Product
santesoft sante pacs server
16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-54862
CVE-2025-54759
CVE-2025-54156
CVE-2025-53948
CVE-2025-2264
CVE-2025-2263
CVE-2025-0574
CVE-2025-0573
CVE-2025-0572
CVE-2025-0571
CVE-2025-0570
CVE-2025-0569
CVE-2025-0568
CVE-2023-51637
CVE-2024-1863
CVE-2022-2272
< 4.2.3
Sante PACS Server web portal is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecti
< 4.2.3
Sante PACS Server is vulnerable to stored cross-site scripting. An attacker could inject malicious HTML codes redirecting a user t
< 4.2.3
The Sante PACS Server Web Portal sends credential information without encryption.
< 4.2.3
The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-serv
all versions
A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can ex
all versions
During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the username an
< 4.0.10
Sante PACS Server URL path Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create
< 4.0.10
Sante PACS Server DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows remote attack
< 4.0.10
Sante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write Vulnerability. This vulnerability allows re
< 4.0.10
Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote
< 4.0.10
Sante PACS Server Web Portal DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote
< 4.0.10
Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers t
< 4.0.10
Sante PACS Server DCM File Parsing Memory Corruption Denial-of-Service Vulnerability. This vulnerability allows remote attackers t
< 3.3.7
Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers t
< 3.3.6
Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to
all versions
This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authenti