Santesoft develops a focused suite of medical imaging and DICOM-handling products, including viewer, PACS server, and editor applications that serve healthcare providers and imaging workflows. Despite a narrow product portfolio, the vendor occupies a prominent position in the clinical IT landscape where DICOM processing is foundational, and its vulnerability disclosures carry meaningful consequence across imaging infrastructure. The exposure recurs through memory-safety and path-traversal weakness classes—out-of-bounds writes and reads, use-after-free conditions, and pathname validation issues—that reflect the complexity of parsing untrusted medical image formats and managing buffer operations in native code. A meaningful share of vulnerabilities reach serious severity, warranting close attention to patch cycles for systems handling sensitive patient imaging data. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Santesoft over time
Signals from CVEs in this vendor scope (46 CVEs).
46 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-2264HIGH A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk d | Mar 13, 2025 | 7.5 | 67 | NO | YES |
CVE-2022-2272CRITICAL This vulnerability allows remote attackers to bypass authentication on affected installations of Sante PACS Server 3.0.4. Authentication is not required to exploit this vulnerabili | Aug 3, 2022 | 9.8 | 32 | NO | NO |
CVE-2025-2263CRITICAL During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the username and password. A fixed 0x80-byte stack-based buffer i | Mar 13, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-1863CRITICAL Sante PACS Server Token Endpoint SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations o | Apr 1, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-54156HIGH The Sante PACS Server Web Portal sends credential information without encryption. | Aug 18, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-53948HIGH The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application would require a man | Aug 18, 2025 | 7.5 | 26 | NO | NO |
CVE-2026-2034HIGH Sante DICOM Viewer Pro DCM File Parsing Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal | Feb 20, 2026 | 7.8 | 25 | NO | NO |
CVE-2023-34295HIGH Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in | May 3, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-32134HIGH Sante DICOM Viewer Pro DCM File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install | May 3, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-32133HIGH Sante DICOM Viewer Pro J2K File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected in | May 3, 2024 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (46 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Santesoft.
Media articles that mention a CVE ID that affects a product developed by Santesoft — matched by CVE ID, not by vendor name.