Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Projectworlds Hospital-management-system-in-phpAI | 18/5/2026 | 17/6/2026 | A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the function getAllPatientDetail of the file update_info.php of the component GET Parameter Handler. Executing a manipulation of the argument appointment_no can lead to sql injection. The attack may be… | |
| Modificada | Crítica (9.8) | 1.1% | — | Projectworlds Hospital Management System IN PHP | 28/9/2023 | 17/6/2026 | Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI. | |
| Modificada | Crítica (9.8) | 1.1% | — | Projectworlds Hospital Management System IN PHP | 28/9/2023 | 17/6/2026 | Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI. | |
| Modificada | Media (5.3) | 0.68% | — | Projectworlds Hospital Management System IN PHP | 16/3/2022 | 17/6/2026 | An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patients without restriction via add_patient.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Projectworlds Hospital Management System IN PHP | 22/12/2021 | 17/6/2026 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php. | |
| Modificada | Alta (8.8) | 2.0% | — | Projectworlds Hospital Management System IN PHP | 22/12/2021 | 17/6/2026 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticated malicious user can compromise the databases system and in some cases leverage this vulnerability to get remote code execution on the remote web server. | |
| Modificada | Crítica (9.8) | 1.1% | — | Projectworlds Hospital Management System IN PHP | 22/12/2021 | 17/6/2026 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php. | |
| Modificada | Crítica (9.8) | 1.1% | — | Projectworlds Hospital Management System IN PHP | 22/12/2021 | 17/6/2026 | Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php. |