Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

357 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.56%—Jenkins Health Advisor BY Cloudbees14/5/202517/6/2026
Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Jenkins Health Advisor server responses.
AplazadaAlta (7.1)0.29%—M ALI Saleem Wordpress Health AND Server Condition Integrated With Google Page SpeedAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M. Ali Saleem WordPress Health and Server Condition – Integrated with Google Page Speed wp-condition allows Reflected XSS.This issue affects WordPress Health and Server Condition – Integrated with Google Page Speed:…
AplazadaMedia (4)0.15%—Samsung Device Health Manager ServiceAI8/4/202517/6/2026
Improper handling of insufficient permission in Samsung Device Health Manager Service prior to SMR Apr-2025 Release 1 allows local attackers to access provider in SDMHS.
AnalizadaAlta (8.8)0.69%—Microsoft Azure Health BOT1/4/202517/6/2026
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.
AplazadaAlta (7.1)0.37%—Brainpulse Page Health-o-meterAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brainpulse Page Health-O-Meter page-health-o-meter allows Reflected XSS.This issue affects Page Health-O-Meter: from n/a through <= 2.0.
AplazadaMedia (6.9)0.31%—Dario Health Internet-based Server InfrastructureAI28/2/202517/6/2026
The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, which could lead to unsafe functionality.
AplazadaAlta (8.7)0.40%—Dario HealthAI28/2/202517/6/2026
An attacker could expose cross-user personal identifiable information (PII) and personal health information transmitted to the Android device via the Dario Health application database.
AplazadaAlta (7.1)0.30%—Dario Health Portal ServiceAI28/2/202517/6/2026
The Dario Health portal service application is vulnerable to XSS, which could allow an attacker to obtain sensitive information.
AplazadaMedia (5.5)0.19%—Boohee Technology Boohee HealthAI27/2/202517/6/2026
An issue in Boohee Technology Boohee Health iOS 13.0.13 allows attackers to access sensitive user information via supplying a crafted link.
AplazadaAlta (8.8)0.42%—Agito Computer Health4allAI24/2/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agito Computer Health4All allows SQL Injection. This issue affects Health4All: before 10.01.2025.
AplazadaAlta (8.3)0.44%—Agito Computer Health4allAI24/2/202517/6/2026
Files or Directories Accessible to External Parties vulnerability in Agito Computer Health4All allows Exploiting Incorrectly Configured Access Control Security Levels, Authentication Abuse. This issue affects Health4All: before 10.01.2025.
AplazadaMedia (5.3)0.29%—Quanticalabs Medicenter - Health Medical ClinicAI18/2/202517/6/2026
Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MediCenter - Health Medical Clinic: from n/a through < 14.7.
AplazadaAlta (7.7)0.29%—Gehealthcare ELI 380AIGehealthcare ELI 280AIGehealthcare Bur280AIGehealthcare Mlbur 280AI+57/2/202517/6/2026
An improper access control vulnerability may allow privilege escalation.This issue affects: Versions 2.2.0 and prior.
AplazadaAlta (8.2)0.79%—Contec Health Cms8000 Patient MonitorAI30/1/202517/6/2026
In its default configuration, Contec Health CMS8000 Patient Monitor transmits plain-text patient data to a hard-coded public IP address when a patient is hooked up to the monitor. This could lead to a leakage of confidential patient data to any device with that IP address or an attacker in a machine-in-the-middle…
AplazadaCrítica (9.3)1.3%—Contec Health Cms8000AI30/1/202517/6/2026
Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.
AnalizadaAlta (7.1)0.33%—Healthygrid Dental Optimizer Patient Generator APP27/1/202517/6/2026
The Dental Optimizer Patient Generator App WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AnalizadaMedia (5.3)0.43%—Anisha E-health Care System8/11/202417/6/2026
A vulnerability classified as critical has been found in code-projects E-Health Care System 1.0. This affects an unknown part of the file /Admin/detail.php. The manipulation of the argument s_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may…
AnalizadaMedia (6.9)0.63%—Anisha E-health Care System8/11/202417/6/2026
A vulnerability was found in code-projects E-Health Care System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Doctor/doctor_login.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been…
AnalizadaMedia (5.3)0.43%—Anisha E-health Care System8/11/202417/6/2026
A vulnerability was found in code-projects E-Health Care System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /Doctor/user_appointment.php. The manipulation of the argument schedule_id/schedule_date/schedule_day/start_time/end_time/booking leads to sql…
AnalizadaMedia (6.9)0.75%—Anisha E-health Care System7/11/202417/6/2026
A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file /Doctor/delete_user_appointment_request.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has…
AnalizadaMedia (5.3)0.47%—Anisha E-health Care System5/11/202417/6/2026
A vulnerability was found in code-projects E-Health Care System 1.0. It has been classified as critical. Affected is an unknown function of the file Doctor/app_request.php. The manipulation of the argument app_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to…
AnalizadaMedia (5.3)0.50%—Anisha E-health Care System5/11/202417/6/2026
A vulnerability was found in code-projects E-Health Care System 1.0 and classified as critical. This issue affects some unknown processing of the file /Doctor/chat.php. The manipulation of the argument name/message leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.3)0.50%—Anisha E-health Care System5/11/202417/6/2026
A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file Admin/req_detail.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public…
AnalizadaMedia (6.9)0.66%—Anisha E-health Care System3/11/202417/6/2026
A vulnerability has been found in code-projects E-Health Care System 1.0 and classified as critical. This vulnerability affects unknown code of the file /Users/registration.php. The manipulation of the argument f_name leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.3)0.55%—Anisha E-health Care System3/11/202417/6/2026
A vulnerability, which was classified as critical, was found in code-projects E-Health Care System up to 1.0. This affects an unknown part of the file /Admin/consulting_detail.php. The manipulation of the argument consulting_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has…