Vulnerabilities
Summary — last 7 days
New vulnerabilities2,808▼ 273 vs. last week
Critical / high1,313▼ 193 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
9 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (8.8) | 0.26% | — | Care2xAI | 6/4/2026 | 10/6/2026 | Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config cookie parameter. Attackers can inject malicious SQL through the ck_config cookie in multiple endpoints including login.php, indexframe.php, and various module… | |
| Modified | Medium (5.4) | 0.65% | — | Care2x Hospital Information Management | 8/26/2021 | 6/17/2026 | Stored cross-site scripting (XSS) vulnerability in Care2x Hospital Information Management 2.7 Alpha. The vulnerability has found POST requests in /modules/registration_admission/patient_register.php page with "name_middle", "addr_str", "station", "name_maiden", "name_2", "name_3" parameters. | |
| Modified | Critical (9.8) | 1.9% | — | Care2x Hospital Information Management System | 8/6/2021 | 6/17/2026 | SQL Injection Vulnerability in Care2x Open Source Hospital Information Management 2.7 Alpha via the (1) pday, (2) pmonth, and (3) pyear parameters in GET requests sent to /modules/nursing/nursing-station.php. | |
| Modified | Medium (4.3) | 2.4% | 💥 Exploit | Hccgmbh Mycare2x | 8/13/2012 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in myCare2x allow remote attackers to inject arbitrary web script or HTML via the (1) name_last, (2) name_first, (3) name_middle, or (4) name_maiden parameter to modules/patient/mycare_pid.php; (5) favorites or (6) lang parameter to… | |
| Modified | High (7.5) | 1.1% | 💥 Exploit | Hccgmbh Mycare2x | 8/13/2012 | 6/16/2026 | SQL injection vulnerability in modules/patient/mycare2x_pat_info.php in myCare2x allows remote attackers to execute arbitrary SQL commands via the lang parameter. | |
| Modified | High (7.5) | 1.7% | 💥 Exploit | Hccgmbh Mycare2x | 8/13/2012 | 6/16/2026 | Multiple SQL injection vulnerabilities in myCare2x allow remote attackers to execute arbitrary SQL commands via the (1) aktion or (2) callurl parameter to modules/patient/mycare2x_pat_info.php; (3) dept_nr or (4) pid parameter to modules/importer/mycare2x_importer.php; (5) myOpsEintrag or (6) keyword parameter in a… | |
| Modified | High (7.5) | 2.7% | — | Care2x 2G | 10/12/2007 | 6/16/2026 | Multiple PHP remote file inclusion vulnerabilities in CARE2X 2G 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) en_copyrite.php, (2) vi_copyrite.php, and (3) ar_copyrite.php in language/ directories; (4) class_access.php, (5) class_department.php, (6)… | |
| Modified | Medium (5) | 1.1% | — | Care2x | 3/21/2007 | 6/16/2026 | CARE2X 2.2, and possibly earlier, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modified | Medium (6.8) | 7.1% | 💥 Exploit | Care2x | 3/14/2007 | 6/16/2026 | Multiple PHP remote file inclusion vulnerabilities in CARE2X 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) inc_checkdate_lang.php, (2) inc_charset_fx.php, (3) inc_config_color.php, (4) inc_currency_set.php, (5) inc_db_makelink.php, (6)… |