Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

186 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.81%—Openclinic GA Project Openclinic GA10/5/202117/6/2026
A number of exploitable SQL injection vulnerabilities exists in ‘patientslist.do’ page of OpenClinic GA 5.173.3 application. The findPersonID parameter in ‘‘patientslist.do’ page is vulnerable to authenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaAlta (8.8)1.0%—Openclinic GA Project Openclinic GA10/5/202117/6/2026
An exploitable SQL injection vulnerability exists in ‘quickFile.jsp’ page of OpenClinic GA 5.173.3. A specially crafted HTTP request can lead to SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaMedia (5.4)1.7%💥 ExploitRemoteclinic Remote Clinic21/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Chat" and "Personal Address" field on staff/register.php
ModificadaMedia (5.4)1.7%💥 ExploitRemoteclinic Remote Clinic21/4/202117/6/2026
Stored XSS in Remote Clinic v2.0 in /medicines due to Medicine Name Field.
ModificadaCrítica (9.8)0.87%—Openclinic GA Project Openclinic GA19/4/202117/6/2026
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)0.87%—Openclinic GA Project Openclinic GA19/4/202117/6/2026
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The componentStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)0.87%—Openclinic GA Project Openclinic GA15/4/202117/6/2026
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The assetStatus parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)0.87%—Openclinic GA Project Openclinic GA15/4/202117/6/2026
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)0.87%—Openclinic GA Project Openclinic GA15/4/202117/6/2026
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The code parameter in the The nomenclature parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)0.88%—Openclinic GA Project Openclinic GA13/4/202117/6/2026
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the compnomenclature parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)0.88%—Openclinic GA Project Openclinic GA13/4/202117/6/2026
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the description parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)0.88%—Openclinic GA Project Openclinic GA13/4/202117/6/2026
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the serviceUID parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)0.88%—Openclinic GA Project Openclinic GA13/4/202117/6/2026
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3 in the supplierUID parameter. An attacker can make an authenticated HTTP request to trigger this vulnerability.
ModificadaAlta (7.8)0.76%—Openclinic GA Project Openclinic GA13/4/202117/6/2026
An incorrect default permissions vulnerability exists in the installation functionality of OpenClinic GA 5.173.3. Overwriting the binary can result in privilege escalation. An attacker can replace a file to exploit this vulnerability.
ModificadaCrítica (9.8)2.9%—Openclinic GA Project Openclinic GA13/4/202117/6/2026
An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be executed on the server. An attacker can send a web request with parameters containing specific parameter to trigger this vulnerability, potentially allowing exfiltration of the…
ModificadaMedia (5.4)1.8%💥 ExploitRemoteclinic Remote Clinic13/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.
ModificadaMedia (5.4)1.8%💥 ExploitRemoteclinic Remote Clinic13/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Clinic Name", "Clinic Address", "Clinic City", or "Clinic Contact" field on clinics/register.php
ModificadaMedia (5.4)1.8%💥 ExploitRemoteclinic Remote Clinic13/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the "Fever" or "Blood Pressure" field on the patients/register-report.php.
ModificadaMedia (5.4)1.8%💥 ExploitRemoteclinic Remote Clinic13/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Symptons field on patients/register-report.php.
ModificadaMedia (5.4)1.8%💥 ExploitRemoteclinic Remote Clinic13/4/202117/6/2026
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the Full Name field on register-patient.php.
ModificadaAlta (7.2)1.7%—Openclinic Project Openclinic3/12/202017/6/2026
OpenClinic version 0.8.2 is affected by a medical/test_new.php insecure file upload vulnerability. This vulnerability allows authenticated users (with substantial privileges) to upload malicious files, such as PHP web shells, which can lead to arbitrary code execution on the application server.
ModificadaMedia (5.4)0.55%—Openclinic Project Openclinic3/12/202017/6/2026
OpenClinic version 0.8.2 is affected by a stored XSS vulnerability in lib/Check.php that allows users of the application to force actions on behalf of other users.
ModificadaAlta (7.5)1.3%—Openclinic Project Openclinic3/12/202017/6/2026
OpenClinic version 0.8.2 is affected by a missing authentication vulnerability that allows unauthenticated users to access any patient's medical test results, possibly resulting in disclosure of Protected Health Information (PHI) stored in the application, via a direct request for the /tests/ URI.
ModificadaAlta (7.1)0.36%—Philips Clinical Collaboration Platform18/9/202017/6/2026
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.
ModificadaMedia (6.5)0.62%—Philips Clinical Collaboration Platform18/9/202017/6/2026
Philips Clinical Collaboration Platform, Versions 12.2.1 and prior, does not properly control the allocation and maintenance of a limited resource, thereby enabling an attacker to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
Orbitaley — Vulnerabilidades