Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.29% | — | Osirix-viewer Osirix MDAI | 8/5/2025 | 17/6/2026 | Pixmeo OsiriX MD is vulnerable to a local use after free scenario, which could allow an attacker to locally import a crafted DICOM file and cause memory corruption or a system crash. | |
| Aplazada | Crítica (9.3) | 0.30% | — | Pixmeo Osirix MD WEB PortalAI | 8/5/2025 | 17/6/2026 | The Pixmeo Osirix MD Web Portal sends credential information without encryption, which could allow an attacker to steal credentials. | |
| Aplazada | Alta (8.7) | 0.97% | — | Osirix-viewer Osirix MDAI | 8/5/2025 | 17/6/2026 | Pixmeo OsiriX MD is vulnerable to a use after free scenario, which could allow an attacker to upload a crafted DICOM file and cause memory corruption leading to a denial-of-service condition. | |
| Modificada | Baja (1.9) | 0.35% | — | Osirix-viewer OsirixOsirix-viewer Osirix MD | 18/11/2013 | 16/6/2026 | The DICOM listener in OsiriX before 5.8 and before 2.5-MD, when starting up, encrypts the TLS private key file using "SuperSecretPassword" as the hardcoded password, which allows local users to obtain the private key. |