Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
285 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 6.3% | 💥 Exploit | Phpgurukul Hospital Management System | 22/6/2021 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. | |
| Modificada | Alta (7.5) | 2.2% | — | Phpgurukul Hospital Management System | 22/6/2021 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\check_availability.php. Remote unauthenticated users can exploit the vulnerability to obtain database sensitive information. | |
| Modificada | Alta (8.8) | 1.8% | — | Phpgurukul Hospital Management System | 7/1/2021 | 17/6/2026 | PHPGURUKUL Hospital Management System V 4.0 does not properly restrict access to admin/dashboard.php, which allows attackers to access all data of users, doctors, patients, change admin password, get appointment history and access all session logs. | |
| Modificada | Media (5.4) | 0.62% | — | Phpgurukul Hospital Management System | 8/10/2020 | 17/6/2026 | PHPGurukul hospital-management-system-in-php 4.0 allows XSS via admin/patient-search.php, doctor/search.php, book-appointment.php, doctor/appointment-history.php, or admin/appointment-history.php. | |
| Modificada | Media (6.1) | 0.92% | — | Phpgurukul Hospital Management System | 14/1/2020 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple reflected XSS vulnerabilities via the searchdata or Doctorspecialization parameter. | |
| Modificada | Alta (8.8) | 17% | 💥 Exploit | Phpgurukul Hospital Management System | 6/1/2020 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages and parameters are not validating user input, and allow for the application's database and information to be fully compromised. | |
| Modificada | Media (6.1) | 5.5% | 💥 Exploit | Phpgurukul Hospital Management System | 6/1/2020 | 17/6/2026 | PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities. | |
| Modificada | Crítica (9.8) | 2.3% | — | Healthnode Hospital Management System Project Healthnode Hospital Management System | 19/6/2019 | 17/6/2026 | SQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or dashboard/Patient/patientdetails.php. | |
| Modificada | Crítica (9.8) | 2.0% | — | Phptpoint Hospital Management System | 29/10/2018 | 17/6/2026 | PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.php, DUNDEL.php, PDEL.php, or PUNDEL.php. | |
| Modificada | Alta (8.8) | 2.7% | 💥 Exploit | Dasinfomedia Hospital Management System | 28/9/2017 | 17/6/2026 | Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter. |