Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

285 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202630/6/2026
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /doctorprofile.php. The manipulation of the argument doctorname leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202629/6/2026
A weakness has been identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /doctorchangepassword.php. Executing a manipulation of the argument newpassword can lead to sql injection. The attack may be performed from remote. The exploit has been made available to the…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202629/6/2026
A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /departmentDoctor.php. This manipulation of the argument deptid causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202629/6/2026
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /department.php. The manipulation of the argument editid results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202630/6/2026
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The exploit is…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI29/6/202629/6/2026
A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Handler. This manipulation of the argument editid causes sql injection. The attack is possible to be carried out remotely. The exploit has…
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI28/6/202629/6/2026
A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment.php. This manipulation of the argument editid causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.
AplazadaBaja (2.1)0.33%—Itsourcecode Hospital Management SystemAI28/6/202629/6/2026
A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php. The manipulation of the argument medicineid results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
AplazadaBaja (2)0.35%—Itsourcecode Hospital Management SystemAI28/6/202629/6/2026
A vulnerability has been found in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminprofile.php. The manipulation of the argument loginid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
AplazadaBaja (2.1)0.20%—Itsourcecode Hospital Management SystemAI8/6/202623/7/2026
A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
AplazadaBaja (2.1)0.20%—Itsourcecode Hospital Management SystemAI8/6/202623/7/2026
A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminaccount.php. The manipulation of the argument Date results in sql injection. The attack can be launched remotely. The exploit is now public and may be used.
AplazadaBaja (2.1)0.27%—Itsourcecode Hospital Management SystemAI8/6/202623/7/2026
A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of the argument patientid leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed publicly and may…
AplazadaBaja (2)0.27%—Code-projects Online Hospital Management SystemAI1/6/202622/7/2026
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made…
AplazadaBaja (2.1)0.20%—Code-projects Online Hospital Management SystemAI1/6/202622/7/2026
A vulnerability has been found in code-projects Online Hospital Management System 1.0. Affected is an unknown function of the file appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible to be carried out remotely. The exploit…
AplazadaMedia (5.5)0.26%—Code-projects Online Hospital Management SystemAI1/6/202622/7/2026
A flaw has been found in code-projects Online Hospital Management System 1.php. This impacts the function login_user of the file login_1.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
AplazadaMedia (5.5)0.27%—Code-projects Online Hospital Management SystemAI31/5/202622/7/2026
A security vulnerability has been detected in code-projects Online Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patient.php. Such manipulation of the argument editid leads to sql injection. The attack can be executed remotely. The exploit has been disclosed…
AplazadaAlta (7.3)0.53%—Offline Hospital Management SystemAI18/5/202617/6/2026
Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration. The application enables Node.js integration while disabling context isolation, allowing JavaScript executed in the renderer process to access Node.js APIs and execute arbitrary operating system…
AplazadaMedia (5.5)0.41%—Projectworlds Hospital-management-system-in-phpAI18/5/202617/6/2026
A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the component GET Parameter Handler. Executing a manipulation of the argument appointment_no can lead to sql injection. The attack may be…
AplazadaMedia (5.4)0.23%—Phpgurukal Hospital Management SystemAI7/5/20265/7/2026
A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to inject a malicious script payload into the User Name parameter, which is stored in the application and later rendered in…
AplazadaMedia (5.5)0.43%—Code-projects Online Hospital Management SystemAI2/5/202617/6/2026
A vulnerability was determined in code-projects Online Hospital Management System 1.0. This affects an unknown function of the file /viewappointment.php. This manipulation of the argument delid causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be…
AplazadaBaja (2.1)0.38%—Code-projects Online Hospital Management SystemAI2/5/202617/6/2026
A vulnerability was found in code-projects Online Hospital Management System 1.0. The impacted element is an unknown function of the component Registration Handler. The manipulation of the argument Username results in improper authorization. The attack can be executed remotely. The exploit has been made public and…
AplazadaMedia (5.5)0.47%—Rickxy Hospital Management SystemAI20/4/202617/6/2026
A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the file /backend/admin/his_admin_account.php. The manipulation of the argument ad_dpic results in unrestricted upload. The attack can be executed remotely. The exploit has…
AnalizadaAlta (8.8)0.48%—Phpgurukul Hospital Management System18/2/202617/6/2026
PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient) can directly access the Administrator Dashboard and all sub-modules (e.g., User Logs, Doctor Management) by manually browsing to the /admin/ directory after authentication. This allows any…
AnalizadaMedia (6.5)0.34%—Phpgurukul Hospital Management System18/2/202617/6/2026
The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference (IDOR) vulnerability. The application fails to verify that the requested 'viewid' parameter belongs to the currently authenticated patient. This allows a user to access the confidential medical…
AnalizadaMedia (6.5)0.18%—Phpgurukul Hospital Management System18/2/202617/6/2026
PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor' module. The application fails to enforce CSRF token validation on the add-doctor.php endpoint. This allows remote attackers to create arbitrary Doctor accounts (privileged users) by tricking an…
Orbitaley — Vulnerabilidades