Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Hospital Management System Project Subscribe
Total 39 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-48120 1 Hospital Management System Project 1 Hospital Management System 2023-01-27 N/A 9.8 CRITICAL
SQL Injection vulnerability in kishan0725 Hospital Management System thru commit 4770d740f2512693ef8fd9aa10a8d17f79fad9bd (on March 13, 2021), allows attackers to execute arbitrary commands via the contact and doctor parameters to /search.php.
CVE-2022-46093 1 Hospital Management System Project 1 Hospital Management System 2023-01-24 N/A 8.2 HIGH
Hospital Management System v1.0 is vulnerable to SQL Injection. Attackers can gain administrator privileges without the need for a password.
CVE-2021-35388 1 Hospital Management System Project 1 Hospital Management System 2022-10-28 N/A 5.4 MEDIUM
Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php.
CVE-2021-35387 1 Hospital Management System Project 1 Hospital Management System 2022-10-28 N/A 8.8 HIGH
Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php.
CVE-2022-42205 1 Hospital Management System Project 1 Hospital Management System 2022-10-21 N/A 5.4 MEDIUM
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via add-patient.php.
CVE-2022-42206 1 Hospital Management System Project 1 Hospital Management System 2022-10-21 N/A 5.4 MEDIUM
PHPGurukul Hospital Management System In PHP V 4.0 is vulnerable to Cross Site Scripting (XSS) via doctor/view-patient.php, admin/view-patient.php, and view-medhistory.php.
CVE-2022-38637 1 Hospital Management System Project 1 Hospital Management System 2022-09-15 N/A 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the Username and Password parameters on the Login page.
CVE-2022-34590 1 Hospital Management System Project 1 Hospital Management System 2022-07-26 N/A 7.2 HIGH
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in /HMS/admin.php.
CVE-2022-32094 1 Hospital Management System Project 1 Hospital Management System 2022-07-08 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at doctorlogin.php.
CVE-2022-32095 1 Hospital Management System Project 1 Hospital Management System 2022-07-08 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter at orders.php.
CVE-2022-32093 1 Hospital Management System Project 1 Hospital Management System 2022-07-08 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the loginid parameter at adminlogin.php.
CVE-2021-44095 1 Hospital Management System Project 1 Hospital Management System 2022-06-08 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in ProjectWorlds Hospital Management System in php 1.0 on login page that allows a remote attacker to compromise Application SQL database.
CVE-2022-30516 1 Hospital Management System Project 1 Hospital Management System 2022-06-03 7.5 HIGH 9.8 CRITICAL
In Hospital-Management-System v1.0, the editid parameter in the doctor.php page is vulnerable to SQL injection attacks.
CVE-2022-30012 1 Hospital Management System Project 1 Hospital Management System 2022-05-24 5.0 MEDIUM 7.5 HIGH
In the POST request of the appointment.php page of HMS v.0, there are SQL injection vulnerabilities in multiple parameters, and database information can be obtained through injection.
CVE-2022-28929 1 Hospital Management System Project 1 Hospital Management System 2022-05-23 7.5 HIGH 9.8 CRITICAL
Hospital Management System v1.0 was discovered to contain a SQL injection vulnerability via the delid parameter at viewtreatmentrecord.php.
CVE-2022-30449 1 Hospital Management System Project 1 Hospital Management System 2022-05-20 7.5 HIGH 9.8 CRITICAL
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a SQL injection vulnerability via the editid parameter in room.php.
CVE-2022-30448 1 Hospital Management System Project 1 Hospital Management System 2022-05-20 7.5 HIGH 9.8 CRITICAL
Hospital Management System in PHP with Source Code (HMS) 1.0 was discovered to contain a File upload vulnerability in treatmentrecord.php.
CVE-2022-25492 1 Hospital Management System Project 1 Hospital Management System 2022-05-12 7.5 HIGH 9.8 CRITICAL
HMS v1.0 was discovered to contain a SQL injection vulnerability via the medicineid parameter in ajaxmedicine.php.
CVE-2022-26546 1 Hospital Management System Project 1 Hospital Management System 2022-05-12 6.4 MEDIUM 9.1 CRITICAL
Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and obtain the admin password.
CVE-2022-25493 1 Hospital Management System Project 1 Hospital Management System 2022-05-12 4.3 MEDIUM 6.1 MEDIUM
HMS v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via treatmentrecord.php.