Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.39%—Broadcom Ehealth26/3/202117/6/2026
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. A regular user must create a malicious library in the writable RPATH, to be dynamically linked when the emtgtctl2 executable is run. The code in the library will be executed as the…
ModificadaCrítica (9.8)1.5%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaCrítica (9.8)1.1%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaAlta (8.8)2.5%—Librehealth EHR1/9/202017/6/2026
interface/new/new_comprehensive_save.php in LibreHealth EHR 2.0.0 suffers from an authenticated file upload vulnerability, allowing remote attackers to achieve remote code execution (RCE) on the hosting webserver by uploading a maliciously crafted image.
ModificadaAlta (8.8)2.0%—Librehealth EHR15/7/202017/6/2026
LibreHealth EMR v2.0.0 is affected by a Local File Inclusion issue allowing arbitrary PHP to be included and executed within the EMR application.
ModificadaAlta (8.8)0.64%—Librehealth EHR15/7/202017/6/2026
LibreHealth EMR v2.0.0 is affected by systemic CSRF.
ModificadaMedia (4.3)0.95%—Librehealth EHR15/7/202017/6/2026
LibreHealth EMR v2.0.0 is affected by SQL injection allowing low-privilege authenticated users to enumerate the database.
ModificadaCrítica (9)1.3%—Librehealth EHR15/7/202017/6/2026
LibreHealth EMR v2.0.0 is vulnerable to XSS that results in the ability to force arbitrary actions on behalf of other users including administrators.
ModificadaCrítica (10)2.2%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+224/1/202017/6/2026
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain…
ModificadaCrítica (9.9)1.1%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape B450 Monitor FirmwareGehealthcare Carescape B650 Monitor FirmwareGehealthcare Carescape B850 Monitor Firmware+524/1/202017/6/2026
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, a vulnerability in the software…
ModificadaAlta (8.6)1.4%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+224/1/202017/6/2026
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices…
ModificadaCrítica (10)2.7%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+224/1/202017/6/2026
In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code.
ModificadaCrítica (10)4.9%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape B450 Monitor FirmwareGehealthcare Carescape B650 Monitor FirmwareGehealthcare Carescape B850 Monitor Firmware+524/1/202017/6/2026
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X,…
ModificadaCrítica (10)1.6%—Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+224/1/202017/6/2026
In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to…
ModificadaAlta (7.8)0.33%—Mckesson Horizon Cardiology FirmwareMckesson Cardiology FirmwareChangehealthcare Cardiology Firmware6/9/201917/6/2026
A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default installation may allow an attacker with local system access to execute unauthorized arbitrary code.
ModificadaAlta (8.8)3.1%—Librehealth EHR20/12/201817/6/2026
LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type.
ModificadaAlta (8.8)1.5%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters.
ModificadaAlta (8.8)2.8%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled input.
ModificadaAlta (8.8)2.8%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled parameters.
ModificadaAlta (7.1)1.5%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter.
ModificadaAlta (8.8)3.3%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution.
ModificadaMedia (6.5)1.4%—Librehealth EHR20/8/201817/6/2026
LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file disclosure that can result in Disclosure of sensitive files on the server. This attack appear to be exploitable via User controlled variable in import templates function.
ModificadaCrítica (9.8)1.4%—Changehealthcare Conserus Image Repository15/12/201717/6/2026
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated user supplying a modified HTTP SOAP request to the vulnerable service allows for…
ModificadaAlta (8.8)3.4%—Broadcom EhealthCA Ehealth26/7/201617/6/2026
CA eHealth 6.2.x and 6.3.x before 6.3.2.13 allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.
ModificadaAlta (8.8)2.7%—CA Ehealth26/7/201617/6/2026
CA eHealth 6.2.x allows remote authenticated users to cause a denial of service or possibly execute arbitrary commands via unspecified vectors.