Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.52% | — | Subhajitkhan Online-clinic-management-systemAI | 15/9/2026 | 15/9/2026 | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Affected by this vulnerability is the function session_start of the file adminappview.php. Executing a manipulation of the argument adminmail can lead to authorization bypass. The attack may be… | |
| Aplazada | Media (5.5) | 0.43% | — | Subhajitkhan Online-clinic-management-systemAI | 14/9/2026 | 15/9/2026 | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. This affects an unknown part of the file doctorlogin.php. Executing a manipulation of the argument doc_mail/doc_pswd can lead to sql injection. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.43% | — | Subhajitkhan Online-clinic-management-systemAI | 14/9/2026 | 14/9/2026 | A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. The affected element is an unknown function of the file listdoctor.php. Performing a manipulation of the argument searchtext results in sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Media (5.5) | 0.43% | — | Itsourcecode Online Clinic Management SystemAI | 24/8/2026 | 24/8/2026 | A vulnerability has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file success/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been… | |
| Analizada | Baja (2.1) | 0.34% | — | Angeljudesuarez Online Clinic Management System | 26/9/2025 | 17/6/2026 | A weakness has been identified in itsourcecode Online Clinic Management System 1.0. Affected is an unknown function of the file /details.php?action=post. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been made available to the public and could… | |
| Analizada | Baja (2.1) | 0.38% | — | Angeljudesuarez Online Clinic Management System | 17/9/2025 | 17/6/2026 | A flaw has been found in itsourcecode Online Clinic Management System 1.0. This vulnerability affects unknown code of the file /editp2.php. Executing manipulation of the argument id/firstname/lastname/type/age/address can lead to sql injection. The attack can be executed remotely. The exploit has been published and… | |
| Analizada | Baja (2.1) | 0.47% | — | Angeljudesuarez Online Clinic Management System | 17/9/2025 | 25/9/2026 | A security vulnerability has been detected in itsourcecode Online Clinic Management System 1.0. Affected by this issue is some unknown functionality of the file transact.php. Such manipulation of the argument firstname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly… | |
| Analizada | Alta (8.1) | 0.46% | — | Angeljudesuarez Online Clinic Management System | 21/10/2024 | 17/6/2026 | Online Clinic Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /success/editp.php?action=edit. | |
| Modificada | Crítica (9.8) | 0.58% | — | Angeljudesuarez Online Clinic Management System | 16/7/2024 | 17/6/2026 | Online Clinic Management System In PHP With Free Source code v1.0 was discovered to contain a SQL injection vulnerability via the user parameter at login.php. | |
| Modificada | Media (5.4) | 0.39% | — | Bigprof Online Clinic Management System | 30/11/2023 | 17/6/2026 | A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /clinic/medical_records_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store… | |
| Modificada | Media (5.4) | 0.39% | — | Bigprof Online Clinic Management System | 30/11/2023 | 17/6/2026 | A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /clinic/disease_symptoms_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store… | |
| Modificada | Media (5.4) | 0.39% | — | Bigprof Online Clinic Management System | 30/11/2023 | 17/6/2026 | A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /clinic/events_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous… | |
| Modificada | Media (5.4) | 0.39% | — | Bigprof Online Clinic Management System | 30/11/2023 | 17/6/2026 | A vulnerability has been discovered in BigProf Online Clinic Management System 2.2, which does not sufficiently encode user-controlled input, resulting in persistent XSS through /clinic/patients_view.php, in the FirstRecord parameter. Exploitation of this vulnerability could allow an attacking user to store dangerous… |