Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

285 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)6.3%💥 ExploitPhpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
ModificadaAlta (7.5)2.2%—Phpgurukul Hospital Management System22/6/202117/6/2026
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information.
ModificadaAlta (8.8)1.8%—Phpgurukul Hospital Management System7/1/202117/6/2026
PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs.
ModificadaMedia (5.4)0.62%—Phpgurukul Hospital Management System8/10/202017/6/2026
PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php.
ModificadaMedia (6.1)0.92%—Phpgurukul Hospital Management System14/1/202017/6/2026
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter.
ModificadaAlta (8.8)17%💥 ExploitPhpgurukul Hospital Management System6/1/202017/6/2026
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised.
ModificadaMedia (6.1)5.5%💥 ExploitPhpgurukul Hospital Management System6/1/202017/6/2026
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
ModificadaCrítica (9.8)2.3%—Healthnode Hospital Management System Project Healthnode Hospital Management System19/6/201917/6/2026
SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php.
ModificadaCrítica (9.8)2.0%—Phptpoint Hospital Management System29/10/201817/6/2026
PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.php, DUNDEL.php, PDEL.php, or PUNDEL.php.
ModificadaAlta (8.8)2.7%💥 ExploitDasinfomedia Hospital Management System28/9/201717/6/2026
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.