Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

357 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.40%—Lenovo Health Android ApplicationAI10/9/202611/9/2026
A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the Chinese market, that could allow an attacker to access sensitive health-related information.
AnalizadaAlta (7.4)0.16%—Oracle Autonomous Health Framework18/8/202626/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework…
AnalizadaAlta (8.4)0.14%—Oracle Autonomous Health Framework18/8/202626/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes…
AnalizadaAlta (8.5)0.30%—Oracle Autonomous Health Framework18/8/202626/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Autonomous Health Framework.…
AnalizadaMedia (6.7)0.24%—Oracle Autonomous Health Framework18/8/202626/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Cluster Health Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware…
AnalizadaMedia (6.8)0.42%—Oracle Autonomous Health Framework18/8/202626/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where…
AnalizadaMedia (6.9)0.17%—Samsung Health10/8/202619/8/2026
Relative path traversal in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
AnalizadaMedia (6.9)0.13%—Samsung Health10/8/202619/8/2026
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
AnalizadaMedia (6.9)0.13%—Samsung Health10/8/202619/8/2026
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
Pendiente de análisisAlta (8.2)0.61%—Nasa Core Flight SystemAINasa Health AND SafetyAI30/7/202631/8/2026
An incomplete fix for CVE-2026-15352 in the NASA core Flight System (cFS) Health and Safety (HS) application leaves a separate NULL pointer dereference reachable in versions through 7.0.1. An attacker who can trigger the affected command under specific conditions could cause the HS application to crash, resulting in a…
AnalizadaMedia (6.3)0.14%—Oracle Autonomous Health Framework21/7/20266/8/2026
Vulnerability in Oracle Autonomous Health Framework (component: Developer triaging platform). Supported versions that are affected are 26.0.0, 26.1.0 and 26.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to…
Pendiente de análisisMedia (6.8)0.35%—Amazon Healthomics MCP ServerAI17/7/202620/7/2026
AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatics analyses at scale for clinical diagnostics, drug discovery, and agricultural research. Improper limitation of a pathname to a restricted directory in the linting tools…
Pendiente de análisisAlta (8.2)0.61%—Nasa Core Flight SystemAINasa Health AND SafetyAI16/7/202617/7/2026
A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segmentation fault when processing a routine Housekeeping Telemetry request, leading to denial of service.
Pendiente de análisisCrítica (9.2)0.39%—Amazon Healthlake-mcp-serverAI14/7/202615/7/2026
AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with AWS HealthLake FHIR datastores. A server-side request forgery in the pagination handling component in AWS awslabs.healthlake-mcp-server before 0.0.14 on all platforms might allow a…
AplazadaMedia (4.8)0.13%—Samsung HealthAI10/7/202610/7/2026
Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device information.
AplazadaAlta (8.1)0.35%—Luxmed Medicine & Healthcare DoctorAI17/6/202630/9/2026
Unauthenticated Local File Inclusion in LuxMed | Medicine & Healthcare Doctor WordPress Theme <= 1.2.2 versions.
AplazadaCrítica (9.2)0.66%—Spacelabs Healthcare SentinelAIMicrosoft IISAIMicrosoft DotnetAI2/6/202622/7/2026
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI…
AplazadaMedia (5.5)0.48%—Picotronica E-clinic Healthcare System EchsAI6/5/202617/6/2026
A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of the file /cdemos/echs/api/v2/ of the component Response Header Handler. Such manipulation leads to information disclosure. The attack may be performed from remote. The exploit has been disclosed to…
AplazadaMedia (5.5)0.47%—Picotronica E-clinic Healthcare System EchsAI6/5/202617/6/2026
A flaw has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. The impacted element is an unknown function of the file /cdemos/echs/priv/echs.js. This manipulation of the argument ADMIN_KEY causes hard-coded credentials. The attack is possible to be carried out remotely. The exploit has been published and…
AplazadaMedia (5.5)0.68%—Picotronica E-clinic Healthcare System EchsAI6/5/202617/6/2026
A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs/api/v2/patient-records of the component API Endpoint. The manipulation results in missing authentication. The attack can be executed remotely. The exploit is now public…
AnalizadaAlta (8.5)0.42%—Agilonhealth Minerva28/4/202617/6/2026
An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user with user modification privileges to escalate their privileges by sending an HTTP request with a manipulated 'identifier' field. Successful exploitation of this…
AnalizadaAlta (8.5)0.35%—Agilonhealth Minerva28/4/202617/6/2026
An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/minerva/moUser/show/'. If this vulnerability is successfully exploited, an authenticated user can access the data of other registered users simply by modifying the ID. This allows an attacker to obtain a…
AnalizadaCrítica (9.4)0.46%—Agilonhealth Minerva28/4/202617/6/2026
An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. This allows an authenticated user to modify the information of other registered users. Successful exploitation of this vulnerability allows an authenticated user to modify…
AplazadaBaja (1.1)0.13%—Albert Saglik Hizmetleri VE Ticaret Albert HealthAI16/3/202617/6/2026
A vulnerability was found in Albert Sağlık Hizmetleri ve Ticaret Albert Health up to 1.7.3 on Android. Affected is an unknown function of the file resources/assets/service-account.json of the component Google Cloud Service Account Key Handler. Performing a manipulation results in unprotected storage of credentials.…
AplazadaAlta (7.1)0.26%—Quanticalabs Medicenter - Health Medical ClinicAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Reflected XSS.This issue affects MediCenter - Health Medical Clinic: from n/a through <= 14.9.