Santesoft
Santesoft Sante Pacs Server: vulnerabilidades y CVE
Santesoft Sante Pacs Server tiene 16 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE16
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-54862 | Media (4.8) | 0.18% | — | 18 ago 2025 | Sante PACS Server web portal is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecting a user to a malicious webpage and stealing the user's cookie. |
| CVE-2025-54759 | Media (5.1) | 0.19% | — | 18 ago 2025 | Sante PACS Server is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecting a user to a malicious webpage and stealing the user's cookie. |
| CVE-2025-54156 | Crítica (9.1) | 0.21% | — | 18 ago 2025 | The Sante PACS Server Web Portal sends credential information without encryption. |
| CVE-2025-53948 | Alta (8.7) | 0.78% | — | 18 ago 2025 | The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application would require a manual restart and no authentication is… |
| CVE-2025-2264 | Alta (7.5) | 35% | — | 13 mar 2025 | A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed. |
| CVE-2025-2263 | Crítica (9.8) | 0.91% | — | 13 mar 2025 | During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the username and password. A fixed 0x80-byte stack-based buffer is passed to the function as the output… |
| CVE-2025-0574 | Alta (7.5) | 0.88% | — | 30 ene 2025 | Sante PACS Server URL path Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server.… |
| CVE-2025-0573 | Media (5.3) | 1.9% | — | 30 ene 2025 | Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Sante PACS Server.… |
| CVE-2025-0572 | Media (4.3) | 1.6% | — | 30 ene 2025 | Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Sante PACS Server.… |
| CVE-2025-0571 | Media (6.5) | 0.95% | — | 30 ene 2025 | Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS… |
| CVE-2025-0570 | Media (6.5) | 0.95% | — | 30 ene 2025 | Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS… |
| CVE-2025-0569 | Alta (7.5) | 1.0% | — | 30 ene 2025 | Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server.… |
| CVE-2025-0568 | Alta (7.5) | 1.0% | — | 30 ene 2025 | Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Sante PACS Server.… |
| CVE-2023-51637 | Crítica (9.8) | 0.97% | — | 22 may 2024 | Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server PG.… |
| CVE-2024-1863 | Crítica (9.8) | 1.1% | — | 1 abr 2024 | Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante PACS Server. Authentication is… |
| CVE-2022-2272 | Crítica (9.8) | 2.8% | — | 3 ago 2022 | This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.