Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.49% | — | Hospital's Patient Records Management System Project Hospital's Patient Records Management System | 30/3/2022 | 9/7/2026 | A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the "special" field. | |
| Modificada | Crítica (9.8) | 1.6% | — | Hospital's Patient Records Management System Project Hospital's Patient Records Management System | 24/2/2022 | 17/6/2026 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/manage_doctor.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Hospital's Patient Records Management System Project Hospital's Patient Records Management System | 24/2/2022 | 17/6/2026 | Hospital Patient Record Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/doctors/view_doctor.php. | |
| Modificada | Alta (7.8) | 1.5% | — | Hospital's Patient Records Management System Project Hospital's Patient Records Management System | 24/2/2022 | 17/6/2026 | A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Media (5.4) | 0.82% | — | Hospital's Patient Records Management System Project Hospital's Patient Records Management System | 16/2/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Hospital Patient Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Name field. | |
| Modificada | Alta (8.8) | 0.95% | — | Hospital's Patient Records Management System Project Hospital's Patient Records Management System | 14/2/2022 | 17/6/2026 | An access control issue in hprms/admin/?page=user/list of Hospital Patient Record Management System v1.0 allows attackers to escalate privileges via accessing and editing the user list. | |
| Modificada | Media (5.4) | 0.85% | 💥 PoC | Hospital's Patient Records Management System Project Hospital's Patient Records Management System | 26/1/2022 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_list. | |
| Modificada | Media (5.4) | 0.66% | 💥 PoC | Hospital's Patient Records Management System Project Hospital's Patient Records Management System | 26/1/2022 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the description parameter in room_types. | |
| Modificada | Media (5.4) | 0.63% | 💥 PoC | Hospital's Patient Records Management System Project Hospital's Patient Records Management System | 26/1/2022 | 17/6/2026 | A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodtester Hospital's Patient Records Management System 1.0 via the specialization parameter in doctors.php | |
| Modificada | Media (5.3) | 0.99% | 💥 PoC | Hospital's Patient Records Management System Project Hospital's Patient Records Management System | 24/1/2022 | 17/6/2026 | Sourcecodester Hospital's Patient Records Management System 1.0 is vulnerable to Insecure Permissions via the id parameter in manage_user endpoint. Simply change the value and data of other users can be displayed. |