Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.65% | — | Anisha E-health Care System | 3/11/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects E-Health Care System 1.0. Affected by this issue is some unknown functionality of the file /Admin/adminlogin.php. The manipulation of the argument email/admin_pswd as part of String leads to sql injection. The attack may be launched… | |
| Analizada | Crítica (9.1) | 0.41% | — | Baxter Connex Health Portal | 9/9/2024 | 17/6/2026 | In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content. | |
| Analizada | Crítica (9.8) | 0.60% | — | Baxter Connex Health Portal | 9/9/2024 | 17/6/2026 | In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database. An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and… | |
| Analizada | Media (5.3) | 0.62% | — | Online Health Care System Project Online Health Care System | 22/8/2024 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument f_name with the input 1%' or 1=1 ) UNION SELECT 1,2,3,4,5,database(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23# as part… | |
| Analizada | Alta (8.8) | 1.8% | — | Microsoft Azure Health BOT | 13/8/2024 | 17/6/2026 | An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. | |
| Modificada | Baja (3.3) | 0.15% | — | Samsung Health | 2/7/2024 | 17/6/2026 | Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this vulnerability. | |
| Analizada | Alta (7.8) | 0.12% | — | HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+349 | 28/6/2024 | 17/6/2026 | A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Aplazada | Alta (7.5) | 0.46% | — | MIA Technology INC Mia-med Health AplicationAI | 24/6/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Interface Manipulation. This issue affects Mia-Med Health Aplication: before 1.0.14. | |
| Aplazada | Media (5.3) | 0.21% | — | MIA Technology INC Mia-med Health AplicationAI | 24/6/2024 | 17/6/2026 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Signature Spoofing by Improper Validation. This issue affects Mia-Med Health Aplication: before 1.0.14. | |
| Modificada | Alta (8.8) | 0.43% | — | Health Care Hospital Management System Project Health Care Hospital Management System | 18/6/2024 | 17/6/2026 | CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter. | |
| Modificada | Alta (8.8) | 0.57% | — | Health Care Hospital Management System Project Health Care Hospital Management System | 18/6/2024 | 17/6/2026 | CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information module via the id parameter. | |
| Modificada | Media (5.4) | 0.33% | — | Health Care Hospital Management System Project Health Care Hospital Management System | 18/6/2024 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page. | |
| Modificada | Alta (8.8) | 0.62% | — | Health Care Hospital Management System Project Health Care Hospital Management System | 18/6/2024 | 17/6/2026 | CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter. | |
| Aplazada | Alta (8.4) | 0.29% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Elevation of privilege vulnerability in GE HealthCare EchoPAC products | |
| Aplazada | Alta (7.6) | 0.34% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Insufficiently protected credentials in GE HealthCare EchoPAC products | |
| Aplazada | Media (6.8) | 0.34% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products | |
| Aplazada | Crítica (9.6) | 0.35% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Weak account password in GE HealthCare EchoPAC products | |
| Aplazada | Media (5.7) | 0.22% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Vulnerable data in transit in GE HealthCare EchoPAC products | |
| Aplazada | Alta (7.7) | 0.28% | — | Gehealthcare Common Service DesktopAI | 14/5/2024 | 17/6/2026 | Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component | |
| Aplazada | Media (6.2) | 0.28% | — | Gehealthcare Common Service DesktopAI | 14/5/2024 | 17/6/2026 | Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component | |
| Aplazada | Alta (8.4) | 0.84% | — | Gehealthcare Ultrasound DevicesAI | 14/5/2024 | 17/6/2026 | OS command injection vulnerabilities in GE HealthCare ultrasound devices | |
| Aplazada | Alta (7.4) | 0.20% | — | Gehealthcare UltrasoundAI | 14/5/2024 | 17/6/2026 | Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices | |
| Aplazada | Media (4.3) | 0.20% | — | Acnam WP Server Health StatsAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saumya Majumder WP Server Health Stats.This issue affects WP Server Health Stats: from n/a through 1.7.3. | |
| Aplazada | Media (5.4) | 0.35% | — | Healthcare-chatbotAI | 15/3/2024 | 17/6/2026 | A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php. | |
| Modificada | Media (6.1) | 0.38% | — | Md1health Md1patient | 28/2/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Msg parameter. |