Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
79 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.7) | 0.29% | — | Gehealthcare ELI 380AIGehealthcare ELI 280AIGehealthcare Bur280AIGehealthcare Mlbur 280AI+5 | 7/2/2025 | 17/6/2026 | An improper access control vulnerability may allow privilege escalation.This issue affects: Versions 2.2.0 and prior. | |
| Aplazada | Alta (8.4) | 0.29% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Elevation of privilege vulnerability in GE HealthCare EchoPAC products | |
| Aplazada | Alta (7.6) | 0.34% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Insufficiently protected credentials in GE HealthCare EchoPAC products | |
| Aplazada | Media (6.8) | 0.34% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products | |
| Aplazada | Crítica (9.6) | 0.35% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Weak account password in GE HealthCare EchoPAC products | |
| Aplazada | Media (5.7) | 0.22% | — | Gehealthcare EchopacAI | 14/5/2024 | 17/6/2026 | Vulnerable data in transit in GE HealthCare EchoPAC products | |
| Aplazada | Alta (7.7) | 0.28% | — | Gehealthcare Common Service DesktopAI | 14/5/2024 | 17/6/2026 | Path traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device component | |
| Aplazada | Media (6.2) | 0.28% | — | Gehealthcare Common Service DesktopAI | 14/5/2024 | 17/6/2026 | Path traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device component | |
| Aplazada | Alta (8.4) | 0.84% | — | Gehealthcare Ultrasound DevicesAI | 14/5/2024 | 17/6/2026 | OS command injection vulnerabilities in GE HealthCare ultrasound devices | |
| Aplazada | Alta (7.4) | 0.20% | — | Gehealthcare UltrasoundAI | 14/5/2024 | 17/6/2026 | Elevation of privileges via misconfigured access control list in GE HealthCare ultrasound devices | |
| Modificada | Media (5.4) | 0.55% | — | Caehealthcare Learningspace Enterprise | 23/11/2022 | 17/6/2026 | CAE LearningSpace Enterprise (with Intuity License) image 267r patch 639 allows DOM XSS, related to ontouchmove and onpointerup. | |
| Modificada | Alta (8.8) | 2.0% | — | Librehealth EHR | 9/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows incorrect interface/super/manage_site_files.php access. | |
| Modificada | Media (6.1) | 0.90% | — | Librehealth EHR | 8/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows interface/main/finder/finder_navigation.php patient XSS. | |
| Modificada | Media (6.1) | 0.97% | — | Librehealth EHR | 7/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php return_page XSS. | |
| Modificada | Media (6.1) | 1.0% | — | Librehealth EHR | 6/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php action XSS. | |
| Modificada | Media (6.1) | 0.97% | — | Librehealth EHR | 6/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows interface/orders/patient_match_dialog.php key XSS. | |
| Modificada | Media (6.1) | 0.97% | — | Librehealth EHR | 6/6/2022 | 17/6/2026 | Cross Site scripting (XSS) vulnerability inLibreHealth EHR Base 2.0.0 via interface/usergroup/usergroup_admin_add.php Username. | |
| Modificada | Media (6.1) | 0.97% | — | Librehealth EHR | 6/6/2022 | 17/6/2026 | LibreHealth EHR Base 2.0.0 allows gacl/admin/acl_admin.php acl_id XSS. | |
| Modificada | Media (5.4) | 0.87% | — | Librehealth EHR | 5/5/2022 | 17/6/2026 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters formseq and formid in interface\orders\find_order_popup.php leads to multiple cross-site scripting (XSS) vulnerabilities. | |
| Modificada | Media (5.4) | 0.87% | — | Librehealth EHR | 5/5/2022 | 17/6/2026 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameters debug and InsId in interface\billing\sl_eob_process.php leads to multiple cross-site scripting (XSS) vulnerabilities. | |
| Modificada | Alta (8.8) | 1.5% | — | Librehealth EHR | 5/5/2022 | 17/6/2026 | In LibreHealth EHR 2.0.0, lack of sanitization of the GET parameter payment_id in interface\billing\new_payment.php via interface\billing\payment_master.inc.php leads to SQL injection. | |
| Modificada | Alta (7.8) | 0.34% | — | CA Ehealth Performance Manager | 26/3/2021 | 17/6/2026 | CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a setuid (and/or setgid) file. When a component is run as an argument of the runpicEhealth executable, the script code will be executed as the ehealth user. NOTE: This vulnerability only affects products that are no longer… | |
| Modificada | Alta (8.8) | 0.41% | — | CA Ehealth Performance Manager | 26/3/2021 | 17/6/2026 | CA eHealth Performance Manager through 6.3.2.12 is affected by Privilege Escalation via a Dynamically Linked Shared Object Library. To exploit the vulnerability, the ehealth user must create a malicious library in the writable RPATH, to be dynamically linked when the FtpCollector executable is run. The code in the… | |
| Modificada | Alta (7.5) | 1.4% | — | Broadcom Ehealth | 26/3/2021 | 17/6/2026 | CA eHealth Performance Manager through 6.3.2.12 is affected by Improper Restriction of Excessive Authentication Attempts. An attacker is able to perform an arbitrary number of /web/frames/ authentication attempts using different passwords, and eventually gain access to a targeted account, NOTE: This vulnerability only… | |
| Modificada | Media (5.4) | 0.74% | — | CA Ehealth Performance Manager | 26/3/2021 | 17/6/2026 | CA eHealth Performance Manager through 6.3.2.12 is affected by Cross Site Scripting (XSS). The impact is: An authenticated remote user is able to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and perform a Reflected Cross-Site Scripting attack against the platform users. The… |