Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.76% | — | Doctors Appointment System Project Doctors Appointment System | 27/2/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Doctors Appointment System 1.0. This issue affects some unknown processing of the file /admin/edit-doc.php. The manipulation of the argument email/oldmail leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Analizada | Media (5.3) | 0.76% | — | Doctors Appointment System Project Doctors Appointment System | 27/2/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /admin/doctors.php of the component Parameter Handler. The manipulation of the argument search/id leads to sql injection. The attack can be initiated remotely. The… | |
| Modificada | Alta (8.8) | 0.76% | — | Doctors Appointment System Project Doctors Appointment System | 27/2/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Doctors Appointment System 1.0. This affects an unknown part of the file create-account.php. The manipulation of the argument newemail leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (8.8) | 0.73% | — | Doctors Appointment System Project Doctors Appointment System | 27/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been rated as critical. Affected by this issue is the function edoc of the file login.php. The manipulation of the argument usermail leads to sql injection. VDB-221822 is the identifier assigned to this vulnerability. | |
| Modificada | Alta (8.8) | 0.70% | — | Doctors Appointment System Project Doctors Appointment System | 27/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Doctors Appointment System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /edoc/doctor/patient.php. The manipulation of the argument search12 leads to sql injection. The attack can be launched remotely. The… | |
| Modificada | Crítica (9.8) | 0.92% | — | Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System | 26/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /APR/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. The attack may be… | |
| Modificada | Media (6.1) | 0.78% | — | Dental Clinic Appointment Reservation System Project Dental Clinic Appointment Reservation System | 26/2/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /APR/signup.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to cross site scripting. The… | |
| Modificada | Crítica (9.8) | 1.2% | — | Online Doctor Appointment Booking System PHP AND Mysql Project Online Doctor Appointment Booking System PHP AND Mysql | 17/2/2023 | 17/6/2026 | SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint. | |
| Modificada | Media (6.1) | 0.48% | — | Phpgurukul Doctor Appointment Management System | 26/1/2023 | 17/6/2026 | phpgurukul Doctor Appointment Management System V 1.0.0 is vulnerable to Cross Site Scripting (XSS) via searchdata=. | |
| Modificada | Media (6.1) | 0.52% | — | Phpgurukul Doctor Appointment Management System | 26/1/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search function. | |
| Modificada | Media (5.4) | 0.47% | — | Easy-appointments Easy Appointments | 23/1/2023 | 17/6/2026 | The Easy Appointments WordPress plugin before 3.11.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as… | |
| Modificada | Media (6.1) | 0.50% | 💥 PoC | Phpgurukul Doctor Appointment Management System | 12/1/2023 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Doctor Appointment Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee ID parameter. | |
| Modificada | Media (6.1) | 0.53% | 💥 PoC | Phpgurukul Doctor Appointment Management System | 12/1/2023 | 17/6/2026 | Doctor Appointment Management System v1.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability. | |
| Modificada | Media (6.1) | 0.54% | — | Innologi Appointment Scheduler | 4/1/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in innologi appointments Extension up to 2.0.5 on TYPO3. This affects an unknown part of the component Appointment Handler. The manipulation of the argument formfield leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading… | |
| Modificada | Media (5.4) | 0.93% | — | Openmrs Appointment Scheduling Module | 27/12/2022 | 17/6/2026 | A vulnerability was found in OpenMRS Appointment Scheduling Module up to 1.12.x. It has been classified as problematic. This affects the function validateFieldName of the file api/src/main/java/org/openmrs/module/appointmentscheduling/validator/AppointmentTypeValidator.java. The manipulation leads to cross site… | |
| Modificada | Media (6.1) | 0.92% | — | Openmrs Appointment Scheduling Module | 27/12/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in OpenMRS Appointment Scheduling Module up to 1.16.x. This affects the function getNotes of the file api/src/main/java/org/openmrs/module/appointmentscheduling/AppointmentRequest.java of the component Notes Handler. The manipulation of the argument notes… | |
| Modificada | Media (5.3) | 0.47% | — | Dwbooster Appointment Hour Booking | 29/11/2022 | 17/6/2026 | The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.72. This is due to the use of insufficiently strong hashing algorithm on the CAPTCHA secret that is also displayed to the user via a cookie. | |
| Modificada | Media (6.1) | 0.75% | — | Dwbooster Appointment Hour Booking | 29/11/2022 | 17/6/2026 | The Appointment Hour Booking plugin for WordPress is vulnerable to iFrame Injection via the ‘email’ or general field parameters in versions up to, and including, 1.3.72 due to insufficient input sanitization and output escaping that makes injecting iFrame tags possible. This makes it possible for unauthenticated… | |
| Modificada | Alta (7.8) | 0.68% | — | Dwbooster Appointment Hour Booking | 29/11/2022 | 17/6/2026 | The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 1.3.72. This makes it possible for unauthenticated attackers to embed untrusted input into content during booking creation that may be exported as a CSV file when a site's administrator exports booking… | |
| Modificada | Alta (8.8) | 0.54% | — | Codepeople Appointment Booking Calendar | 18/11/2022 | 17/6/2026 | Missing Authorization vulnerability in Appointment Booking Calendar plugin <= 1.3.69 on WordPress. | |
| Modificada | Alta (8.8) | 0.54% | — | Dwbooster Appointment Hour Booking | 18/11/2022 | 17/6/2026 | Missing Authorization vulnerability in Appointment Hour Booking plugin <= 1.3.71 on WordPress. | |
| Modificada | Media (6.1) | 0.27% | — | Bookingultrapro Booking Ultra PRO Appointments Booking Calendar | 30/9/2022 | 17/6/2026 | Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro plugin <= 1.1.4 at WordPress. | |
| Modificada | Alta (8.8) | 0.34% | — | Bookingultrapro Booking Ultra PRO Appointments Booking Calendar | 30/9/2022 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Booking Ultra Pro plugin <= 1.1.4 at WordPress. | |
| Modificada | Media (6.1) | 1.0% | — | Doctor's Appointment System Project Doctor's Appointment System | 31/8/2022 | 17/6/2026 | Doctor's Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) via the admin panel. In addition, it leads to takeover the administrator account by stealing the cookie via XSS. | |
| Modificada | Crítica (9.8) | 0.89% | — | Doctor's Appointment System Project Doctor's Appointment System | 31/8/2022 | 9/7/2026 | Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter. |