Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.56% | — | Projectworlds Online Doctor Appointment Booking System PHP AND Mysql | 4/4/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /patient/invoice.php. The manipulation of the argument appid leads to sql injection. The attack can be launched remotely. The… | |
| Analizada | Media (6.9) | 0.64% | — | Projectworlds Online Doctor Appointment Booking System PHP AND Mysql | 3/4/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been classified as critical. Affected is an unknown function of the file /patient/patientupdateprofile.php. The manipulation of the argument patientFirstName leads to sql injection. It is possible to launch the attack… | |
| Analizada | Media (6.9) | 0.60% | — | Projectworlds Online Doctor Appointment Booking System PHP AND Mysql | 3/4/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /patient/profile.php?patientId=1. The manipulation of the argument patientFirstName leads to sql injection. The attack may be initiated remotely.… | |
| Analizada | Media (6.9) | 0.60% | — | Projectworlds Online Doctor Appointment Booking System PHP AND Mysql | 3/4/2025 | 17/6/2026 | A vulnerability has been found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /patient/patientupdateprofile.php. The manipulation of the argument patientFirstName leads to sql injection. The attack can be initiated remotely.… | |
| Analizada | Media (6.9) | 0.64% | — | Projectworlds Online Doctor Appointment Booking System PHP AND Mysql | 3/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in projectworlds Online Doctor Appointment Booking System 1.0. This affects an unknown part of the file /patient/getschedule.php. The manipulation of the argument q leads to sql injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.60% | — | Projectworlds Online Doctor Appointment Booking System PHP AND Mysql | 3/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this issue is some unknown functionality of the file /patient/appointment.php?scheduleDate=1&appid=1. The manipulation of the argument scheduleDate leads to sql injection. The… | |
| Modificada | Crítica (9.8) | 1.2% | — | Online Doctor Appointment Booking System PHP AND Mysql Project Online Doctor Appointment Booking System PHP AND Mysql | 17/2/2023 | 17/6/2026 | SQL Injection vulnerability in Projectworlds Online Doctor Appointment Booking System, allows attackers to gain sensitive information via the q parameter to the getuser.php endpoint. | |
| Modificada | Crítica (9.8) | 1.3% | — | Online Doctor Appointment Booking System PHP AND Mysql Project Online Doctor Appointment Booking System PHP AND Mysql | 2/12/2020 | 17/6/2026 | An SQL injection vulnerability was discovered in Online Doctor Appointment Booking System PHP and Mysql via the q parameter to getuser.php. |