📦 Sante Pacs Server

by Santesoft

🔍 What is Sante Pacs Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-2263

CRITICAL CVSS 9.8 Mar 13, 2025

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on Sante PACS Server systems by exploiting a stack-based buffer overflow during login. Attackers can send specially...

CVE-2023-51637

CRITICAL CVSS 9.8 May 22, 2024

This is a critical SQL injection vulnerability in Sante PACS Server PG that allows unauthenticated remote attackers to execute arbitrary code. Attackers can exploit the DICOM service on port 11122 by ...

CVE-2024-1863

CRITICAL CVSS 9.8 Apr 1, 2024

This is a critical SQL injection vulnerability in Sante PACS Server's token endpoint that allows unauthenticated remote attackers to execute arbitrary code. Attackers can exploit this by sending speci...

CVE-2025-53948

HIGH CVSS 7.5 Aug 18, 2025

CVE-2025-53948 is a denial-of-service vulnerability in Sante PACS Server where a remote attacker can crash the main thread by sending a specially crafted HL7 message. This affects all Sante PACS Serve...

CVE-2025-0574

HIGH CVSS 7.5 Jan 30, 2025

CVE-2025-0574 is a memory corruption vulnerability in Sante PACS Server's URL parsing that allows unauthenticated remote attackers to cause denial-of-service conditions. The flaw exists due to imprope...

CVE-2025-0568

HIGH CVSS 7.5 Jan 30, 2025

This vulnerability allows remote attackers to cause denial-of-service on Sante PACS Server by sending specially crafted DCM files. Authentication is not required, making any internet-facing installati...

CVE-2025-0569

HIGH CVSS 7.5 Jan 30, 2025

This vulnerability allows remote attackers to cause denial-of-service on Sante PACS Server by sending specially crafted DCM files. The memory corruption occurs during DCM file parsing without requirin...

CVE-2025-54759

MEDIUM CVSS 6.1 Aug 18, 2025

Sante PACS Server contains a stored cross-site scripting vulnerability that allows attackers to inject malicious HTML code. When exploited, this can redirect users to malicious websites and steal sess...

CVE-2025-54862

MEDIUM CVSS 5.4 Aug 18, 2025

Sante PACS Server web portal contains a stored cross-site scripting vulnerability that allows attackers to inject malicious HTML. When exploited, this can redirect users to malicious websites and stea...

CVE-2025-0572

MEDIUM CVSS 4.3 Jan 30, 2025

This vulnerability allows authenticated remote attackers to write arbitrary files to the Sante PACS Server filesystem via directory traversal in DCM file parsing. Attackers can create files anywhere t...

CVE-2025-0570

MEDIUM CVSS 6.5 Jan 30, 2025

This vulnerability allows authenticated remote attackers to cause denial-of-service conditions on Sante PACS Server installations by sending specially crafted DCM files. The memory corruption occurs d...