📦 Pacs Server

by Meddream

🔍 What is Pacs Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-53912

CRITICAL CVSS 9.6 Jan 20, 2026

This vulnerability allows attackers to read arbitrary files on MedDream PACS Premium servers by sending specially crafted HTTP requests to the encapsulatedDoc functionality. It affects MedDream PACS P...

CVE-2025-26469

CRITICAL CVSS 9.3 Jul 28, 2025

This vulnerability allows attackers to decrypt credentials stored in registry keys due to incorrect default permissions in MedDream PACS Premium. Attackers can execute malicious scripts to exploit thi...

CVE-2025-3484

CRITICAL CVSS 9.8 May 22, 2025

This critical vulnerability in MedDream PACS Server allows remote attackers to execute arbitrary code without authentication by sending specially crafted DICOM files. The stack-based buffer overflow o...

CVE-2025-3481

HIGH CVSS 7.8 May 22, 2025

This vulnerability allows remote attackers to execute arbitrary code on MedDream PACS Server installations without authentication by sending specially crafted DICOM files. The stack-based buffer overf...

CVE-2025-3483

HIGH CVSS 7.8 May 22, 2025

This vulnerability allows remote attackers to execute arbitrary code on MedDream PACS Server installations without authentication by sending specially crafted DICOM files. The flaw exists in DICOM fil...

CVE-2025-58093

MEDIUM CVSS 6.1 Jan 20, 2026

Multiple reflected cross-site scripting vulnerabilities in MedDream PACS Premium allow attackers to execute arbitrary JavaScript code via specially crafted URLs targeting the phpdir parameter. This af...

CVE-2025-58094

MEDIUM CVSS 6.1 Jan 20, 2026

This vulnerability allows attackers to execute arbitrary JavaScript code in users' browsers through specially crafted URLs targeting the config.php functionality in MedDream PACS Premium. It affects h...

CVE-2025-58095

MEDIUM CVSS 6.1 Jan 20, 2026

This vulnerability allows attackers to execute arbitrary JavaScript code in users' browsers by tricking them into clicking specially crafted malicious URLs. It affects MedDream PACS Premium installati...

CVE-2025-58087

MEDIUM CVSS 6.1 Jan 20, 2026

This vulnerability allows attackers to execute arbitrary JavaScript code in users' browsers by tricking them into clicking specially crafted malicious URLs. It affects MedDream PACS Premium users thro...

CVE-2025-58088

MEDIUM CVSS 6.1 Jan 20, 2026

This CVE describes reflected cross-site scripting vulnerabilities in MedDream PACS Premium's config.php functionality. Attackers can craft malicious URLs containing JavaScript payloads that execute wh...

CVE-2025-58089

MEDIUM CVSS 6.1 Jan 20, 2026

This vulnerability allows attackers to execute arbitrary JavaScript code in users' browsers by tricking them into clicking specially crafted malicious URLs targeting the config.php file in MedDream PA...

CVE-2025-58090

MEDIUM CVSS 6.1 Jan 20, 2026

MedDream PACS Premium 7.3.6.870 contains reflected cross-site scripting vulnerabilities in the config.php uploaddir parameter. Attackers can craft malicious URLs that execute arbitrary JavaScript in v...

CVE-2025-58091

MEDIUM CVSS 6.1 Jan 20, 2026

Multiple reflected cross-site scripting vulnerabilities in MedDream PACS Premium allow attackers to execute arbitrary JavaScript code via specially crafted URLs targeting the thumbnaildir parameter. T...

CVE-2025-58092

MEDIUM CVSS 6.1 Jan 20, 2026

This vulnerability allows attackers to execute arbitrary JavaScript code in users' browsers by tricking them into clicking specially crafted malicious URLs targeting the config.php functionality in Me...

CVE-2025-57786

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking a malicious URL. This affects MedDream PAC...

CVE-2025-57787

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting (XSS) vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking a malicious URL. This affects health...

CVE-2025-57881

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium's modifyEmail functionality allows attackers to execute arbitrary JavaScript by tricking users into clicking malicious URLs. Thi...

CVE-2025-58080

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. This affects healthcare or...

CVE-2025-54778

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. This affects healthcare or...

CVE-2025-54814

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. This affects healthcare or...

CVE-2025-54817

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. This affects MedDream PACS...

CVE-2025-54852

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking a malicious URL. This affects healthcare o...

CVE-2025-54853

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. This affects healthcare or...

CVE-2025-54861

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. This affects healthcare or...

CVE-2025-55071

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. This affects healthcare or...

CVE-2025-54157

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking a malicious URL. This affects healthcare o...

CVE-2025-54495

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking specially crafted malicious URLs. This aff...

CVE-2025-53707

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. This affects healthcare or...

CVE-2025-53854

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. This affects healthcare or...

CVE-2025-53516

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking a malicious URL. This affects healthcare o...

CVE-2025-44000

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. This affects healthcare or...

CVE-2025-46270

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. This affects healthcare or...

CVE-2025-36556

MEDIUM CVSS 6.1 Jan 20, 2026

A reflected cross-site scripting vulnerability in MedDream PACS Premium's ldapUser functionality allows attackers to execute arbitrary JavaScript code by tricking users into clicking malicious URLs. T...

CVE-2025-24485

MEDIUM CVSS 5.8 Jul 28, 2025

An unauthenticated server-side request forgery vulnerability in MedDream PACS Premium allows attackers to make arbitrary HTTP requests from the vulnerable server. This could lead to internal network s...