Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

357 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.65%—Anisha E-health Care System3/11/202417/6/2026
A vulnerability, which was classified as critical, has been found in code-projects E-Health Care System 1.0. Affected by this issue is some unknown functionality of the file /Admin/adminlogin.php. The manipulation of the argument email/admin_pswd as part of String leads to sql injection. The attack may be launched…
AnalizadaCrítica (9.1)0.41%—Baxter Connex Health Portal9/9/202417/6/2026
In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content.
AnalizadaCrítica (9.8)0.60%—Baxter Connex Health Portal9/9/202417/6/2026
In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database. An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and…
AnalizadaMedia (5.3)0.62%—Online Health Care System Project Online Health Care System22/8/202417/6/2026
A vulnerability classified as critical has been found in SourceCodester Online Health Care System 1.0. Affected is an unknown function of the file search.php. The manipulation of the argument f_name with the input 1%' or 1=1 ) UNION SELECT 1,2,3,4,5,database(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23# as part…
AnalizadaAlta (8.8)1.8%—Microsoft Azure Health BOT13/8/202417/6/2026
An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.
ModificadaBaja (3.3)0.15%—Samsung Health2/7/202417/6/2026
Improper input validation in Samsung Health prior to version 6.27.0.113 allows local attackers to write arbitrary document files to the sandbox of Samsung Health. User interaction is required for triggering this vulnerability.
AnalizadaAlta (7.8)0.12%—HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+34928/6/202417/6/2026
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
AplazadaAlta (7.5)0.46%—MIA Technology INC Mia-med Health AplicationAI24/6/202417/6/2026
Improper Restriction of Excessive Authentication Attempts vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Interface Manipulation. This issue affects Mia-Med Health Aplication: before 1.0.14.
AplazadaMedia (5.3)0.21%—MIA Technology INC Mia-med Health AplicationAI24/6/202417/6/2026
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Mia Technology Inc. Mia-Med Health Aplication allows Signature Spoofing by Improper Validation. This issue affects Mia-Med Health Aplication: before 1.0.14.
ModificadaAlta (8.8)0.43%—Health Care Hospital Management System Project Health Care Hospital Management System18/6/202417/6/2026
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter.
ModificadaAlta (8.8)0.57%—Health Care Hospital Management System Project Health Care Hospital Management System18/6/202417/6/2026
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information module via the id parameter.
ModificadaMedia (5.4)0.33%—Health Care Hospital Management System Project Health Care Hospital Management System18/6/202417/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in CodeProjects Health Care hospital Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the fname and lname parameters under the Staff Info page.
ModificadaAlta (8.8)0.62%—Health Care Hospital Management System Project Health Care Hospital Management System18/6/202417/6/2026
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Patient Info module via the searvalu parameter.
AplazadaAlta (8.4)0.29%—Gehealthcare EchopacAI14/5/202417/6/2026
Elevation of privilege vulnerability in GE HealthCare EchoPAC products
AplazadaAlta (7.6)0.34%—Gehealthcare EchopacAI14/5/202417/6/2026
Insufficiently protected credentials in GE HealthCare EchoPAC products
AplazadaMedia (6.8)0.34%—Gehealthcare EchopacAI14/5/202417/6/2026
Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products
AplazadaCrítica (9.6)0.35%—Gehealthcare EchopacAI14/5/202417/6/2026
Weak account password in GE HealthCare EchoPAC products
AplazadaMedia (5.7)0.22%—Gehealthcare EchopacAI14/5/202417/6/2026
Vulnerable data in transit in GE HealthCare EchoPAC products
AplazadaAlta (7.7)0.28%—Gehealthcare Common Service DesktopAI14/5/202417/6/2026
Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component
AplazadaMedia (6.2)0.28%—Gehealthcare Common Service DesktopAI14/5/202417/6/2026
Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component
AplazadaAlta (8.4)0.84%—Gehealthcare Ultrasound DevicesAI14/5/202417/6/2026
OS command injection vulnerabilities in GE HealthCare ultrasound devices
AplazadaAlta (7.4)0.20%—Gehealthcare UltrasoundAI14/5/202417/6/2026
Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices
AplazadaMedia (4.3)0.20%—Acnam WP Server Health StatsAI12/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Saumya Majumder WP Server Health Stats.This issue affects WP Server Health Stats: from n/a through 1.7.3.
AplazadaMedia (5.4)0.35%—Healthcare-chatbotAI15/3/202417/6/2026
A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php.
ModificadaMedia (6.1)0.38%—Md1health Md1patient28/2/202417/6/2026
A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Msg parameter.