Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.95% | — | Chikitsa Patient Management System | 15/1/2026 | 17/6/2026 | Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability that allows attackers to upload malicious PHP plugins through the module upload functionality. Authenticated attackers can generate and upload a ZIP plugin with a PHP backdoor that enables arbitrary command execution… | |
| Analizada | Alta (8.7) | 0.86% | — | Chikitsa Patient Management System | 15/1/2026 | 17/6/2026 | Chikitsa Patient Management System 2.0.2 contains an authenticated remote code execution vulnerability in the backup restoration functionality. Authenticated attackers can upload a modified backup zip file with a malicious PHP shell to execute arbitrary system commands on the server. | |
| Aplazada | Crítica (9.3) | 1.5% | — | Chikitsa Patient Management SystemAI | 1/4/2025 | 17/6/2026 | Clinic’s Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page. | |
| Modificada | Media (4.8) | 0.55% | — | Chikitsa Patient Management Software | 31/3/2022 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 via the last_name parameter in the (1) patient/insert, (2) patient_report, (3) /appointment_report, (4) visit_report, and (5) /bill_detail_report pages. | |
| Modificada | Media (4.8) | 0.51% | — | Chikitsa Patient Management Software | 31/3/2022 | 9/7/2026 | A Cross Site Scripting (XSS) vulnerability exists in Chikista Patient Management Software 2.0.2 in the first_name parameter in (1) patient/insert, (2) patient_report, (3) appointment_report, (4) visit_report, and (5) bill_detail_report pages. . | |
| Modificada | Media (5.4) | 1.0% | — | Chikitsa Patient Management System | 6/8/2021 | 17/6/2026 | index.php/appointment/insert_patient_add_appointment in Chikitsa Patient Management System 2.0.0 allows XSS. | |
| Modificada | Media (5.4) | 0.62% | — | Chikitsa Patient Management System | 6/8/2021 | 17/6/2026 | index.php/appointment/todos in Chikitsa Patient Management System 2.0.0 allows XSS. | |
| Modificada | Media (5.4) | 0.66% | — | Chikitsa Patient Management System | 6/8/2021 | 17/6/2026 | index.php/admin/add_user in Chikitsa Patient Management System 2.0.0 allows XSS. | |
| Modificada | Media (6.4) | 2.4% | — | Hiki | 2/7/2007 | 16/6/2026 | Directory traversal vulnerability in session.rb in Hiki 0.8.0 through 0.8.6 allows remote attackers to delete arbitrary files via directory traversal sequences in the session ID, which is matched against an insufficiently restrictive regular expression before it is used to construct a filename that is marked for… | |
| Modificada | Media (5) | 1.6% | — | Mochikit Framework | 30/4/2007 | 16/6/2026 | The MochiKit framework exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka… | |
| Modificada | Media (5) | 2.3% | — | Hiki Wiki | 6/7/2006 | 16/6/2026 | Algorithmic complexity vulnerability in Hiki Wiki 0.6.0 through 0.6.5 and 0.8.0 through 0.8.5 allows remote attackers to cause a denial of service (CPU consumption) by performing a diff between large, crafted pages that trigger the worst case. | |
| Modificada | Media (4.3) | 1.2% | — | Hiki | 6/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Hiki 0.8.1 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via a page name in a Login link, a different vulnerability than CVE-2005-2336. | |
| Modificada | Media (4.3) | 1.2% | — | Hiki | 6/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Hiki 0.8.0 to 0.8.2 allows remote attackers to inject arbitrary web script or HTML via "missing pages" in which the page name is not properly escaped, a different vulnerability than CVE-2005-2803. |