Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.43%—Code-projects Doctor Appointment SystemAI4/9/20264/9/2026
A flaw has been found in code-projects Doctor Appointment System 1.0. This issue affects some unknown processing of the file /contactus.php. This manipulation of the argument firstname causes sql injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
AplazadaMedia (5.5)0.43%—Code-projects Doctor Appointment SystemAI4/9/202611/9/2026
A vulnerability was detected in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient/booking.php. The manipulation of the argument doc_id results in sql injection. The attack may be launched remotely. The exploit is now public and may be used.
AplazadaMedia (5.5)0.43%—Code-projects Doctor Appointment SystemAI3/9/20265/9/2026
A vulnerability was identified in code-projects Doctor Appointment System 1.0. This vulnerability affects unknown code of the file /patient_login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
AplazadaMedia (6.1)0.26%—Sourcecodester Doctor Appointment SystemAI29/5/202621/7/2026
SourceCodester Doctor Appointment System 1.0 is vulnerable to Cross Site Scripting (XSS) due to improper handling of user supplied input in the user registration functionality in register.php.
AplazadaMedia (5.5)0.55%—Sourcecodester Edoc Doctor Appointment SystemAI26/5/202624/7/2026
A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument ID leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly…
AnalizadaBaja (2)0.51%—Unguardable Online Doctor Appointment System20/3/202617/6/2026
A vulnerability was detected in itsourcecode Online Doctor Appointment System 1.0. This issue affects some unknown processing of the file /admin/appointment_action.php. The manipulation of the argument appointment_id results in sql injection. The attack can be launched remotely. The exploit is now public and may be…
AnalizadaMedia (5.5)0.58%—Unguardable Online Doctor Appointment System12/3/202617/6/2026
A vulnerability was found in itsourcecode Online Doctor Appointment System 1.0. Affected is an unknown function of the file /admin/doctor_action.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
AnalizadaMedia (5.5)0.58%—Unguardable Online Doctor Appointment System12/3/202617/6/2026
A vulnerability has been found in itsourcecode Online Doctor Appointment System 1.0. This impacts an unknown function of the file /admin/patient_action.php. Such manipulation of the argument patient_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be…
AnalizadaBaja (2.1)0.49%—Remyandrade Doctor Appointment System27/2/202617/6/2026
A weakness has been identified in SourceCodester Doctor Appointment System 1.0. Affected by this issue is some unknown functionality of the file /register.php of the component Sign Up Page. Executing a manipulation of the argument Email can lead to cross site scripting. The attack can be launched remotely. The exploit…
AnalizadaAlta (8.8)0.56%—Hashenudara Edoc-doctor-appointment-system11/12/202517/6/2026
edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.
AnalizadaCrítica (9.8)0.41%—Hashenudara Edoc-doctor-appointment-system2/12/202517/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.
AnalizadaMedia (6.9)0.60%—Projectworlds Doctor Appointment System3/4/202517/6/2026
A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor/deleteschedule.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit…
AnalizadaMedia (6.9)0.60%—Projectworlds Doctor Appointment System3/4/202517/6/2026
A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected is an unknown function of the file /doctor/deletepatient.php. The manipulation of the argument ic leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
AnalizadaMedia (6.9)0.60%—Projectworlds Doctor Appointment System3/4/202517/6/2026
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /doctor/deleteappointment.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has…
ModificadaCrítica (9.8)0.93%—Doctor Appointment System Project Doctor Appointment System11/9/202317/6/2026
Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.
ModificadaCrítica (9.8)1.0%—Doctor Appointment System Project Doctor Appointment System15/8/202317/6/2026
Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The original reporter counterclaims that…
AnalizadaMedia (5.4)0.61%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field.
AnalizadaMedia (6.1)0.66%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search field.
AnalizadaAlta (8.8)0.50%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php.
AnalizadaCrítica (9.8)1.2%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.
AnalizadaCrítica (9.8)1.2%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.
AnalizadaCrítica (9.8)1.2%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.
AnalizadaMedia (6.5)0.75%—Hashenudara Edoc-doctor-appointment-system26/8/202217/6/2026
An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data.
ModificadaMedia (5.4)2.5%—Online Doctor Appointment System PHP Full Source Code Project Online Doctor Appointment System PHP Full Source Code23/7/202117/6/2026
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment System 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in the First Name, Last Name, and Address text fields.
ModificadaAlta (7.5)9.3%—Doctor Appointment System Project Doctor Appointment System24/3/202117/6/2026
Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstname parameter.