Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
357 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.98% | — | Contechealth Cms8000 Firmware | 13/9/2022 | 17/6/2026 | The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast request could be sent that causes a mass… | |
| Modificada | Media (6.1) | 0.32% | — | Contechealth Cms8000 Firmware | 13/9/2022 | 17/6/2026 | Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters | |
| Modificada | Media (6.8) | 0.39% | — | Contechealth Cms8000 Firmware | 13/9/2022 | 17/6/2026 | A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware and performing a drive-by attack to load… | |
| Modificada | Media (6.1) | 0.51% | — | Redhat Build OF QuarkusRedhat Openshift Application RuntimesRedhat Smallrye Health | 25/8/2022 | 17/6/2026 | It was found that the smallrye health metrics UI component did not properly sanitize some user inputs. An attacker could use this flaw to conduct cross-site scripting attacks. | |
| Modificada | Media (5.5) | 0.19% | — | NHI Health Insurance WEB Service Component | 2/8/2022 | 17/6/2026 | The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service. | |
| Modificada | Media (5.5) | 0.19% | — | NHI Health Insurance WEB Service Component | 2/8/2022 | 17/6/2026 | The NHI card’s web service component has a heap-based buffer overflow vulnerability due to insufficient validation for packet origin parameter length. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service. | |
| Modificada | Alta (7.8) | 0.23% | — | NHI Health Insurance WEB Service Component | 2/8/2022 | 17/6/2026 | The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet header length. A local area network attacker with general user privilege can exploit this vulnerability to execute arbitrary code, manipulate system command or disrupt service. | |
| Modificada | Media (6.5) | 0.80% | — | Oracle Health Sciences Data Management Workbench | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Health Sciences Data Management Workbench product of Oracle Health Sciences Applications (component: User Interface). Supported versions that are affected are 2.4.8.7 and 2.5.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… | |
| Modificada | Alta (7.5) | 1.5% | — | NHI Health Insurance WEB Service Component | 20/6/2022 | 17/6/2026 | NHI’s health insurance web service component has insufficient validation for input string length, which can result in heap-based buffer overflow attack. A remote attacker can exploit this vulnerability to flood the memory space reserved for the program, in order to terminate service without authentication, which… | |
| Modificada | Alta (8.8) | 2.0% | — | Librehealth EHR | 9/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access. | |
| Modificada | Media (6.1) | 0.92% | — | Librehealth EHR | 8/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS. | |
| Modificada | Media (6.1) | 0.97% | — | Librehealth EHR | 7/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS. | |
| Modificada | Media (6.1) | 1.0% | — | Librehealth EHR | 6/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS. | |
| Modificada | Media (6.1) | 0.97% | — | Librehealth EHR | 6/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS. | |
| Modificada | Media (6.1) | 0.97% | — | Librehealth EHR | 6/6/2022 | 17/6/2026 | Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username. | |
| Modificada | Media (6.1) | 0.97% | — | Librehealth EHR | 6/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS. | |
| Modificada | Media (5.4) | 0.87% | — | Librehealth EHR | 5/5/2022 | 17/6/2026 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities. | |
| Modificada | Media (5.4) | 0.87% | — | Librehealth EHR | 5/5/2022 | 17/6/2026 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities. | |
| Modificada | Alta (8.8) | 1.5% | — | Librehealth EHR | 5/5/2022 | 17/6/2026 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection. | |
| Modificada | Alta (7.5) | 4.9% | 💥 PoC | Fasterxml Jackson-databindOracle BIG Data Spatial AND GraphOracle CoherenceOracle Commerce Platform+32 | 11/3/2022 | 17/6/2026 | jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects. | |
| Modificada | Alta (8.8) | 0.44% | — | HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+183 | 16/2/2022 | 17/6/2026 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.42% | — | HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+183 | 16/2/2022 | 17/6/2026 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.42% | — | HP Elite Dragonfly FirmwareHP Elite Dragonfly G2 FirmwareHP Elite Dragonfly MAX FirmwareHP Elite X2 1013 G3 Firmware+183 | 16/2/2022 | 17/6/2026 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution. | |
| Modificada | Alta (8.8) | 0.45% | — | HP Z1 Entry Tower G5 Workstation FirmwareHP Z1 Entry Tower G6 Workstation FirmwareHP Z1 G8 Tower Desktop PC FirmwareHP Z4 G4 Workstation (core-x) Firmware+183 | 16/2/2022 | 17/6/2026 | A potential vulnerability in AMD System Management Mode (SMM) interrupt handler may allow an attacker with high privileges to access the SMM resulting in arbitrary code execution which could be used by malicious actors to bypass security mechanisms provided in the UEFI firmware. | |
| Modificada | Alta (8.8) | 0.44% | — | HP 260 G3 Desktop Mini PC FirmwareHP Elitedesk 800 35W G4 Desktop Mini PC FirmwareHP Elitedesk 800 65W G4 Desktop Mini PC FirmwareHP Elitedesk 800 95W G4 Desktop Mini PC Firmware+183 | 16/2/2022 | 17/6/2026 | Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution. |