Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
288 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.49% | — | Phpgurukul Hospital Management System | 21/10/2022 | 17/6/2026 | PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php. | |
| Modificada | Media (5.4) | 0.49% | — | Phpgurukul Hospital Management System | 21/10/2022 | 17/6/2026 | PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php. | |
| Modificada | Crítica (9.8) | 0.78% | — | Hospital Management System Mini-project Project Hospital Management System Mini-project | 29/9/2022 | 17/6/2026 | hms-staff.php in Projectworlds Hospital Management System Mini-Project through 2018-06-17 allows SQL injection via the type parameter. | |
| Modificada | Crítica (9.8) | 6.1% | 💥 Exploit | Hospital Management System Project Hospital Management System | 13/9/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page. | |
| Modificada | Alta (7.2) | 4.6% | 💥 Exploit | Hospital Management System Project Hospital Management System | 20/7/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Hospital Management System Project Hospital Management System | 1/7/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orders.php. | |
| Modificada | Crítica (9.8) | 7.7% | 💥 Exploit | Hospital Management System Project Hospital Management System | 1/7/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Hospital Management System Project Hospital Management System | 1/7/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.php. | |
| Modificada | Crítica (9.8) | 2.2% | — | Hospital Management System Project Hospital Management System | 2/6/2022 | 17/6/2026 | A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database. | |
| Modificada | Crítica (9.8) | 1.6% | — | Hospital Management System Project Hospital Management System | 26/5/2022 | 17/6/2026 | In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks. | |
| Modificada | Alta (7.5) | 1.8% | — | Hospital Management System Project Hospital Management System | 16/5/2022 | 17/6/2026 | In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection. | |
| Modificada | Crítica (9.8) | 19% | — | Hospital Management System Project Hospital Management System | 16/5/2022 | 17/6/2026 | In HMS 1.0 when requesting appointment.php through POST, multiple parameters can lead to a SQL injection vulnerability. | |
| Modificada | Crítica (9.8) | 1.6% | — | Hospital Management System Project Hospital Management System | 15/5/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewtreatmentrecord.php. | |
| Modificada | Crítica (9.8) | 1.7% | — | Hospital Management System Project Hospital Management System | 11/5/2022 | 17/6/2026 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php. | |
| Modificada | Crítica (9.8) | 1.9% | — | Hospital Management System Project Hospital Management System | 11/5/2022 | 17/6/2026 | Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Hospital Management System Project Hospital Management System | 4/5/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the patient_contact parameter in patientsearch.php. | |
| Modificada | Crítica (9.8) | 3.0% | 💥 PoC | Hospital Management System Project Hospital Management System | 3/5/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the adminname parameter in admin.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Hospital Management System Project Hospital Management System | 26/4/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the component room.php. | |
| Modificada | Crítica (9.1) | 1.4% | — | Hospital Management System Project Hospital Management System | 31/3/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password. | |
| Modificada | Crítica (9.8) | 1.9% | — | Hospital Management System Project Hospital Management System | 31/3/2022 | 17/6/2026 | Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php. To exploit, an attacker can upload any PHP file, and then execute it. | |
| Modificada | Media (5.3) | 0.68% | — | Projectworlds Hospital Management System IN PHP | 16/3/2022 | 17/6/2026 | An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patients without restriction via add_patient.php. | |
| Modificada | Media (6.1) | 0.80% | — | Hospital Management System Project Hospital Management System | 15/3/2022 | 17/6/2026 | HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Hospital Management System Project Hospital Management System | 15/3/2022 | 17/6/2026 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php. | |
| Modificada | Alta (7.5) | 1.5% | — | Hospital Management System Project Hospital Management System | 15/3/2022 | 17/6/2026 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in appointment.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Hospital Management System Project Hospital Management System | 15/3/2022 | 17/6/2026 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in department.php. |