Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.14% | — | HP Zcentral 4R Workstation FirmwareHP Z1 All-in-one G3 Workstation FirmwareHP Elitebook 725 G4 FirmwareHP Elitebook 745 G4 Firmware+383 | 12/6/2023 | 17/6/2026 | Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. | |
| Modificada | Alta (8.8) | 0.27% | — | Wordpress Health Check & Troubleshooting | 25/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in The WordPress.Org community Health Check & Troubleshooting plugin <= 1.5.1 versions. | |
| Modificada | Media (5.5) | 0.25% | — | Oracle Health Sciences Inform | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Health… | |
| Modificada | Media (5.3) | 0.63% | — | Oracle Health Sciences Inform | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health… | |
| Modificada | Media (5.9) | 0.39% | — | Oracle Health Sciences Inform | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Health… | |
| Modificada | Alta (8.3) | 0.59% | — | Oracle Health Sciences Inform | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health… | |
| Modificada | Media (6.8) | 0.49% | — | Oracle Health Sciences Inform | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… | |
| Modificada | Media (5.4) | 0.41% | — | Oracle Health Sciences Inform | 18/4/2023 | 17/6/2026 | Vulnerability in the Oracle Health Sciences InForm product of Oracle Health Sciences Applications (component: Core). Supported versions that are affected are Prior to 6.3.1.3 and Prior to 7.0.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Health… | |
| Modificada | Media (6.5) | 0.67% | — | Imaworldhealth Bhima | 5/4/2023 | 17/6/2026 | Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. This is possible because the application is vulnerable to IDOR, it does not properly validate user permissions with respect to… | |
| Modificada | Media (6.5) | 0.75% | — | Imaworldhealth Bhima | 5/4/2023 | 17/6/2026 | Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator. This is possible because the application is vulnerable to CSRF. | |
| Modificada | Media (4.3) | 0.48% | — | Imaworldhealth Bhima | 5/4/2023 | 17/6/2026 | Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session data such as username, email and password. This is possible because the application is vulnerable to IDOR, it does not correctly validate user permissions with respect to certain actions that can be… | |
| Modificada | Media (5.4) | 0.55% | — | Health Center Patient Record Management System Project Health Center Patient Record Management System | 7/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file birthing_print.php. The manipulation of the argument birth_id leads to cross site scripting. The attack can be initiated remotely. The… | |
| Modificada | Crítica (9.8) | 0.80% | — | Health Center Patient Record Management System Project Health Center Patient Record Management System | 7/3/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Health Center Patient Record Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (6.1) | 0.61% | — | Health Center Patient Record Management System Project Health Center Patient Record Management System | 5/3/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file hematology_print.php. The manipulation of the argument hem_id leads to cross site scripting. The attack can be… | |
| Modificada | Media (6.1) | 0.56% | — | Health Center Patient Record Management System Project Health Center Patient Record Management System | 2/3/2023 | 17/6/2026 | A vulnerability classified as problematic was found in SourceCodester Health Center Patient Record Management System 1.0. This vulnerability affects unknown code of the file admin/fecalysis_form.php. The manipulation of the argument itr_no leads to cross site scripting. The attack can be initiated remotely. The… | |
| Modificada | Alta (7) | 0.14% | — | HP Dragonfly Folio G3 2-in-1 FirmwareHP Elite Dragonfly FirmwareHP Elite Dragonfly G3 FirmwareHP Elite Dragonfly G2 Firmware+313 | 1/2/2023 | 17/6/2026 | A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability. | |
| Modificada | Alta (7.8) | 0.17% | — | HP 340 G3 FirmwareHP 340 G4 FirmwareHP 346 G3 FirmwareHP 346 G4 Firmware+373 | 1/2/2023 | 17/6/2026 | HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities. | |
| Modificada | Media (5.3) | 0.56% | — | Healthchecks | 23/1/2023 | 17/6/2026 | Observable Discrepancy in GitHub repository healthchecks/healthchecks prior to v2.6. | |
| Modificada | Crítica (9.8) | 0.83% | — | Online Health Care System Project Online Health Care System | 13/1/2023 | 17/6/2026 | Online Health Care System v1.0 was discovered to contain a SQL injection vulnerability via the consulting_id parameter at /healthcare/Admin/consulting_detail.php. | |
| Modificada | Media (6.1) | 0.63% | — | Healthmateweb Project Healthmateweb | 9/1/2023 | 17/6/2026 | A vulnerability was found in HealthMateWeb. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file createaccount.php. The manipulation of the argument username/password/first_name/last_name/company/phone leads to cross site scripting. The attack can be launched… | |
| Modificada | Crítica (9.8) | 0.72% | — | Healthit Code-validator-api | 29/12/2022 | 17/6/2026 | A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidationConfigurations of the file src/main/java/org/sitenv/vocabularies/configuration/CodeValidatorApiConfiguration.java of the component XML Handler. The manipulation leads… | |
| Modificada | Media (5.4) | 0.55% | 💥 PoC | Caehealthcare Learningspace Enterprise | 23/11/2022 | 17/6/2026 | CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup. | |
| Modificada | Media (4.8) | 0.68% | — | Acnam WP Server Health Stats | 16/9/2022 | 17/6/2026 | The WP Server Health Stats WordPress plugin before 1.7.0 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.7) | 0.30% | — | Contechealth Cms8000 Firmware | 13/9/2022 | 17/6/2026 | The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to the malicious SSID, the device can be exploited to write arbitrary files or… | |
| Modificada | Media (4.4) | 0.19% | — | Contechealth Cms8000 Firmware | 13/9/2022 | 17/6/2026 | Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse engineer sensitive code and identify additional vulnerabilities. |