| Modificada | Alta (8.8) | 2.7% | — | CA Ehealth | 26/7/2016 | 17/6/2026 | CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors. | |
| Modificada | Alta (8.8) | 5.1% | — | Oracle DocumakerOracle Enterprise Manager OPS CenterOracle Health Sciences Information ManagerOracle Healthcare Master Person Index+7 | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index… | |
| Modificada | Crítica (9.8) | 1.5% | — | Epiphanyhealthdata Cardio Server | 27/12/2015 | 17/6/2026 | SQL injection vulnerability in the login page in Epiphany Cardio Server 3.3 allows remote attackers to execute arbitrary SQL commands via a crafted URL. | |
| Modificada | Crítica (9.8) | 41% | — | Apache GroovyOracle Health Sciences Clinical Development CenterOracle Retail Order Broker Cloud ServiceOracle Retail Service Backbone+2 | 13/8/2015 | 17/6/2026 | The MethodClosure class in runtime/MethodClosure.java in Apache Groovy 1.7.0 through 2.4.3 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted serialized object. | |
| Modificada | Alta (10) | 1.6% | — | Gehealthcare Centricity Clinical Archive Audit Trail Repository | 4/8/2015 | 17/6/2026 | GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key manager and (2) server keystore; (3) keystore_password for the server truststore; and atna for the (4) primary storage database and (5) archive storage database, which has unspecified impact and… | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Precision Thunis-800+ | 4/8/2015 | 17/6/2026 | GE Healthcare Precision THUNIS-800+ has a default password of (1) 1973 for the factory default System Utilities menu, (2) TH8740 for installation using TH8740_122_Setup.exe, (3) hrml for "Setup and Activation" using DSASetup, and (4) an empty string for Shutter Configuration, which has unspecified impact and attack… | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Discovery Xr656Gehealthcare Discovery Xr656 G2 | 4/8/2015 | 17/6/2026 | GE Healthcare Discovery XR656 and XR656 G2 has a password of (1) 2getin for the insite user, (2) 4$xray for the xruser user, and (3) #superxr for the root user, which has unspecified impact and attack vectors. NOTE: it is not clear whether these passwords are default, hardcoded, or dependent on another system or… | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Centricity Pacs Workstation | 4/8/2015 | 17/6/2026 | GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of (1) CANal1 for the Administrator user and (2) iis for the IIS user, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or… | |
| Modificada | Alta (10) | 1.6% | — | Gehealthcare Centricity DMS | 4/8/2015 | 17/6/2026 | The Ad Hoc Reporting feature in GE Healthcare Centricity DMS 4.2 has a password of Never!Mind for the Administrator user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Discovery NM 750b | 4/8/2015 | 17/6/2026 | GE Healthcare Discovery NM 750b has a password of 2getin for the insite account for (1) Telnet and (2) FTP, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Centricity Pacs Workstation | 4/8/2015 | 16/6/2026 | GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of ddpadmin for the ddpadmin user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Centricity Pacs ServerGehealthcare Centricity Pacs Workstation | 4/8/2015 | 16/6/2026 | GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1, and Server 4.0, has a password of 2charGE for the geservice account, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that… | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Centricity Pacs Server | 4/8/2015 | 16/6/2026 | GE Healthcare Centricity PACS 4.0 Server has a default password of (1) nasro for the nasro (ReadOnly) user and (2) nasrw for the nasrw (Read/Write) user, which has unspecified impact and attack vectors. | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Precision MPI | 4/8/2015 | 16/6/2026 | GE Healthcare Precision MPi has a password of (1) orion for the serviceapp user, (2) orion for the clinical operator user, and (3) PlatinumOne for the administrator user, which has unspecified impact and attack vectors. NOTE: it is not clear whether these passwords are default, hardcoded, or dependent on another… | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Centricity Pacs-iw | 4/8/2015 | 16/6/2026 | The TeraRecon server, as used in GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions, has a password of (1) shared for the shared user and (2) scan for the scan user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or… | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Centricity Pacs-iw | 4/8/2015 | 16/6/2026 | GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions has a password of A11enda1e for the sa SQL server user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed… | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Centricity Analytics Server | 4/8/2015 | 16/6/2026 | GE Healthcare Centricity Analytics Server 1.1 has a default password of (1) V0yag3r for the SQL Server sa user, (2) G3car3s for the analyst user, (3) G3car3s for the ccg user, (4) V0yag3r for the viewer user, and (5) geservice for the geservice user in the Webmin interface, which has unspecified impact and attack… |