Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
372 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.3% | — | Doctor's Appointment System Project Doctor's Appointment System | 31/8/2022 | 17/6/2026 | Doctor’s Appointment System v1.0 is vulnerable to Blind SQLi via settings.php. | |
| Modificada | Media (4.8) | 0.68% | — | Nsqua Simply Schedule Appointments | 29/8/2022 | 17/6/2026 | The Simply Schedule Appointments WordPress plugin before 1.5.7.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Media (5.3) | 1.9% | 💥 Exploit | Nsqua Simply Schedule Appointments | 29/8/2022 | 17/6/2026 | The Simply Schedule Appointments WordPress plugin before 1.5.7.7 is missing authorisation in a REST endpoint, allowing unauthenticated users to retrieve WordPress users details such as name and email address | |
| Analizada | Media (5.4) | 0.61% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field. | |
| Analizada | Media (6.1) | 0.66% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field. | |
| Analizada | Alta (8.8) | 0.50% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php. | |
| Analizada | Crítica (9.8) | 1.2% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php. | |
| Analizada | Crítica (9.8) | 1.2% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php. | |
| Analizada | Crítica (9.8) | 1.2% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php. | |
| Analizada | Media (6.5) | 0.75% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data. | |
| Modificada | Media (4.8) | 0.59% | — | Dwbooster Appointment Hour Booking | 13/6/2022 | 17/6/2026 | The Appointment Hour Booking WordPress plugin before 1.3.56 does not sanitise and escape a settings of its Calendar fields, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed. | |
| Modificada | Alta (8.8) | 1.2% | — | Easyappointments | 10/5/2022 | 17/6/2026 | API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover. | |
| Modificada | Crítica (9.8) | 3.3% | — | Simple Doctor's Appointment System Project Simple Doctor's Appointment System | 4/5/2022 | 9/7/2026 | Sourcecodester Doctor's Appointment System 1.0 is vulnerable to File Upload to RCE via Image upload from the administrator panel. An attacker can obtain remote command execution just by knowing the path where the images are stored. | |
| Modificada | Crítica (9.1) | 44% | 💥 Exploit | Easyappointments | 9/3/2022 | 17/6/2026 | Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3. | |
| Modificada | Crítica (9.8) | 1.3% | — | Patient Appointment Scheduler System Project Patient Appointment Scheduler System | 24/1/2022 | 17/6/2026 | SQL injection vulnerability in Sourcecodester Patient Appointment Scheduler System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password fields to login.php. | |
| Modificada | Media (5.4) | 0.62% | — | Dwbooster Appointment Hour Booking | 11/10/2021 | 17/6/2026 | The Appointment Hour Booking WordPress plugin before 1.3.17 does not properly sanitize values used when creating new calendars. | |
| Modificada | Media (4.8) | 0.62% | — | Dwbooster Appointment Hour Booking | 4/10/2021 | 17/6/2026 | The Appointment Hour Booking WordPress plugin before 1.3.16 does not escape some of the Calendar Form settings, allowing high privilege users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.8) | 0.62% | — | Oz-plugin Book Appointment Online | 13/9/2021 | 17/6/2026 | The Book appointment online WordPress plugin before 1.39 does not sanitise or escape Service Prices before outputting it in the List, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 2.5% | 💥 Exploit | Online Doctor Appointment System PHP Full Source Code Project Online Doctor Appointment System PHP Full Source Code | 23/7/2021 | 17/6/2026 | Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields. | |
| Modificada | Alta (7.5) | 9.3% | 💥 Exploit | Doctor Appointment System Project Doctor Appointment System | 24/3/2021 | 17/6/2026 | Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Doctor Appointment System Project Doctor Appointment System | 24/3/2021 | 17/6/2026 | Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email parameter. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Doctor Appointment System Project Doctor Appointment System | 24/3/2021 | 17/6/2026 | Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname parameter. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Doctor Appointment System Project Doctor Appointment System | 24/3/2021 | 17/6/2026 | Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comment parameter. | |
| Modificada | Crítica (9.8) | 12% | 💥 Exploit | Doctor Appointment System Project Doctor Appointment System | 5/3/2021 | 17/6/2026 | SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter at login page. | |
| Modificada | Media (6.1) | 1.5% | — | Doctor Appointment System Project Doctor Appointment System | 1/3/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or HTML via the lastname parameter. |