VendorsSantesoftsante_pacs_serverall versions
Vulnerabilities

Santesoft Sante PACS Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2022-2272
This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of calls to the login endpoint. When parsing the username element, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17331.
Published 2022-08-03 · Modified
9.8EPSS 0.027
CVE-2024-1863
Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability
Published 2024-04-01 · Analyzed
9.8EPSS 0.011
CVE-2023-51637
Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability
Published 2024-05-22 · Analyzed
9.8EPSS 0.010
CVE-2025-2263
Santesoft Sante PACS Server Stack-based Buffer Overflow
Published 2025-03-13 · Analyzed
9.8EPSS 0.009
CVE-2025-54156
Santesoft Sante PACS Server Cleartext Transmission of Sensitive Information
Published 2025-08-18 · Analyzed
9.1EPSS 0.002
CVE-2025-53948
Santesoft Sante PACS Server Double Free
Published 2025-08-18 · Analyzed
8.7EPSS 0.007
CVE-2025-0574
Sante PACS Server URL path Memory Corruption Denial-of-Service Vulnerability
Published 2025-01-30 · Analyzed
8.2EPSS 0.009
CVE-2025-2264
Santesoft Sante PACS Server Path Traversal Information Disclosure
Published 2025-03-13 · Analyzed
7.5EPSS 0.348
CVE-2025-0568
Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability
Published 2025-01-30 · Analyzed
7.5EPSS 0.010
CVE-2025-0569
Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability
Published 2025-01-30 · Analyzed
7.5EPSS 0.010
CVE-2025-0570
Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability
Published 2025-01-30 · Analyzed
6.5EPSS 0.010
CVE-2025-0571
Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability
Published 2025-01-30 · Analyzed
6.5EPSS 0.010
CVE-2025-54759
Santesoft Sante PACS Server Cross-site Scripting
Published 2025-08-18 · Analyzed
6.1EPSS 0.002
CVE-2025-54862
Santesoft Sante PACS Server Cross-site Scripting
Published 2025-08-18 · Analyzed
5.4EPSS 0.002
CVE-2025-0573
Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability
Published 2025-01-30 · Analyzed
5.3EPSS 0.019
CVE-2025-0572
Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability
Published 2025-01-30 · Analyzed
4.3EPSS 0.016