Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.27% | — | Open-emr Openemr | 25/2/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a Broken Access Control vulnerability exists in OpenEMR’s edih_main.php endpoint, which allows any authenticated user—including low-privilege roles like Receptionist—to access EDI log files… | |
| Analizada | Media (6.5) | 2.2% | 💥 Exploit | Open-emr Openemr | 25/2/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, the `disposeDocument()` method in `EtherFaxActions.php` allows authenticated users to read arbitrary files from the server filesystem. Any authenticated user (regardless of privilege level)… | |
| Analizada | Media (6.1) | 0.18% | — | Open-emr Openemr | 25/2/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the Eye Exam form module allows any authenticated user to be redirected to an arbitrary external URL. This can be exploited for phishing attacks against healthcare providers using OpenEMR.… | |
| Analizada | Baja (1.2) | 0.15% | — | Open-emr Openemr | 25/2/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the `xl()` translation function returns unescaped strings. While wrapper functions exist for escaping in different contexts (`xlt()` for HTML, `xla()` for attributes, `xlj()` for… | |
| Analizada | Media (5.4) | 3.7% | — | Open-emr Openemr | 25/2/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, a stored cross-site scripting vulnerability in the GAD-7 anxiety assessment form allows authenticated users with clinician privileges to inject malicious JavaScript that executes when other… | |
| Analizada | Alta (7.2) | 0.16% | — | Open-emr Openemr | 25/2/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, when a link is sent via Secure Messaging, clicking the link opens the website within the OpenEMR/Portal site. This behavior could be exploited for phishing. Version 7.0.4 patches the issue. | |
| Analizada | Alta (8.1) | 0.24% | — | Open-emr Openemr | 25/2/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: false`), making all external HTTPS connections vulnerable to… | |
| Analizada | Alta (8.5) | 0.25% | — | Open-emr Openemr | 25/2/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions 5.0.0.5 through 7.0.3.4 have a stored cross-site scripting vulnerability in the ub04 helper of the billing interface. The variable `$data` is passed in a click event handler enclosed in single quotes… | |
| Analizada | Alta (8.8) | 0.39% | — | Open-emr Openemr | 28/1/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a broken access control in the Profile Edit endpoint. An authenticated normal user can modify the request parameters (pubpid / pid) to reference another user’s record; the server… | |
| Analizada | Alta (7.1) | 0.41% | — | Open-emr Openemr | 28/1/2026 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.0.4 have a vulnerability where sensitive data is unintentionally revealed to unauthorized parties. Contents of Clinical Notes and Care Plan, where an encounter has Sensitivity=high, can be… | |
| Modificada | Media (4.8) | 0.80% | — | Open-emr Openemr | 21/1/2026 | 17/6/2026 | OpenEMR 5.0.2.1 contains a cross-site scripting vulnerability in user profile parameters that authenticated attackers can chain with a file upload to achieve remote code execution. Attackers can exploit the vulnerability by crafting a malicious payload to download and execute a web shell, enabling remote command… | |
| Analizada | Alta (8.7) | 2.0% | 💥 Exploit | Open-emr Openemr | 1/8/2025 | 16/6/2026 | An authenticated SQL injection vulnerability exists in OpenEMR ≤ 4.1.1 Patch 14 that allows a low-privileged attacker to extract administrator credentials and subsequently escalate privileges. Once elevated, the attacker can exploit an unrestricted file upload flaw to achieve remote code execution, resulting in full… | |
| Analizada | Alta (7.6) | 14% | — | Open-emr Openemr | 23/5/2025 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation and editing privileges to inject arbitrary JavaScript code into the system by… | |
| Analizada | Media (5.4) | 0.29% | — | Open-emr Openemr | 23/5/2025 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. A logging oversight in versions prior to 7.0.3.4 allows password change events to go unrecorded on the client-side log viewer, preventing administrators from auditing critical actions. This weakens traceability and… | |
| Analizada | Alta (7.6) | 10% | — | Open-emr Openemr | 23/5/2025 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. A stored cross-site scripting (XSS) vulnerability in versions prior to 7.0.3.4 allows any authenticated user with patient creation privileges to inject arbitrary JavaScript code into the system by entering… | |
| Analizada | Crítica (9.8) | 6.3% | — | Open-emr Openemr | 3/4/2025 | 17/6/2026 | OpenEMR 7.0.2 is vulnerable to SQL Injection via \openemr\library\classes\Pharmacy.class.php, \controllers\C_Pharmacy.class.php and \openemr\controller.php. | |
| Analizada | Alta (7) | 17% | — | Open-emr Openemr | 1/4/2025 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature in OpenEMR is vulnerable to cross-site scripting attacks via the EXIF title in an image. This vulnerability is fixed in 7.0.3.1. | |
| Analizada | Media (6.9) | 0.47% | — | Open-emr Openemr | 31/3/2025 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. An Out-of-Band Server-Side Request Forgery (OOB SSRF) vulnerability was identified in OpenEMR, allowing an attacker to force the server to make unauthorized requests to external or internal resources. this attack… | |
| Analizada | Alta (8.4) | 11% | — | Open-emr Openemr | 31/3/2025 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. A stored XSS vulnerability in the Bronchitis form component of OpenEMR allows anyone who is able to edit a bronchitis form to steal credentials from administrators. This vulnerability is fixed in 7.0.3. | |
| Analizada | Media (4.6) | 0.33% | — | Open-emr Openemr | 31/3/2025 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. OpenEMR allows reflected cross-site scripting (XSS) in the AJAX Script interface\super\layout_listitems_ajax.php via the target parameter. This vulnerability is fixed in 7.0.3. | |
| Analizada | Alta (7.2) | 0.27% | — | Open-emr Openemr | 31/3/2025 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. The POST parameter hidden_subcategory is output to the page without being properly processed. This leads to a reflected cross-site scripting (XSS) vul;nerability in CAMOS new.php. This vulnerability is fixed in… | |
| Analizada | Media (4.6) | 0.86% | — | Open-emr Openemr | 25/3/2025 | 17/6/2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Versions prior to 7.3.0 are vulnerable to Directory Traversal in the Load Code feature. Version 7.3.0 contains a patch for the issue. | |
| Analizada | Media (4.8) | 0.38% | — | Open-emr Openemr | 15/11/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in openemr/openemr version 7.0.1. An attacker can inject malicious payloads into the 'inputBody' field in the Secure Messaging feature, which can then be sent to other users. When the recipient views the malicious message, the payload is executed, potentially… | |
| Analizada | Crítica (9.8) | 0.80% | — | Open-emr Openemr | 26/6/2024 | 17/6/2026 | An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter. | |
| Analizada | Baja (3.5) | 0.41% | — | Open-emr Openemr | 28/2/2024 | 17/6/2026 | An issue in open-emr before v.7.0.2 allows a remote attacker to escalate privileges via a crafted script to the formid parameter in the ereq_form.php component. |