Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.56% | — | Jenkins Health Advisor BY Cloudbees | 14/5/2025 | 17/6/2026 | Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Jenkins Health Advisor server responses. | |
| Aplazada | Alta (7.1) | 0.29% | — | M ALI Saleem Wordpress Health AND Server Condition Integrated With Google Page SpeedAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Ali Saleem WordPress Health and Server Condition – Integrated with Google Page Speed wp-condition allows Reflected XSS.This issue affects WordPress Health and Server Condition – Integrated with Google Page Speed:… | |
| Aplazada | Media (4) | 0.15% | — | Samsung Device Health Manager ServiceAI | 8/4/2025 | 17/6/2026 | Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS. | |
| Analizada | Alta (8.8) | 0.69% | — | Microsoft Azure Health BOT | 1/4/2025 | 17/6/2026 | An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. | |
| Aplazada | Alta (7.1) | 0.37% | — | Brainpulse Page Health-o-meterAI | 3/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brainpulse Page Health-O-Meter page-health-o-meter allows Reflected XSS.This issue affects Page Health-O-Meter: from n/a through <= 2.0. | |
| Aplazada | Media (6.9) | 0.31% | — | Dario Health Internet-based Server InfrastructureAI | 28/2/2025 | 17/6/2026 | The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, which could lead to unsafe functionality. | |
| Aplazada | Alta (8.7) | 0.40% | — | Dario HealthAI | 28/2/2025 | 17/6/2026 | An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database. | |
| Aplazada | Alta (7.1) | 0.30% | — | Dario Health Portal ServiceAI | 28/2/2025 | 17/6/2026 | The Dario Health portal service application is vulnerable to XSS, which could allow an attacker to obtain sensitive information. | |
| Aplazada | Media (5.5) | 0.19% | — | Boohee Technology Boohee HealthAI | 27/2/2025 | 17/6/2026 | An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Alta (8.8) | 0.42% | — | Agito Computer Health4allAI | 24/2/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Health4All allows SQL Injection. This issue affects Health4All: before 10.01.2025. | |
| Aplazada | Alta (8.3) | 0.44% | — | Agito Computer Health4allAI | 24/2/2025 | 17/6/2026 | Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorrectly Configured Access Control Security Levels, Authentication Abuse. This issue affects Health4All: before 10.01.2025. | |
| Aplazada | Media (5.3) | 0.29% | — | Quanticalabs Medicenter - Health Medical ClinicAI | 18/2/2025 | 17/6/2026 | Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MediCenter - Health Medical Clinic: from n/a through < 14.7. | |
| Aplazada | Alta (7.7) | 0.29% | — | Gehealthcare ELI 380AIGehealthcare ELI 280AIGehealthcare Bur280AIGehealthcare Mlbur 280AI+5 | 7/2/2025 | 17/6/2026 | An improper access control vulnerability may allow privilege escalation.This issue affects: Versions 2.2.0 and prior. | |
| Aplazada | Alta (8.2) | 0.79% | — | Contec Health Cms8000 Patient MonitorAI | 30/1/2025 | 17/6/2026 | In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or an attacker in a machine-in-the-middle… | |
| Aplazada | Crítica (9.3) | 1.3% | — | Contec Health Cms8000AI | 30/1/2025 | 17/6/2026 | Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution. | |
| Analizada | Alta (7.1) | 0.33% | — | Healthygrid Dental Optimizer Patient Generator APP | 27/1/2025 | 17/6/2026 | The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Analizada | Media (5.3) | 0.43% | — | Anisha E-health Care System | 8/11/2024 | 17/6/2026 | A vulnerability classified as critical has been found in code-projects E-Health Care System 1.0. This affects an unknown part of the file /Admin/detail.php. The manipulation of the argument s_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may… | |
| Analizada | Media (6.9) | 0.63% | — | Anisha E-health Care System | 8/11/2024 | 17/6/2026 | A vulnerability was found in code-projects E-Health Care System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Doctor/doctor_login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been… | |
| Analizada | Media (5.3) | 0.43% | — | Anisha E-health Care System | 8/11/2024 | 17/6/2026 | A vulnerability was found in code-projects E-Health Care System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Doctor/user_appointment.php. The manipulation of the argument schedule_id/schedule_date/schedule_day/start_time/end_time/booking leads to sql… | |
| Analizada | Media (6.9) | 0.75% | — | Anisha E-health Care System | 7/11/2024 | 17/6/2026 | A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file /Doctor/delete_user_appointment_request.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.47% | — | Anisha E-health Care System | 5/11/2024 | 17/6/2026 | A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file Doctor/app_request.php. The manipulation of the argument app_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Analizada | Media (5.3) | 0.50% | — | Anisha E-health Care System | 5/11/2024 | 17/6/2026 | A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some unknown processing of the file /Doctor/chat.php. The manipulation of the argument name/message leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.50% | — | Anisha E-health Care System | 5/11/2024 | 17/6/2026 | A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file Admin/req_detail.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Media (6.9) | 0.66% | — | Anisha E-health Care System | 3/11/2024 | 17/6/2026 | A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file /Users/registration.php. The manipulation of the argument f_name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the… | |
| Analizada | Media (5.3) | 0.55% | — | Anisha E-health Care System | 3/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects E-Health Care System up to 1.0. This affects an unknown part of the file /Admin/consulting_detail.php. The manipulation of the argument consulting_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has… |