Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.53% | — | Code-projects Hospital Information SystemAI | 7/9/2026 | 9/9/2026 | A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. Remote exploitation of the attack is possible.… | |
| Aplazada | Baja (2) | 0.35% | — | Code-projects Hospital Information SystemAI | 7/9/2026 | 8/9/2026 | A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the component Patient Management. Such manipulation of the argument ID leads to cross site scripting. The attack may be launched remotely. The exploit has… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital Information SystemAI | 4/9/2026 | 8/9/2026 | A security flaw has been discovered in code-projects Hospital Information System 1.0. Affected by this vulnerability is the function getSinglePresp of the file includes/presp/PrespController.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital Information SystemAI | 4/9/2026 | 4/9/2026 | A vulnerability was identified in code-projects Hospital Information System 1.0. Affected is the function viewReq of the file viewReq.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital Information SystemAI | 4/9/2026 | 4/9/2026 | A vulnerability was determined in code-projects Hospital Information System 1.0. This impacts the function findBySearch of the file addReq.php. This manipulation of the argument Search causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Hospital Information SystemAI | 19/8/2026 | 25/8/2026 | A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/UsersController.php of the component User Login Handler. This manipulation of the argument email causes sql injection. The attack is possible to be carried out remotely.… | |
| Aplazada | Alta (8.7) | 0.40% | — | Unimax Hospital Information SystemAI | 17/7/2025 | 17/6/2026 | The Hospital Information System developed by UNIMAX has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Modificada | Media (4.8) | 0.64% | — | Code-projects Hospital Information System | 14/8/2023 | 17/6/2026 | Code Projects Hospital Information System 1.0 is vulnerable to Cross Site Scripting (XSS) | |
| Modificada | Crítica (9.8) | 2.8% | — | Hospital Information System Project Hospital Information System | 14/9/2022 | 17/6/2026 | Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. |