Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.88% | — | Santesoft Sante Pacs Server | 30/1/2025 | 17/6/2026 | Sante PACS Server URL path Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of… | |
| Analizada | Media (5.3) | 1.9% | — | Santesoft Sante Pacs Server | 30/1/2025 | 17/6/2026 | Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of… | |
| Analizada | Media (4.3) | 1.6% | — | Santesoft Sante Pacs Server | 30/1/2025 | 17/6/2026 | Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Sante PACS Server. Authentication is required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (6.5) | 0.95% | — | Santesoft Sante Pacs Server | 30/1/2025 | 17/6/2026 | Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Media (6.5) | 0.95% | — | Santesoft Sante Pacs Server | 30/1/2025 | 17/6/2026 | Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is required to exploit this vulnerability. The specific flaw exists within… | |
| Analizada | Alta (7.5) | 1.0% | — | Santesoft Sante Pacs Server | 30/1/2025 | 17/6/2026 | Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Alta (7.5) | 1.0% | — | Santesoft Sante Pacs Server | 30/1/2025 | 17/6/2026 | Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Crítica (9.8) | 0.97% | — | Santesoft Sante Pacs Server | 22/5/2024 | 17/6/2026 | Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server PG. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation… | |
| Analizada | Crítica (9.8) | 1.1% | — | Santesoft Sante Pacs Server | 1/4/2024 | 17/6/2026 | Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of HTTP… | |
| Modificada | Crítica (9.8) | 2.8% | — | Santesoft Sante Pacs Server | 3/8/2022 | 17/6/2026 | This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of calls to the login endpoint. When parsing the username element, the process does not… | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Centricity Pacs ServerGehealthcare Centricity Pacs Workstation | 4/8/2015 | 16/6/2026 | GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1, and Server 4.0, has a password of 2charGE for the geservice account, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that… | |
| Modificada | Alta (10) | 1.7% | — | Gehealthcare Centricity Pacs Server | 4/8/2015 | 16/6/2026 | GE Healthcare Centricity PACS 4.0 Server has a default password of (1) nasro for the nasro (ReadOnly) user and (2) nasrw for the nasrw (Read/Write) user, which has unspecified impact and attack vectors. |