Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
285 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2) | 0.36% | — | Phpgurukul Hospital Management System | 8/2/2026 | 17/6/2026 | A vulnerability was determined in PHPGurukul Hospital Management System 4.0. This impacts an unknown function of the file /admin/manage-users.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Baja (2) | 0.36% | — | Phpgurukul Hospital Management System | 8/2/2026 | 17/6/2026 | A security vulnerability has been detected in PHPGurukul Hospital Management System 4.0. The affected element is an unknown function of the file /hms/admin/manage-doctors.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly… | |
| Analizada | Baja (2.1) | 0.40% | — | Phpgurukul Hospital Management System | 28/1/2026 | 17/6/2026 | A security flaw has been discovered in PHPGurukul Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /hms/hospital/docappsystem/adminviews.py of the component Admin Dashboard Page. Performing a manipulation results in improper authorization. Remote exploitation of the… | |
| Analizada | Alta (7.3) | 0.20% | — | Campcodes Online Hospital Management System | 19/11/2025 | 17/6/2026 | Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter username. | |
| Analizada | Media (6.1) | 0.20% | — | Kishan0725 Hospital Management System | 18/11/2025 | 17/6/2026 | kishan0725 Hospital Management System has a Cross-Site Scripting (XSS) vulnerability in appsearch.php via the email parameter. | |
| Analizada | Media (6.5) | 0.27% | — | Kishan0725 Hospital Management System | 18/11/2025 | 17/6/2026 | kishan0725 Hospital Management System v4 has an Insecure Direct Object Reference (IDOR) vulnerability in the appointment cancellation functionality. | |
| Analizada | Media (6.5) | 0.24% | — | Kishan0725 Hospital Management System | 18/11/2025 | 17/6/2026 | kishan0725 Hospital Management System/ v4 is vulnerable to SQL Injection in admin-panel1.php, specifically in the deleting doctor logic. The application fails to properly sanitize or parameterize user-supplied input from the demail parameter before incorporating it directly into a dynamic SQL query. | |
| Analizada | Alta (7.1) | 0.22% | — | Rickxy Hospital Management System | 10/11/2025 | 17/6/2026 | The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization, allowing authenticated attackers (doctor role)… | |
| Analizada | Baja (2.9) | 0.52% | — | Fabian Hospital Management System | 11/10/2025 | 17/6/2026 | A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component express-session. This manipulation of the argument secret with the input secret causes use of hard-coded cryptographic key . The attack can be initiated remotely. The attack is considered to have… | |
| Aplazada | Baja (2.1) | 0.25% | — | Nahiduddinahammed Hospital-management-system-websiteAI | 6/10/2025 | 17/6/2026 | A weakness has been identified in nahiduddinahammed Hospital-Management-System-Website up to e6562429e14b2f88bd2139cae16e87b965024097. This issue affects some unknown processing of the file /delete.php. This manipulation of the argument ai causes sql injection. It is possible to initiate the attack remotely. The… | |
| Aplazada | Media (6.5) | 0.27% | — | Karthikg1908 Hospital Management SystemAI | 30/9/2025 | 17/6/2026 | An SQL injection vulnerability in user-login.php and index.php of Karthikg1908 Hospital Management System (HMS) 1.0 allows remote attackers to execute arbitrary SQL queries via the username and password POST parameters. The application fails to properly sanitize input before embedding it into SQL queries, leading to… | |
| Analizada | Media (5.5) | 0.47% | — | Campcodes Hospital Management System | 1/9/2025 | 25/9/2026 | A weakness has been identified in Campcodes Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ of the component Admin Dashboard Login. This manipulation of the argument Password causes sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Baja (2) | 0.29% | — | Campcodes Online Hospital Management System | 1/9/2025 | 17/6/2026 | A flaw has been found in Campcodes Online Hospital Management System 1.0. The impacted element is an unknown function of the file /edit-profile.php of the component Edit Profile Page. Executing manipulation of the argument Username can lead to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Analizada | Baja (1.9) | 0.29% | — | Campcodes Online Hospital Management System | 1/9/2025 | 17/6/2026 | A vulnerability was detected in Campcodes Online Hospital Management System 1.0. The affected element is an unknown function of the file /admin/patient-search.php of the component Patient Search Module. Performing manipulation of the argument Search by Name Mobile No results in cross site scripting. The attack may be… | |
| Analizada | Baja (1.9) | 0.25% | — | Campcodes Hospital Management System | 31/8/2025 | 17/6/2026 | A vulnerability was detected in Campcodes Hospital Management System 1.0. This affects an unknown function of the file /admin/edit-doctor-specialization.php of the component Edit Doctor Specialization Page. The manipulation results in cross site scripting. The attack may be launched remotely. The exploit is now public… | |
| Modificada | Alta (8.5) | 0.29% | — | Phpgurukul Hospital Management System | 25/8/2025 | 17/6/2026 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in about-us.php via the pagetitle parameter. | |
| Modificada | Media (6.5) | 0.27% | — | Phpgurukul Hospital Management System | 25/8/2025 | 17/6/2026 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in contact.php via the pagetitle parameter. | |
| Modificada | Crítica (9.8) | 0.35% | — | Phpgurukul Hospital Management System | 25/8/2025 | 17/6/2026 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in index.php via the username parameter. | |
| Modificada | Crítica (9.8) | 0.43% | — | Phpgurukul Hospital Management System | 25/8/2025 | 17/6/2026 | phpgurukul Hospital Management System 4.0 is vulnerable to SQL Injection in add-doctor.php via the docname parameter. | |
| Analizada | Media (5.5) | 0.52% | — | Code-projects Hospital Management System | 14/8/2025 | 17/6/2026 | A vulnerability has been found in PHPGurukul Hospital Management System 4.0. This vulnerability affects unknown code of the file /admin/edit-doctor.php. The manipulation of the argument docfees leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.42% | — | Code-projects Hospital Management System | 14/8/2025 | 17/6/2026 | A vulnerability was identified in PHPGurukul Hospital Management System 4.0. This affects an unknown part of the file /admin/doctor-specilization.php. The manipulation of the argument doctorspecilization leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the… | |
| Aplazada | Crítica (9.8) | 0.37% | — | Danphe Health Hospital Management System EMRAI | 13/8/2025 | 17/6/2026 | An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health Hospital Management System EMR 3.2 allowing attackers to reset any account password. | |
| Analizada | Alta (8.8) | 0.30% | — | Kishan0725 Hospital Management System | 7/8/2025 | 17/6/2026 | Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the doctor_contact parameter in doctorsearch.php. | |
| Analizada | Alta (8.8) | 0.30% | — | Kishan0725 Hospital Management System | 7/8/2025 | 17/6/2026 | Hospital Management System v4 was discovered to contain multiple SQL injection vulnerabilities in func3.php via the username1 and password2 parameters. | |
| Analizada | Crítica (9.8) | 0.35% | — | Kishan0725 Hospital Management System | 7/8/2025 | 17/6/2026 | Hospital Management System v4 was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php. |