Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.7)0.29%—Gehealthcare ELI 380AIGehealthcare ELI 280AIGehealthcare Bur280AIGehealthcare Mlbur 280AI+57/2/202517/6/2026
An improper access control vulnerability may allow privilege escalation.This issue affects: Versions 2.2.0 and prior.
AplazadaAlta (8.4)0.29%—Gehealthcare EchopacAI14/5/202417/6/2026
Elevation of privilege vulnerability in GE HealthCare EchoPAC products
AplazadaAlta (7.6)0.34%—Gehealthcare EchopacAI14/5/202417/6/2026
Insufficiently protected credentials in GE HealthCare EchoPAC products
AplazadaMedia (6.8)0.34%—Gehealthcare EchopacAI14/5/202417/6/2026
Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products
AplazadaCrítica (9.6)0.35%—Gehealthcare EchopacAI14/5/202417/6/2026
Weak account password in GE HealthCare EchoPAC products
AplazadaMedia (5.7)0.22%—Gehealthcare EchopacAI14/5/202417/6/2026
Vulnerable data in transit in GE HealthCare EchoPAC products
AplazadaAlta (7.7)0.28%—Gehealthcare Common Service DesktopAI14/5/202417/6/2026
Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component
AplazadaMedia (6.2)0.28%—Gehealthcare Common Service DesktopAI14/5/202417/6/2026
Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component
AplazadaAlta (8.4)0.84%—Gehealthcare Ultrasound DevicesAI14/5/202417/6/2026
OS command injection vulnerabilities in GE HealthCare ultrasound devices
AplazadaAlta (7.4)0.20%—Gehealthcare UltrasoundAI14/5/202417/6/2026
Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices
ModificadaMedia (5.4)0.55%—Caehealthcare Learningspace Enterprise23/11/202217/6/2026
CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup.
ModificadaAlta (8.8)2.0%—Librehealth EHR9/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access.
ModificadaMedia (6.1)0.90%—Librehealth EHR8/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS.
ModificadaMedia (6.1)0.97%—Librehealth EHR7/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS.
ModificadaMedia (6.1)1.0%—Librehealth EHR6/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS.
ModificadaMedia (6.1)0.97%—Librehealth EHR6/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS.
ModificadaMedia (6.1)0.97%—Librehealth EHR6/6/202217/6/2026
Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username.
ModificadaMedia (6.1)0.97%—Librehealth EHR6/6/202217/6/2026
LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS.
ModificadaMedia (5.4)0.87%—Librehealth EHR5/5/202217/6/2026
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities.
ModificadaMedia (5.4)0.87%—Librehealth EHR5/5/202217/6/2026
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities.
ModificadaAlta (8.8)1.5%—Librehealth EHR5/5/202217/6/2026
In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection.
ModificadaAlta (7.8)0.34%—CA Ehealth Performance Manager26/3/202117/6/2026
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the script code will be executed as the ehealth user. NOTE: This vulnerability only affects products that are no longer…
ModificadaAlta (8.8)0.41%—CA Ehealth Performance Manager26/3/202117/6/2026
CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a malicious library in the writable RPATH, to be dynamically linked when the FtpCollector executable is run. The code in the…
ModificadaAlta (7.5)1.4%—Broadcom Ehealth26/3/202117/6/2026
CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only…
ModificadaMedia (5.4)0.74%—CA Ehealth Performance Manager26/3/202117/6/2026
CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and perform a Reflected Cross-Site Scripting attack against the platform users. The…