Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.30% | — | Open-emr Openemr | 25/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an authenticated attacker could craft a malicious form that, when submitted by a victim, executes arbitrary JavaScript in the victim's browser session. Version 8.0.0.3 patches the issue. | |
| Analizada | Media (5.4) | 0.29% | — | Open-emr Openemr | 25/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, the POST parameter `title` is reflected back in a JSON response built with `json_encode()`. Because the response is served with a `text/html` Content-Type, the browser interprets injected… | |
| Analizada | Alta (8.8) | 0.64% | 💥 PoC | Open-emr Openemr | 25/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions up to and including 8.0.0.2 contain a SQL injection vulnerability in the patient selection feature that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input… | |
| Analizada | Media (5.9) | 0.39% | — | Open-emr Openemr | 25/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, several variables in the MedEx recall/reminder processing code are concatenated directly into SQL queries without parameterization or type casting, enabling SQL injection. Version 8.0.0.3… | |
| Analizada | Media (5.4) | 0.95% | — | Open-emr Openemr | 25/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form are displayed on the encounter page and in the visit history for the users with the same role.… | |
| Analizada | Media (6.3) | 0.38% | — | Open-emr Openemr | 25/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, an Insecure Direct Object Reference (IDOR) vulnerability in the fee sheet product save logic (`library/FeeSheet.class.php`) allows any authenticated user with fee sheet ACL access to… | |
| Analizada | Alta (8.8) | 0.64% | 💥 PoC | Open-emr Openemr | 25/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.3, a Blind SQL Injection vulnerability exists in the Patient Search functionality (/interface/new/new_search_popup.php). The vulnerability allows an authenticated attacker to execute… | |
| Modificada | Alta (8.7) | 1.0% | — | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, a stored cross-site scripting (XSS) vulnerability in the patient portal payment flow allows a patient portal user to persist arbitrary JavaScript that executes in the browser of a staff member who… | |
| Analizada | Alta (7.2) | 0.33% | — | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An Out-of-Band Server-Side Request Forgery (OOB… | |
| Analizada | Media (5.4) | 0.31% | — | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the optional FaxSMS module (`oe-module-faxsms`) allows any authenticated OpenEMR user to invoke controller methods — including `getNotificationLog()`, which returns… | |
| Analizada | Media (6.5) | 0.44% | — | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, an authorization bypass in the dated reminders log allows any authenticated non-admin user to view reminder messages belonging to other users, including associated patient names and free-text… | |
| Analizada | Media (5.4) | 0.65% | — | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 are vulnerable to stored cross-site scripting (XSS) via unescaped `portal_login_username` in the portal credential print view. A patient portal user can set their login username to an XSS… | |
| Analizada | Alta (7.3) | 0.37% | — | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the module ACL function `AclMain::zhAclCheck()` only checks for the presence of any "allow" (user or group). It never checks for explicit "deny" (allowed=0). As a result, administrators cannot… | |
| Analizada | Alta (7.1) | 0.42% | — | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill Eye Exam forms in patient encounters. The answers to the form can be printed out in PDF form. An arbitrary file read vulnerability was… | |
| Analizada | Alta (8.5) | 0.65% | — | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, users with the `Notes - my encounters` role can fill **Eye Exam** forms in patient encounters. The answers to the form are displayed on the encounter page and in the visit history for the users… | |
| Modificada | Crítica (9.1) | 2.6% | 💥 PoC | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 8.0.0.2 contain a Command injection vulnerability in the backup functionality that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the… | |
| Analizada | Media (4.4) | 0.56% | — | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, DOM-based stored XSS in the jQuery SearchHighlight plugin (`library/js/SearchHighlight.js`) allows an authenticated user with encounter form write access to inject arbitrary JavaScript that… | |
| Analizada | Media (6.5) | 0.67% | — | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the DICOM zip/export feature uses a user-supplied destination or path component when creating the zip file, without sanitizing path traversal sequences (e.g. `../`). An attacker with DICOM… | |
| Analizada | Media (6.5) | 0.39% | — | Open-emr Openemr | 19/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.2, the encounter vitals API accepts an `id` in the request body and treats it as an UPDATE. There is no verification that the vital belongs to the current patient or encounter. An authenticated user… | |
| Modificada | Media (6.5) | 0.39% | — | Open-emr Openemr | 18/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. In versions up to and including 8.0.0, the message/note update endpoint (e.g. PUT or POST) updates by message/note ID only and does not verify that the message belongs to the current patient (or that the user is… | |
| Analizada | Alta (8.8) | 0.56% | 💥 PoC | Open-emr Openemr | 11/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, OpenEMR contains a SQL injection vulnerability in the ajax graphs library that can be exploited by authenticated attackers. The vulnerability exists due to insufficient input validation in the… | |
| Analizada | Alta (8.1) | 0.48% | — | Open-emr Openemr | 11/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, an inverted boolean condition in ControllerRouter::route() causes the admin/super ACL check to be enforced only for controllers that already have their own internal authorization (review, log),… | |
| Analizada | Media (5.4) | 0.63% | — | Open-emr Openemr | 11/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, track/item names from the Track Anything feature are stored from user input (POST) and later rendered in Dygraph charts (titles/labels) using innerHTML or equivalent without escaping. A user who… | |
| Analizada | Media (5.4) | 0.63% | — | Open-emr Openemr | 11/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJAX endpoint returns code descriptions (code_text) that are rendered in the front end (e.g. DataTables) without HTML escaping. If an administrator (or user with code… | |
| Analizada | Media (6.5) | 0.34% | — | Open-emr Openemr | 11/3/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, sensitivity checks for group encounters are broken because the code only consults form_encounter for sensitivity, while group encounters store sensitivity in form_groups_encounter. As a result,… |