Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Doctor Appointment SystemAI | 4/9/2026 | 4/9/2026 | A flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the argument firstname causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Doctor Appointment SystemAI | 4/9/2026 | 11/9/2026 | A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be launched remotely. The exploit is now public and may be used. | |
| Aplazada | Media (5.5) | 0.43% | — | Code-projects Doctor Appointment SystemAI | 3/9/2026 | 5/9/2026 | A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (6.1) | 0.26% | — | Sourcecodester Doctor Appointment SystemAI | 29/5/2026 | 21/7/2026 | SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php. | |
| Aplazada | Media (5.5) | 0.55% | — | Sourcecodester Edoc Doctor Appointment SystemAI | 26/5/2026 | 24/7/2026 | A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly… | |
| Analizada | Baja (2) | 0.51% | — | Unguardable Online Doctor Appointment System | 20/3/2026 | 17/6/2026 | A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appointment_action.php. The manipulation of the argument appointment_id results in sql injection. The attack can be launched remotely. The exploit is now public and may be… | |
| Analizada | Media (5.5) | 0.58% | — | Unguardable Online Doctor Appointment System | 12/3/2026 | 17/6/2026 | A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the file /admin/doctor_action.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.58% | — | Unguardable Online Doctor Appointment System | 12/3/2026 | 17/6/2026 | A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. This impacts an unknown function of the file /admin/patient_action.php. Such manipulation of the argument patient_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Baja (2.1) | 0.49% | — | Remyandrade Doctor Appointment System | 27/2/2026 | 17/6/2026 | A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown functionality of the file /register.php of the component Sign Up Page. Executing a manipulation of the argument Email can lead to cross site scripting. The attack can be launched remotely. The exploit… | |
| Analizada | Alta (8.8) | 0.56% | — | Hashenudara Edoc-doctor-appointment-system | 11/12/2025 | 17/6/2026 | edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter. | |
| Analizada | Crítica (9.8) | 0.41% | — | Hashenudara Edoc-doctor-appointment-system | 2/12/2025 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php. | |
| Analizada | Media (6.9) | 0.60% | — | Projectworlds Doctor Appointment System | 3/4/2025 | 17/6/2026 | A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor/deleteschedule.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (6.9) | 0.60% | — | Projectworlds Doctor Appointment System | 3/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected is an unknown function of the file /doctor/deletepatient.php. The manipulation of the argument ic leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | |
| Analizada | Media (6.9) | 0.60% | — | Projectworlds Doctor Appointment System | 3/4/2025 | 17/6/2026 | A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /doctor/deleteappointment.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.93% | — | Doctor Appointment System Project Doctor Appointment System | 11/9/2023 | 17/6/2026 | Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php. | |
| Modificada | Crítica (9.8) | 1.0% | — | Doctor Appointment System Project Doctor Appointment System | 15/8/2023 | 17/6/2026 | Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The original reporter counterclaims that… | |
| Analizada | Media (5.4) | 0.61% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field. | |
| Analizada | Media (6.1) | 0.66% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field. | |
| Analizada | Alta (8.8) | 0.50% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php. | |
| Analizada | Crítica (9.8) | 1.2% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php. | |
| Analizada | Crítica (9.8) | 1.2% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php. | |
| Analizada | Crítica (9.8) | 1.2% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php. | |
| Analizada | Media (6.5) | 0.75% | — | Hashenudara Edoc-doctor-appointment-system | 26/8/2022 | 17/6/2026 | An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data. | |
| Modificada | Media (5.4) | 2.5% | — | Online Doctor Appointment System PHP Full Source Code Project Online Doctor Appointment System PHP Full Source Code | 23/7/2021 | 17/6/2026 | Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields. | |
| Modificada | Alta (7.5) | 9.3% | — | Doctor Appointment System Project Doctor Appointment System | 24/3/2021 | 17/6/2026 | Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter. |