Known vulnerabilities in Dario Application Database and Internet-based Server Infrastructure
Vendor:
DarioHealth Corp
Software CPE:
cpe:2.3:a:dariohealth_corp:dario_application_database_and_internet-based_server_infrastructure:*:*:*:*:*:*:*:*
Website:
https://www.dariohealth.com/
Total vulnerabilities:
7
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (7)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU105347 - Exposure of sensitive information to an unauthorized actor CVE-2025-24316 |
CWE-200 | Medium | - | 05.03.2025 |
SB2025030537 |
||
| #VU105346 - Sensitive Cookie Without 'HttpOnly' Flag CVE-2025-24318 |
CWE-1004 | Medium | - | 05.03.2025 |
SB2025030537 |
||
| #VU105345 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-20049 |
CWE-79 | Low | - | 05.03.2025 |
SB2025030537 |
||
| #VU105344 - Cleartext Transmission of Sensitive Information CVE-2025-24849 |
CWE-319 | Medium | - | 05.03.2025 |
SB2025030537 |
||
| #VU105342 - Storage of Sensitive Data in a Mechanism without Access Control CVE-2025-24843 |
CWE-921 | Low | - | 05.03.2025 |
SB2025030537 |
||
| #VU105341 - Improper Output Neutralization for Logs CVE-2025-23405 |
CWE-117 | Medium | - | 05.03.2025 |
SB2025030537 |
||
| #VU105339 - Exposure of sensitive information to an unauthorized actor CVE-2025-20060 |
CWE-200 | High | - | 05.03.2025 |
SB2025030537 |