Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

285 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.6%—Hospital Management System Project Hospital Management System24/2/202217/6/2026
HMS v1.0 was discovered to contain a SQL injection vulnerability via the component admin.php.
ModificadaCrítica (9.1)1.6%—Hospital Management System Project Hospital Management System24/2/202217/6/2026
An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify all PHP files.
ModificadaAlta (7.5)1.7%—Phpgurukul Hospital Management System15/2/202217/6/2026
Hospital Management System v4.0 was discovered to contain a blind SQL injection vulnerability via the register function in func2.php.
ModificadaAlta (7.5)1.7%—Phpgurukul Hospital Management System10/2/202217/6/2026
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/contact.php via the txtMsg parameters.
ModificadaCrítica (9.8)8.2%💥 ExploitPhpgurukul Hospital Management System31/1/202217/6/2026
Hospital Management System v4.0 was discovered to contain a SQL injection vulnerability in /Hospital-Management-System-master/func.php via the email parameter.
ModificadaCrítica (9.8)1.1%—Projectworlds Hospital Management System IN PHP22/12/202117/6/2026
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.
ModificadaAlta (8.8)2.0%—Projectworlds Hospital Management System IN PHP22/12/202117/6/2026
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server.
ModificadaCrítica (9.8)1.1%—Projectworlds Hospital Management System IN PHP22/12/202117/6/2026
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.
ModificadaCrítica (9.8)1.1%—Projectworlds Hospital Management System IN PHP22/12/202117/6/2026
Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.
ModificadaMedia (6.1)0.91%💥 ExploitPhpgurukul Hospital Management System5/11/202117/6/2026
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the (1) searchdata parameter in (a) doctor/search.php and (b) admin/patient-search.php, and the (2) fromdate and (3) todate parameters in admin/betweendates-detailsreports.php.
ModificadaMedia (6.1)0.88%—Hospital Management System Project Hospital Management System16/8/202117/6/2026
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through contact.php.
ModificadaMedia (6.1)0.72%—Hospital Management System Project Hospital Management System16/8/202117/6/2026
Persistent cross-site scripting (XSS) in Hospital Management System targeted towards web admin through prescribe.php.
ModificadaMedia (5.3)0.98%—Hospital Management System Project Hospital Management System16/8/202117/6/2026
Unauthenticated doctor entry deletion in Hospital Management System in admin-panel1.php.
ModificadaCrítica (9.8)1.8%—Hospital Management System Project Hospital Management System16/8/202117/6/2026
SQL Injection vulnerability in Hospital Management System due to lack of input validation in messearch.php.
ModificadaAlta (7.5)2.1%—Phpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a sensitive information disclosure vulnerability in multiple areas. Remote unauthenticated users can exploit the vulnerability to obtain user sensitive information.
ModificadaAlta (7.5)2.2%—Phpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\admin\betweendates-detailsreports.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
ModificadaAlta (7.5)2.2%—Phpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\book-appointment.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
ModificadaAlta (7.5)2.2%—Phpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\edit-profile.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
ModificadaAlta (7.5)2.2%—Phpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
ModificadaAlta (7.5)2.2%—Phpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\registration.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
ModificadaAlta (7.5)2.2%—Phpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\get_doctor.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
ModificadaAlta (7.5)2.2%—Phpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\appointment-history.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
ModificadaAlta (7.5)2.2%—Phpgurukul Hospital Management System22/6/20219/7/2026
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\change-emaild.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
ModificadaMedia (5.4)0.52%—Phpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a Persistent Cross-Site Scripting vulnerability in \hms\admin\appointment-history.php. Remote registered users can exploit the vulnerability to obtain user cookie data.
ModificadaAlta (7.5)2.2%—Phpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\forgot-password.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
Orbitaley — Vulnerabilidades