Vulnerabilities
Summary — last 7 days
New vulnerabilities2,571▼ 304 vs. last week
Critical / high1,353▲ 102 vs. last week
New active exploitation (KEV)5▼ 7 vs. last week
Unscored (no CVSS)56▼ 472 vs. last week
107 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Analyzed | Critical (9.3) | 1.9% | — | Hyland Pacsgear | 7/1/2026 | 7/9/2026 | PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By exploiting the MarshalByRefObject object unmarshalling technique and implementing .NET WebClient class methods,… | |
| Analyzed | Critical (9.3) | 1.8% | — | Hyland Pacsgear | 7/1/2026 | 7/9/2026 | PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed .NET Remoting TCP service on port 22222 via PGImageExchQueue.exe without any authentication requirement. Attackers can chain the arbitrary… | |
| Deferred | High (8.7) | 0.78% | — | Softneta Meddream Pacs Server PremiumAI | 5/25/2026 | 7/24/2026 | Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers can send requests to nocache.php with encoded backslash sequences to traverse directories and access sensitive files… | |
| Deferred | High (8.8) | 0.30% | — | Meddream Pacs Server PremiumAI | 5/25/2026 | 7/23/2026 | MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the email parameter. Attackers can submit crafted POST requests to the userSignup.php endpoint with SQL payloads in the email field to… | |
| Awaiting Analysis | Medium (6.9) | 0.14% | — | Merge PacsAI | 4/29/2026 | 6/17/2026 | Merge PACS 7.0 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTML forms targeting the merge-viewer endpoint. Attackers can submit POST requests to /servlet/actions/merge-viewer/summary with login credentials to hijack user sessions and… | |
| Deferred | High (8.7) | 0.59% | — | Meddream Pacs ServerAI | 1/29/2026 | 6/17/2026 | MedDream PACS Server 6.8.3.751 contains an authenticated remote code execution vulnerability that allows authorized users to upload malicious PHP files. Attackers can exploit the uploadImage.php endpoint by authenticating and uploading a PHP shell to execute arbitrary system commands with elevated privileges. | |
| Analyzed | Medium (6.1) | 0.36% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the… | |
| Analyzed | Medium (6.1) | 0.27% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the… | |
| Analyzed | Medium (6.1) | 0.27% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the… | |
| Analyzed | Medium (6.1) | 0.27% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the… | |
| Analyzed | Medium (6.1) | 0.27% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the… | |
| Analyzed | Medium (6.1) | 0.27% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the… | |
| Analyzed | Medium (6.1) | 0.27% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the… | |
| Analyzed | Medium (6.1) | 0.27% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the… | |
| Analyzed | Medium (6.1) | 0.36% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger these vulnerabilities.This vulnerability affects the… | |
| Analyzed | Medium (5.4) | 0.35% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | A reflected cross-site scripting (xss) vulnerability exists in the modifyHL7App functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. | |
| Analyzed | Medium (5.4) | 0.35% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | A reflected cross-site scripting (xss) vulnerability exists in the modifyEmail functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. | |
| Analyzed | Medium (6.1) | 0.39% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | A reflected cross-site scripting (xss) vulnerability exists in the modifyRoute functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. | |
| Analyzed | Medium (5.4) | 0.35% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | A reflected cross-site scripting (xss) vulnerability exists in the notifynewstudy functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. | |
| Analyzed | Medium (6.1) | 0.39% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | A reflected cross-site scripting (xss) vulnerability exists in the modifyAnonymize functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. | |
| Analyzed | Medium (5.4) | 0.35% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | A reflected cross-site scripting (xss) vulnerability exists in the modifyCoercion functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. | |
| Analyzed | Medium (5.4) | 0.35% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | A reflected cross-site scripting (xss) vulnerability exists in the modifyUser functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. | |
| Analyzed | Medium (6.1) | 0.39% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | A reflected cross-site scripting (xss) vulnerability exists in the modifyAeTitle functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. | |
| Analyzed | Medium (5.4) | 0.35% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | A reflected cross-site scripting (xss) vulnerability exists in the autoPurge functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious url can lead to arbitrary javascript code execution. An attacker can provide a URL to a malicious website to trigger this vulnerability. | |
| Analyzed | Medium (5.4) | 0.35% | — | Meddream Pacs Server | 1/20/2026 | 6/17/2026 | A reflected cross-site scripting (xss) vulnerability exists in the modifyAutopurgeFilter functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability. |