Celk develops Celk Saúde, a health-management application that exhibits a narrowly scoped vulnerability profile centered on web-application input-handling weaknesses, including cross-site scripting and observable response discrepancies. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Celk over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-48761HIGH Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter. | Jan 29, 2025 | 8.8 | 23 | NO | NO |
CVE-2024-51182MEDIUM HTML Injection vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary HTML code via the "erro" parameter. | Jan 29, 2025 | 6.1 | 18 | NO | NO |
CVE-2024-55198MEDIUM User Enumeration via Discrepancies in Error Messages in the Celk Sistemas Celk Saude v.3.1.252.1 password recovery functionality which allows a remote attacker to enumerate users t | Mar 13, 2025 | 5.3 | 17 | NO | NO |
CVE-2024-55199MEDIUM A Stored Cross Site Scripting (XSS) vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to store JavaScript code inside a PDF file through the file uploa | Mar 10, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Celk.
Media articles that mention a CVE ID that affects a product developed by Celk — matched by CVE ID, not by vendor name.