Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.19% | — | Iqonic KivicareAI | 1/9/2026 | 1/9/2026 | The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient roster and, when a payment gateway is configured, the payment gateway secret key. | |
| Aplazada | Media (6.5) | 0.34% | — | Iqonic KivicareAI | 19/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticated patient-level users to download any file in the media library, including other patients' uploaded medical reports. | |
| Aplazada | Media (4.3) | 0.27% | — | Iqonic KivicareAI | 19/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user owns the appointment being modified, allowing authenticated patient-level users to cancel and reschedule other patients' appointments. | |
| Aplazada | Media (6.5) | 0.41% | — | Iqonic KivicareAI | 15/8/2026 | 20/8/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'searchTerm' parameter in all versions up to, and including, 4.5.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Alta (7.5) | 0.41% | — | Iqonic KivicareAI | 13/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauthenticated attackers to create an active, privileged clinic-staff (doctor) account with full access to patient records, billing and clinic data. | |
| Aplazada | Alta (8.8) | 0.43% | — | Iqonic KivicareAI | 12/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection. | |
| Aplazada | Media (4.3) | 0.25% | — | Iqonic KivicareAI | 12/8/2026 | 26/8/2026 | The KiviCare WordPress plugin before 4.5.2 does not verify that the requesting user owns the records being accessed, allowing authenticated patient-level users to read other patients' bills, invoices and appointment details. | |
| Aplazada | Media (6.5) | 0.41% | — | Iqonic KivicareAI | 11/7/2026 | 15/7/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (6.5) | 0.47% | — | Iqonic KivicareAI | 11/7/2026 | 13/7/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all versions up to, and including, 4.5.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This… | |
| Aplazada | Media (5.3) | 0.56% | — | Iqonic KivicareAI | 10/7/2026 | 10/7/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to mark… | |
| Aplazada | Media (6.3) | 0.26% | — | Iqonic KivicareAI | 15/6/2026 | 17/6/2026 | Subscriber Insecure Direct Object References (IDOR) in KiviCare <= 4.2.1 versions. | |
| Aplazada | Alta (8.2) | 0.44% | — | Iqonic KivicareAI | 27/5/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Password Recovery Exploitation.This issue affects KiviCare: from n/a through <= 4.3.0. | |
| Aplazada | Alta (7.1) | 0.18% | — | Iqonic KivicareAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Reflected XSS.This issue affects KiviCare: from n/a through <= 3.6.16. | |
| Aplazada | Media (6.5) | 0.19% | — | Iqonic KivicareAI | 25/3/2026 | 17/6/2026 | Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.16. | |
| Aplazada | Alta (8.2) | 0.42% | — | Iqonic KivicareAI | 18/3/2026 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization on the `/wp-json/kivicare/v1/setup-wizard/clinic` REST API endpoint in all versions up to, and including, 4.1.2. This makes it possible for unauthenticated attackers to create… | |
| Aplazada | Alta (7.3) | 0.54% | — | Iqonic KivicareAI | 18/3/2026 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.1.2. This is due to the `patientSocialLogin()` function not verifying the social provider access token before authenticating a user. This makes it possible for… | |
| Aplazada | Alta (8.5) | 0.24% | — | Iqonic KivicareAI | 3/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Blind SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.16. | |
| Aplazada | Media (5.3) | 0.33% | — | Iqonic KivicareAI | 23/1/2026 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to arbitrary file uploads due to missing authorization checks in the uploadMedicalReport() function in all versions up to, and including, 3.6.15. This makes it possible for unauthenticated attackers to upload text files and PDF… | |
| Aplazada | Alta (8.5) | 0.24% | — | Iqonic KivicareAI | 21/11/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows SQL Injection.This issue affects KiviCare: from n/a through <= 3.6.13. | |
| Analizada | Alta (8.8) | 0.53% | — | Iqonic Kivicare | 28/2/2025 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the ‘u_id’ parameter in all versions up to, and including, 3.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it… | |
| Analizada | Media (6.5) | 0.41% | — | Iqonic Kivicare | 6/12/2024 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'sort[]' parameter of the static_data_list AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the… | |
| Analizada | Media (6.5) | 0.58% | — | Iqonic Kivicare | 6/12/2024 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'service_list[0][service_id]' parameter of the get_widget_payment_options AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of… | |
| Analizada | Alta (7.5) | 14% | — | Iqonic Kivicare | 6/12/2024 | 17/6/2026 | The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to SQL Injection via the 'visit_type[service_id]' parameter of the tax_calculated_data AJAX action in all versions up to, and including, 3.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient… | |
| Modificada | Alta (8.8) | 0.34% | — | Iqonic Kivicare | 8/6/2024 | 17/6/2026 | Missing Authorization vulnerability in Iqonic Design KiviCare kivicare-clinic-management-system allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects KiviCare: from n/a through <= 3.6.6. | |
| Modificada | Alta (8.8) | 0.39% | — | Iqonic Kivicare | 27/6/2023 | 17/6/2026 | The KiviCare WordPress plugin before 3.2.1 does not have CSRF checks (either flawed or missing completely) in various AJAX actions, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks. This includes, but is not limited to: Delete arbitrary appointments/medical records/etc,… |