Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

186 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.5)0.42%—Neville EYE Clinic Management System1/9/202517/6/2026
A security vulnerability has been detected in SourceCodester Eye Clinic Management System 1.0. Affected by this issue is some unknown functionality of the file /main/search_index_Diagnosis.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit…
AplazadaAlta (8.7)0.42%—Changing Clinic Image SystemAI29/8/202517/6/2026
Clinic Image System developed by Changing has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
AplazadaCrítica (9.3)0.53%—Changing Clinic Image SystemAI29/8/202517/6/2026
Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to log into the system using administrator credentials embedded in the source code.
AplazadaCrítica (9.8)0.40%—Quanticalabs Medicenter - Health Medical ClinicAI20/8/202517/6/2026
Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Object Injection.This issue affects MediCenter - Health Medical Clinic: from n/a through <= 15.1.
AnalizadaBaja (2)0.44%—Metaclinic Nanovault5/8/202517/6/2026
A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file /main.js of the component xrb URL Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been…
ModificadaCrítica (9.8)0.60%—Qodeinteractive Mediclinic9/6/202517/6/2026
Path Traversal: '.../...//' vulnerability in Mikado-Themes MediClinic mediclinic allows PHP Local File Inclusion.This issue affects MediClinic: from n/a through <= 2.1.
AnalizadaMedia (5.5)0.44%—Nikhil-bhalerao Open Source Clinic Management System6/6/202517/6/2026
A vulnerability classified as critical has been found in SourceCodester Open Source Clinic Management System 1.0. This affects an unknown part of the file /doctor.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to…
AnalizadaMedia (5.5)0.44%💥 PoCNikhil-bhalerao Open Source Clinic Management System6/6/202517/6/2026
A vulnerability was found in SourceCodester Open Source Clinic Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /email_config.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaBaja (2.1)0.45%—Nikhil-bhalerao Open Source Clinic Management System6/6/202517/6/2026
A vulnerability classified as critical was found in SourceCodester Open Source Clinic Management System 1.0. This vulnerability affects unknown code of the file /manage_website.php. The manipulation of the argument website_image leads to unrestricted upload. The attack can be initiated remotely. The exploit has been…
AnalizadaMedia (5.5)0.42%—Nikhil-bhalerao Open Source Clinic Management System6/6/202517/6/2026
A vulnerability classified as critical has been found in SourceCodester Open Source Clinic Management System 1.0. Affected is an unknown function of the file /login.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the…
AnalizadaMedia (5.5)0.45%—Nikhil-bhalerao Open Source Clinic Management System6/6/202517/6/2026
A vulnerability has been found in SourceCodester Open Source Clinic Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /appointment.php. The manipulation of the argument patient leads to sql injection. The attack can be launched remotely. The…
AnalizadaMedia (6.5)0.34%—Philips Clinical Collaboration Platform2/6/202517/6/2026
Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attacker to obtain sensitive information and execute arbitrary code.
AnalizadaMedia (6.5)0.36%—Philips Clinical Collaboration Platform2/6/202517/6/2026
An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the usertoken function of default.aspx.
AnalizadaMedia (6.5)0.36%—Philips Clinical Collaboration Platform2/6/202517/6/2026
An issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code via the session management component.
AnalizadaMedia (4.8)0.22%—Oretnom23 Clinic Queuing System28/3/202517/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the page parameter in /patient_side.php.
AnalizadaMedia (4.8)0.22%—Oretnom23 Clinic Queuing System28/3/202517/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the id parameter in /manage_user.php.
AnalizadaMedia (4.8)0.22%—Oretnom23 Clinic Queuing System28/3/202517/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in version 1.0 of the Clinic Queuing System. This vulnerability could allow an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the page parameter in /index.php.
AplazadaMedia (5.3)0.29%—Quanticalabs Medicenter - Health Medical ClinicAI18/2/202517/6/2026
Missing Authorization vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MediCenter - Health Medical Clinic: from n/a through < 14.7.
AnalizadaAlta (8.1)0.46%—Angeljudesuarez Online Clinic Management System21/10/202417/6/2026
Online Clinic Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /success/editp.php?action=edit.
AnalizadaBaja (3.5)0.33%—Clinical-genomics Scout30/9/202417/6/2026
Scout is a web-based visualizer for VCF-files. Due to the lack of sanitization in the filename, it is possible bypass intended file extension and make users download malicious files with any extension. With malicious content injected inside the file data and users unknowingly downloading it and opening may lead to the…
AnalizadaMedia (6.1)0.39%—Clinical-genomics Scout30/9/202417/6/2026
Scout is a web-based visualizer for VCF-files. Open redirect vulnerability allows performing phishing attacks on users by redirecting them to malicious page. /login API endpoint is vulnerable to open redirect attack via next parameter due to absence of sanitization logic. Additionally, due to lack of scheme…
AnalizadaMedia (6.9)0.65%—Oretnom23 Clinic's Patient Management System7/9/202417/6/2026
A vulnerability was found in SourceCodesters Clinics Patient Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /print_diseases.php. The manipulation of the argument disease/from/to leads to sql injection. The attack may be initiated remotely. The exploit has…
AnalizadaMedia (6.9)0.64%—Oretnom23 Clinic's Patient Management System7/9/202417/6/2026
A vulnerability was found in SourceCodester Clinics Patient Management System 2.0. It has been classified as problematic. Affected is an unknown function of the file congratulations.php. The manipulation of the argument goto_page leads to open redirect. It is possible to launch the attack remotely. The exploit has…
AnalizadaMedia (5.3)0.49%—Oretnom23 Clinic's Patient Management System7/9/202417/6/2026
A vulnerability was found in SourceCodester Clinics Patient Management System 2.0 and classified as problematic. This issue affects some unknown processing of the file /users.php. The manipulation of the argument message leads to cross site scripting. The attack may be initiated remotely. The exploit has been…
AnalizadaMedia (5.3)0.61%—Oretnom23 Clinic's Patient Management System19/8/202417/6/2026
A vulnerability has been found in SourceCodester Clinics Patient Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /pms/ajax/get_packings.php. The manipulation of the argument medicine_id leads to sql injection. The attack can be initiated remotely. The exploit has…
Orbitaley — Vulnerabilidades