Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
288 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.49% | — | Hospital Management System Project Hospital Management System | 28/2/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the demail parameter at /admin-panel1.php. | |
| Modificada | Media (5.4) | 0.49% | — | Hospital Management System Project Hospital Management System | 28/2/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the dpassword parameter at /admin-panel1.php. | |
| Modificada | Media (5.4) | 0.49% | — | Hospital Management System Project Hospital Management System | 28/2/2022 | 17/6/2026 | Hospital Management System v1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Doctor parameter at /admin-panel1.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Hospital Management System Project Hospital Management System | 24/2/2022 | 17/6/2026 | HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php. | |
| Modificada | Crítica (9.1) | 1.6% | — | Hospital Management System Project Hospital Management System | 24/2/2022 | 17/6/2026 | An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files. | |
| Modificada | Alta (7.5) | 1.7% | — | Phpgurukul Hospital Management System | 15/2/2022 | 17/6/2026 | Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php. | |
| Modificada | Alta (7.5) | 1.7% | — | Phpgurukul Hospital Management System | 10/2/2022 | 17/6/2026 | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters. | |
| Modificada | Crítica (9.8) | 8.2% | 💥 Exploit | Phpgurukul Hospital Management System | 31/1/2022 | 17/6/2026 | Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter. | |
| Modificada | Crítica (9.8) | 1.1% | — | Projectworlds Hospital Management System IN PHP | 22/12/2021 | 17/6/2026 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php. | |
| Modificada | Alta (8.8) | 2.0% | — | Projectworlds Hospital Management System IN PHP | 22/12/2021 | 17/6/2026 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server. | |
| Modificada | Crítica (9.8) | 1.1% | — | Projectworlds Hospital Management System IN PHP | 22/12/2021 | 17/6/2026 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Projectworlds Hospital Management System IN PHP | 22/12/2021 | 17/6/2026 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php. | |
| Modificada | Media (6.1) | 0.91% | 💥 Exploit | Phpgurukul Hospital Management System | 5/11/2021 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in admin/betweendates-detailsreports.php. | |
| Modificada | Media (6.1) | 0.88% | — | Hospital Management System Project Hospital Management System | 16/8/2021 | 17/6/2026 | Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php. | |
| Modificada | Media (6.1) | 0.72% | — | Hospital Management System Project Hospital Management System | 16/8/2021 | 17/6/2026 | Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php. | |
| Modificada | Media (5.3) | 0.98% | — | Hospital Management System Project Hospital Management System | 16/8/2021 | 17/6/2026 | Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php. | |
| Modificada | Crítica (9.8) | 1.8% | — | Hospital Management System Project Hospital Management System | 16/8/2021 | 17/6/2026 | SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php. | |
| Modificada | Alta (7.5) | 2.1% | — | Phpgurukul Hospital Management System | 22/6/2021 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information. | |
| Modificada | Alta (7.5) | 2.2% | — | Phpgurukul Hospital Management System | 22/6/2021 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. | |
| Modificada | Alta (7.5) | 2.2% | — | Phpgurukul Hospital Management System | 22/6/2021 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. | |
| Modificada | Alta (7.5) | 2.2% | — | Phpgurukul Hospital Management System | 22/6/2021 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. | |
| Modificada | Alta (7.5) | 2.2% | — | Phpgurukul Hospital Management System | 22/6/2021 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. | |
| Modificada | Alta (7.5) | 2.2% | — | Phpgurukul Hospital Management System | 22/6/2021 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. | |
| Modificada | Alta (7.5) | 2.2% | — | Phpgurukul Hospital Management System | 22/6/2021 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. | |
| Modificada | Alta (7.5) | 2.2% | — | Phpgurukul Hospital Management System | 22/6/2021 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. |