Pacs Server

Vendor:

First CVE: May 22, 2025 · Active for 1 year

38
Total CVEs
More Total CVEs than 98% of tracked products
19.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pacs Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 22, 2025
14 months ago
Most Recent CVE
Jan 20, 2026
189 days ago

CVE Severity & Scoring

Pacs Server38 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local3 (7.9%)
Network34 (89.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (2.6%)
Attack Complexity
Low38 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (15.8%)
Unknown0 (0.0%)
Required32 (84.2%)
Privileges Required
Low14 (36.8%)
High0 (0.0%)
None24 (63.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A privilege escalation vulnerability exists in the login.php functionality of meddream MedDream PACS Premium 7.3.3.840. A specially crafted .php file can lead to elevated capabilit
Jul 28, 20259.831NONO
An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A specially crafted HTTP request can lead to an arbitrary file
Jan 20, 20268.130NONO
An incorrect default permissions vulnerability exists in the CServerSettings::SetRegistryValues functionality of MedDream PACS Premium 7.3.3.840. A specially crafted application c
Jul 28, 20259.830NONO
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff
May 22, 20259.827NONO
A server-side request forgery vulnerability exists in the cecho.php functionality of MedDream PACS Premium 7.3.5.860. A specially crafted HTTP request can lead to SSRF. An attacker
Jul 28, 20257.526NONO
MedDream PACS Server DICOM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on aff
May 22, 20257.825NONO
Multiple reflected cross-site scripting (xss) vulnerabilities exist in the config.php functionality of MedDream PACS Premium 7.3.6.870. Specially crafted malicious URLs can lead to
Jan 20, 20266.124NONO
A reflected cross-site scripting (xss) vulnerability exists in the modifyRoute functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to arbit
Jan 20, 20266.124NONO
A reflected cross-site scripting (xss) vulnerability exists in the modifyAnonymize functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to a
Jan 20, 20266.124NONO
A reflected cross-site scripting (xss) vulnerability exists in the modifyTranscript functionality of MedDream PACS Premium 7.3.6.870. A specially crafted malicious URL can lead to
Jan 20, 20266.124NONO

Exploit Exposure

Signals from CVEs in this product scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (38 CVEs).

Media Mentions

Signals from CVEs in this product scope (38 CVEs).

Top CNAs Publishing CVEs For Pacs Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.3.6.870295.90.3%00
7.3.5.86026.83.0%00
7.3.2.84038.70.4%00