Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.88% | — | Oretnom23 Clinic's Patient Management System | 16/8/2022 | 17/6/2026 | Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=. | |
| Modificada | Crítica (9.8) | 0.97% | — | Oretnom23 Clinic's Patient Management System | 10/8/2022 | 17/6/2026 | Clinic's Patient Management System v1.0 is vulnerable to SQL injection via /pms/update_user.php?id=. | |
| Modificada | Crítica (9.8) | 1.4% | — | Oretnom23 Clinic's Patient Management System | 10/8/2022 | 17/6/2026 | Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php. | |
| Modificada | Crítica (9.8) | 0.96% | — | Oretnom23 Clinic's Patient Management System | 12/7/2022 | 17/6/2026 | A vulnerability has been found in SourceCodester Clinics Patient Management System 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pms/index.php of the component Login Page. The manipulation of the argument user_name with the input admin' or '1'='1 leads to sql… | |
| Modificada | Alta (8.8) | 3.4% | 💥 Exploit | Oretnom23 Clinic's Patient Management System | 12/7/2022 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.php?user_id=1. The manipulation of the argument profile_picture with the input <?php phpinfo();?> leads to unrestricted upload. It is… | |
| Modificada | Crítica (9.8) | 1.1% | — | Openclinica | 14/5/2022 | 17/6/2026 | OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). Versions prior to 3.16.1 are vulnerable to SQL injection due to the use of string concatenation to create SQL queries instead of prepared statements. No known workarounds exist. This issue has been patched in… | |
| Modificada | Crítica (9.8) | 3.2% | — | Openclinica | 14/5/2022 | 17/6/2026 | OpenClinica is an open source software for Electronic Data Capture (EDC) and Clinical Data Management (CDM). OpenClinica prior to version 3.16 is vulnerable to path traversal in multiple endpoints, leading to arbitrary file read/write, and potential remote code execution. There are no known workarounds. This issue has… | |
| Modificada | Alta (8.2) | 1.2% | 💥 PoC | Clinical-genomics Scout | 5/5/2022 | 17/6/2026 | Server-Side Request Forgery in scout in GitHub repository clinical-genomics/scout prior to v4.42. An attacker could make the application perform arbitrary requests to fishing steal cookie, request to private area, or lead to xss... | |
| Modificada | Alta (7.5) | 1.4% | — | Clinical-genomics Scout | 3/5/2022 | 17/6/2026 | Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52. | |
| Modificada | Media (6.1) | 1.1% | — | Remoteclinic Remote Clinic | 5/11/2021 | 17/6/2026 | Multiple Cross Site Scripting (XSS) vulnerabilities exists in Remote Clinic v2.0 in (1) patients/register-patient.php via the (a) Contact, (b) Email, (c) Weight, (d) Profession, (e) ref_contact, (f) address, (g) gender, (h) age, and (i) serial parameters; in (2) patients/edit-patient.php via the (a) Contact, (b)… | |
| Modificada | Alta (7.8) | 1.3% | — | Openclinic GA Project Openclinic GA | 26/10/2021 | 17/6/2026 | OpenClinic GA 5.194.18 is affected by Insecure Permissions. By default the Authenticated Users group has the modify permission to openclinic folders/files. A low privilege account is able to rename mysqld.exe or tomcat8.exe files located in bin folders and replace with a malicious file that would connect back to an… | |
| Modificada | Media (5.4) | 0.64% | — | Cliniccases | 7/9/2021 | 17/6/2026 | Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. This can result in account takeover via session token theft. | |
| Modificada | Alta (8.8) | 1.0% | — | Cliniccases | 7/9/2021 | 17/6/2026 | messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter. | |
| Modificada | Alta (8.8) | 0.77% | — | Cliniccases | 7/9/2021 | 17/6/2026 | ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticated user following a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user. This can be exploited to create a secondary administrator account… | |
| Modificada | Media (6.1) | 3.5% | 💥 Exploit | Cliniccases | 7/9/2021 | 17/6/2026 | Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via session token theft. | |
| Modificada | Alta (7.5) | 2.4% | — | Oracle Advanced Networking OptionOracle Agile Engineering Data ManagementOracle Agile Product Lifecycle ManagementOracle Agile Product Lifecycle Management FOR Process+107 | 21/7/2021 | 25/8/2026 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks… | |
| Modificada | Alta (7.2) | 1.1% | — | Openclinic Project Openclinic | 16/6/2021 | 17/6/2026 | Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability . | |
| Modificada | Alta (8.8) | 0.81% | — | Openclinic GA Project Openclinic GA | 11/5/2021 | 17/6/2026 | An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoComment parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.81% | — | Openclinic GA Project Openclinic GA | 11/5/2021 | 17/6/2026 | An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoBuyer parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.81% | — | Openclinic GA Project Openclinic GA | 11/5/2021 | 17/6/2026 | An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoCode parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.81% | — | Openclinic GA Project Openclinic GA | 11/5/2021 | 17/6/2026 | An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoService parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.81% | — | Openclinic GA Project Openclinic GA | 11/5/2021 | 17/6/2026 | An exploitable SQL injection vulnerability exists in ‘listImmoLabels.jsp’ page of OpenClinic GA 5.173.3 application. The immoLocation parameter in the ‘listImmoLabels.jsp’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 1.0% | — | Openclinic GA Project Openclinic GA | 10/5/2021 | 17/6/2026 | An exploitable SQL injection vulnerability exists in ‘manageServiceStocks.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.81% | — | Openclinic GA Project Openclinic GA | 10/5/2021 | 17/6/2026 | A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findDistrict parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.81% | — | Openclinic GA Project Openclinic GA | 10/5/2021 | 17/6/2026 | A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findSector parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection An attacker can make an authenticated HTTP request to trigger this vulnerability. |