Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 0.56% | — | Philips Clinical Collaboration Platform | 18/9/2020 | 17/6/2026 | When an attacker claims to have a given identity, Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not prove or insufficiently proves the claim is correct. | |
| Modificada | Baja (3.5) | 0.47% | — | Philips Clinical Collaboration Platform | 18/9/2020 | 17/6/2026 | Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a webpage that is served to other users. | |
| Modificada | Media (4.3) | 0.29% | — | Philips Clinical Collaboration Platform | 18/9/2020 | 17/6/2026 | Philips Clinical Collaboration Platform, Versions 12.2.1 and prior. The product receives input or data, but it does not validate or incorrectly validates that the input has the properties required to process the data safely and correctly. | |
| Modificada | Alta (8.8) | 1.7% | — | Freemedsoftware Openclinic GA | 29/7/2020 | 17/6/2026 | OpenClinic GA 5.09.02 and 5.89.05b does not properly verify uploaded files, which may allow a low-privilege user to upload and execute arbitrary files on the system. | |
| Modificada | Crítica (9.8) | 2.2% | — | Freemedsoftware Openclinic GA | 29/7/2020 | 17/6/2026 | OpenClinic GA 5.09.02 contains a hidden default user account that may be accessed if an administrator has not expressly turned off this account, which may allow an attacker to login and execute arbitrary commands. | |
| Modificada | Alta (8.8) | 1.3% | — | Openclinic GA Project Openclinic GA | 29/7/2020 | 17/6/2026 | An attacker may bypass permission/authorization checks in OpenClinic GA 5.09.02 and 5.89.05b by ignoring the redirect of a permission failure, which may allow unauthorized execution of commands. | |
| Modificada | Alta (8.8) | 1.7% | — | Openclinic GA Project Openclinic GA | 29/7/2020 | 17/6/2026 | A low-privilege user may use SQL syntax to write arbitrary files to the OpenClinic GA 5.09.02 and 5.89.05b server, which may allow the execution of arbitrary commands. | |
| Modificada | Media (6.1) | 1.2% | — | Openclinic GA Project Openclinic GA | 29/7/2020 | 17/6/2026 | OpenClinic GA 5.09.02 and 5.89.05b does not properly neutralize user-controllable input, which may allow the execution of malicious code within the user’s browser. | |
| Modificada | Alta (8.8) | 2.5% | — | Openclinic GA Project Openclinic GA | 29/7/2020 | 17/6/2026 | OpenClinic GA 5.09.02 and 5.89.05b includes arbitrary local files specified within its parameter and executes some files, which may allow disclosure of sensitive files or the execution of malicious uploaded files. | |
| Modificada | Alta (7.5) | 0.98% | — | Openclinic GA Project Openclinic GA | 29/7/2020 | 17/6/2026 | OpenClinic GA 5.09.02 and 5.89.05b stores passwords using inadequate hashing complexity, which may allow an attacker to recover passwords using known password cracking techniques. | |
| Modificada | Crítica (9.8) | 1.3% | — | Openclinic GA Project Openclinic GA | 20/7/2020 | 17/6/2026 | OpenClinic GA versions 5.09.02 and 5.89.05b contain an authentication mechanism within the system that does not provide sufficient complexity to protect against brute force attacks, which may allow unauthorized users to access the system after no more than a fixed maximum number of attempts. | |
| Modificada | Media (6.5) | 0.84% | — | Openclinic GA Project Openclinic GA | 20/7/2020 | 17/6/2026 | OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may allow a low-privilege user to access privileged information. | |
| Modificada | Crítica (9.8) | 2.5% | — | Openclinic GA Project Openclinic GA | 20/7/2020 | 17/6/2026 | OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass client-side access controls or use a crafted request to initiate a session with limited functionality, which may allow execution of admin functions such as SQL queries. | |
| Modificada | Crítica (9.8) | 1.2% | — | Openclinic GA Project Openclinic GA | 20/7/2020 | 17/6/2026 | OpenClinic GA versions 5.09.02 and 5.89.05b may allow an attacker to bypass the system’s account lockout protection, which may allow brute force password attacks. | |
| Modificada | Crítica (9.8) | 8.9% | 💥 Exploit | Themerex AddonsThemerex Ozeum-museumThemerex Chit Club-board GamesThemerex Yottis-simple Portfolio+59 | 10/3/2020 | 17/6/2026 | The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter. | |
| Modificada | Crítica (10) | 2.2% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilize a weak encryption scheme for remote desktop control, which may allow an attacker to obtain… | |
| Modificada | Crítica (9.9) | 1.1% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape B450 Monitor FirmwareGehealthcare Carescape B650 Monitor FirmwareGehealthcare Carescape B850 Monitor Firmware+5 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, B450 Version 2.X, B650 Version 1.X, B650 Version 2.X, B850 Version 1.X, B850 Version 2.X, a vulnerability in the software… | |
| Modificada | Alta (8.6) | 1.4% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X and CARESCAPE Central Station (CSCS) Versions 2.X, the integrated service for keyboard switching of the affected devices… | |
| Modificada | Crítica (10) | 2.7% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Central Station (CSCS) Versions 1.X, the affected products utilized hard coded SMB credentials, which may allow an attacker to remotely execute arbitrary code. | |
| Modificada | Crítica (10) | 4.9% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape B450 Monitor FirmwareGehealthcare Carescape B650 Monitor FirmwareGehealthcare Carescape B850 Monitor Firmware+5 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X CARESCAPE Central Station (CSCS) Versions 2.X, B450 Version 2.X, B650 Version 1.X,… | |
| Modificada | Crítica (10) | 1.6% | — | Gehealthcare Apexpro Telemetry Server FirmwareGehealthcare Carescape Central Station Mai700 FirmwareGehealthcare Carescape Central Station Mas700 FirmwareGehealthcare Clinical Information Center Mp100d Firmware+2 | 24/1/2020 | 17/6/2026 | In ApexPro Telemetry Server, Versions 4.2 and prior, CARESCAPE Telemetry Server v4.2 & prior, Clinical Information Center (CIC) Versions 4.X and 5.X, CARESCAPE Telemetry Server Version 4.3, CARESCAPE Central Station (CSCS) Versions 1.X, a vulnerability exists in the affected products that could allow an attacker to… | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Crítica (9.8) | 14% | — | Oracle Application Testing SuiteOracle Banking Enterprise CollectionsOracle Banking Enterprise OriginationsOracle Banking Enterprise Product Manufacturing+18 | 16/10/2019 | 17/6/2026 | Vulnerability in the Oracle JDeveloper and ADF product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 11.1.1.9.0, 12.1.3.0.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper and… | |
| Modificada | Media (6.1) | 0.68% | — | Eclinicalworks Patient Portal | 27/1/2017 | 17/6/2026 | An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a reflected Cross Site Scripting vulnerability which affects the raceMasterList.jsp page within the Patient Portal. Inserted payload is rendered within the Patient Portal and the raceMasterList.jsp page does not require authentication. The… | |
| Modificada | Alta (7.5) | 1.1% | — | Eclinicalworks Patient Portal | 27/1/2017 | 17/6/2026 | An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as… |