Cgm
25 CVEs tracked since 2025. Since Aug 2025, none of them reached CISA KEV.
Cgm CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-08 | 17 | 0 |
| 2025-09 | null or fewer | |
| 2025-10 | null or fewer | |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | null or fewer | |
| 2026-02 | null or fewer | |
| 2026-03 | 8 | 0 |
Products
The products that kept showing up in Cgm's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Cgm.
- CVE-2025-58406Lack of HTTP Response Headers—
- CVE-2025-58405Lack of protection mechanisms against Clickjacking attacks—
- CVE-2025-58402Insecure Direct Object Reference Message ID—
- CVE-2025-30062SQL injection in CheckUnitCodeAndKey.pl—
- CVE-2025-30044RCE on uhcapache user permissions—
- CVE-2025-30042Session generation possible with certificate number only—
- CVE-2025-30035Lack of API authentication allowing session generation for any user—
- CVE-2025-10350SQL injection in CGM NETRAAD—
- CVE-2025-30064Possibility to generate a session for any user via the "ex:action" parameter after obtaining access to the JWT key—
- CVE-2025-30063Excessive permissions on configuration files containing database logins and passwords—
- CVE-2025-30061SQL injection in utils/Reporter/OpenReportWindow.pl via the UserID parameter—
- CVE-2025-30060SQL injection in ReturnUserUnitsXML.pl via the UserID parameter—
- CVE-2025-30059Authenticated SQL injection in PrepareCDExportJSON.pl—
- CVE-2025-30058SQL injection in getPatientIdentifier function of PatientService.pl—
- CVE-2025-30057Authenticated RCE with uhcapache privileges in ConvertToPDF—
The record
- Peak rank
- #54 in Aug 2025
- Busiest month shown
- Aug 2025, 17 CVEs
- Months with a KEV entry
- 0 since Aug 2025
- Monthly snapshots
- 2 since 2025