Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Santesoft

First CVE: Feb 18, 2022Active for: 4 yearsTotal CVEs: 46
55.1
VTI Score
TOP TARGET

Santesoft develops a focused suite of medical imaging and DICOM-handling products, including viewer, PACS server, and editor applications that serve healthcare providers and imaging workflows. Despite a narrow product portfolio, the vendor occupies a prominent position in the clinical IT landscape where DICOM processing is foundational, and its vulnerability disclosures carry meaningful consequence across imaging infrastructure. The exposure recurs through memory-safety and path-traversal weakness classes—out-of-bounds writes and reads, use-after-free conditions, and pathname validation issues—that reflect the complexity of parsing untrusted medical image formats and managing buffer operations in native code. A meaningful share of vulnerabilities reach serious severity, warranting close attention to patch cycles for systems handling sensitive patient imaging data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
46
Total CVEs
More Total CVEs than 98% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Santesoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 18, 2022
4 years ago
Most Recent CVE
Feb 20, 2026
154 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (46 CVEs).

46 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-2264HIGH
A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk d
Mar 13, 20257.567NOYES
CVE-2022-2272CRITICAL
This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authentication is not required to exploit this vulnerabili
Aug 3, 20229.832NONO
CVE-2025-2263CRITICAL
During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the username and password. A fixed 0x80-byte stack-based buffer i
Mar 13, 20259.830NONO
CVE-2024-1863CRITICAL
Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations o
Apr 1, 20249.827NONO
CVE-2025-54156HIGH
The Sante PACS Server Web Portal sends credential information without encryption.
Aug 18, 20257.526NONO
CVE-2025-53948HIGH
The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application would require a man
Aug 18, 20257.526NONO
CVE-2026-2034HIGH
Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal
Feb 20, 20267.825NONO
CVE-2023-34295HIGH
Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in
May 3, 20248.825NONO
CVE-2023-32134HIGH
Sante DICOM Viewer Pro DCM File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install
May 3, 20248.825NONO
CVE-2023-32133HIGH
Sante DICOM Viewer Pro J2K File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in
May 3, 20248.825NONO
View all 46 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products46 CVEs
26%
65%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local20 (43.5%)
Network26 (56.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (32.6%)
Unknown0 (0.0%)
Required31 (67.4%)
Privileges Required
Low5 (10.9%)
High0 (0.0%)
None41 (89.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (46 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
2.2% of CVEs· 97th percentile
Nuclei
1 CVE
2.2% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Santesoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Santesoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Santesoft's Products

View all 3 CNAs →

Top CWEs