Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

357 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.98%—Contechealth Cms8000 Firmware13/9/202217/6/2026
The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast request could be sent that causes a mass…
ModificadaMedia (6.1)0.32%—Contechealth Cms8000 Firmware13/9/202217/6/2026
Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters
ModificadaMedia (6.8)0.39%—Contechealth Cms8000 Firmware13/9/202217/6/2026
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware and performing a drive-by attack to load…
ModificadaMedia (6.1)0.51%—Redhat Build OF QuarkusRedhat Openshift Application RuntimesRedhat Smallrye Health25/8/202217/6/2026
It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks.
ModificadaMedia (5.5)0.19%—NHI Health Insurance WEB Service Component2/8/202217/6/2026
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.
ModificadaMedia (5.5)0.19%—NHI Health Insurance WEB Service Component2/8/202217/6/2026
The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.
ModificadaAlta (7.8)0.23%—NHI Health Insurance WEB Service Component2/8/202217/6/2026
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A local area network attacker with general user privilege can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service.
ModificadaMedia (6.5)0.80%—Oracle Health Sciences Data Management Workbench19/7/202217/6/2026
Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: User Interface). Supported versions that are affected are 2.4.8.7 and 2.5.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
ModificadaAlta (7.5)1.5%—NHI Health Insurance WEB Service Component20/6/202217/6/2026
NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate service without authentication, which…
ModificadaAlta (8.8)2.0%—Librehealth EHR9/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.
ModificadaMedia (6.1)0.92%—Librehealth EHR8/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.
ModificadaMedia (6.1)0.97%—Librehealth EHR7/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.
ModificadaMedia (6.1)1.0%—Librehealth EHR6/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.
ModificadaMedia (6.1)0.97%—Librehealth EHR6/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.
ModificadaMedia (6.1)0.97%—Librehealth EHR6/6/202217/6/2026
Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username.
ModificadaMedia (6.1)0.97%—Librehealth EHR6/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.
ModificadaMedia (5.4)0.87%—Librehealth EHR5/5/202217/6/2026
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities.
ModificadaMedia (5.4)0.87%—Librehealth EHR5/5/202217/6/2026
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities.
ModificadaAlta (8.8)1.5%—Librehealth EHR5/5/202217/6/2026
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection.
ModificadaAlta (7.5)4.9%💥 PoCFasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+3211/3/202217/6/2026
jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.
ModificadaAlta (8.8)0.44%—HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+18316/2/202217/6/2026
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
ModificadaAlta (8.8)0.42%—HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+18316/2/202217/6/2026
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
ModificadaAlta (8.8)0.42%—HP Elite Dragonfly FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX FirmwareHP Elite X2 1013 G3 Firmware+18316/2/202217/6/2026
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
ModificadaAlta (8.8)0.45%—HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+18316/2/202217/6/2026
A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware.
ModificadaAlta (8.8)0.44%—HP 260 G3 Desktop Mini PC FirmwareHP Elitedesk 800 35W G4 Desktop Mini PC FirmwareHP Elitedesk 800 65W G4 Desktop Mini PC FirmwareHP Elitedesk 800 95W G4 Desktop Mini PC Firmware+18316/2/202217/6/2026
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.