Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.1) | 0.14% | — | Vivo Health Module | 27/2/2026 | 17/6/2026 | Insufficient protection mechanisms in the Health Module may lead to partial information disclosure. | |
| Analizada | Media (5.5) | 0.59% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 24/2/2026 | 17/6/2026 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This vulnerability affects unknown code of the file /check_profile_old.php. The manipulation of the argument profile_id leads to sql injection. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Alta (8.1) | 0.53% | — | Mikado-themes HealthfirstAI | 20/2/2026 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes HealthFirst healthfirst allows PHP Local File Inclusion.This issue affects HealthFirst: from n/a through <= 1.0.1. | |
| Modificada | Alta (8.1) | 0.53% | — | Ancorathemes Healthhub | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes HealthHub healthhub allows PHP Local File Inclusion.This issue affects HealthHub: from n/a through <= 1.3.0. | |
| Aplazada | Media (4.9) | 0.47% | — | Health CheckAI | 16/12/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in WordPress.org Health Check & Troubleshooting health-check allows Path Traversal.This issue affects Health Check & Troubleshooting: from n/a through <= 1.7.1. | |
| Analizada | Media (4.8) | 0.21% | — | Mieweb Enterprise Health | 20/11/2025 | 17/6/2026 | Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authenticated attacker to add arbitrary content in the 'Demographic Information' page. This content will be rendered and executed when a victim accesses it. This issue is fixed as of 2025-03-14. | |
| Aplazada | Alta (8.8) | 0.35% | — | Nootheme Yogi - Health Beauty & YogaAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in NooTheme Yogi - Health Beauty & Yoga noo-yogi allows Object Injection.This issue affects Yogi - Health Beauty & Yoga: from n/a through <= 2.9.2. | |
| Aplazada | Alta (7.1) | 0.22% | — | Nootheme Yogi - Health Beauty AND YogaAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme Yogi - Health Beauty & Yoga noo-yogi allows Reflected XSS.This issue affects Yogi - Health Beauty & Yoga: from n/a through <= 2.9.2. | |
| Analizada | Media (4.9) | 0.30% | — | Oracle Health Sciences Data Management Workbench | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: Logger). Supported versions that are affected are 3.4.0.1.3 and 3.4.1.0.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Media (5.5) | 0.12% | — | Samsung Health | 10/10/2025 | 17/6/2026 | Improper authorization in Samsung Health prior to version 6.30.5.105 allows local attackers to access data in Samsung Health. | |
| Aplazada | Crítica (9.8) | 0.35% | — | Callvision Healthcare Callvision Emergency CodeAI | 7/10/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthcare Callvision Emergency Code allows SQL Injection, Blind SQL Injection. This issue affects Callvision Emergency Code: before V3.0. | |
| Analizada | Media (5.1) | 0.26% | — | Mieweb Enterprise Health | 29/9/2025 | 17/6/2026 | Medical Informatics Engineering Enterprise Health has a reflected cross site scripting vulnerability in the 'portlet_user_id' URL parameter. A remote, unauthenticated attacker can craft a URL that can execute arbitrary JavaScript in the victim's browser. This issue is fixed as of 2025-03-14. | |
| Analizada | Media (6.3) | 0.24% | — | Mieweb Enterprise Health | 29/9/2025 | 17/6/2026 | Medical Informatics Engineering Enterprise Health has a CSV injection vulnerability that allows a remote, authenticated attacker to inject macros in downloadable CSV files. This issue is fixed as of 2025-03-14. | |
| Analizada | Media (6.2) | 0.25% | — | Mieweb Enterprise Health | 29/9/2025 | 17/6/2026 | Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08. | |
| Analizada | Media (4.6) | 0.14% | — | Mieweb Enterprise Health | 29/9/2025 | 17/6/2026 | Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08. | |
| Analizada | Alta (8.6) | 0.20% | — | Mieweb Enterprise Health | 29/9/2025 | 17/6/2026 | Medical Informatics Engineering Enterprise Health has a cross site request forgery vulnerability that allows an unauthenticated attacker to trick administrative users into clicking a crafted URL and perform actions on behalf of that administrative user. This issue is fixed as of 2025-04-08. | |
| Analizada | Media (5.5) | 0.42% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 18/9/2025 | 17/6/2026 | A flaw has been found in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /check_profile.php. Executing manipulation of the argument profile_id can lead to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 0.35% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 17/9/2025 | 25/9/2026 | A vulnerability was determined in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 on COVID. This affects an unknown function of the file /print_reports_prev.php. Executing manipulation of the argument profile_id can lead to cross site scripting. It is possible to launch the attack remotely. The… | |
| Analizada | Baja (2.1) | 0.36% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 14/9/2025 | 17/6/2026 | A vulnerability was detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some unknown processing of the file /stc-log-keeper/check_profile.php of the component POST Request Handler. The manipulation of the argument profile_id results in cross site scripting. The attack… | |
| Analizada | Media (5.5) | 0.53% | — | Emiloi E-logbook With Health Monitoring System FOR Covid-19 | 9/9/2025 | 17/6/2026 | A security vulnerability has been detected in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. The affected element is an unknown function of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has… | |
| Aplazada | Crítica (9.8) | 0.40% | — | Quanticalabs Medicenter - Health Medical ClinicAI | 20/8/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Object Injection.This issue affects MediCenter - Health Medical Clinic: from n/a through <= 15.1. | |
| Aplazada | Crítica (9.8) | 0.37% | — | Danphe Health Hospital Management System EMRAI | 13/8/2025 | 17/6/2026 | An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health Hospital Management System EMR 3.2 allowing attackers to reset any account password. | |
| Analizada | Media (5.5) | 0.14% | — | Samsung Health | 6/8/2025 | 17/6/2026 | Improper authorization in Samsung Health prior to version 6.30.1.003 allows local attackers to access data in Samsung Health. User interaction is required for triggering this vulnerability. | |
| Analizada | Media (6.9) | 0.48% | — | Razormist Health Center Patient Record Management System | 31/5/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Health Center Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /patient.php. The manipulation of the argument itr_no leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (6.9) | 0.52% | — | Razormist Health Center Patient Record Management System | 31/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Health Center Patient Record Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin.php. The manipulation of the argument Username leads to sql injection. The attack may be launched… |