Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Doctor Appointment System CRITICAL 9.8
CVE-2023-40945

Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php.

No fix yet
Fix from $2,300 2023-09-11
Doctor Appointment System CRITICAL 9.8
CVE-2023-39852

Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a thi…

No fix yet
Fix from $2,300 2023-08-15
Doctor Appointment System HIGH 7.5
CVE-2021-27319EPSS 8%

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via email pa…

No fix yet
Fix from $1,950 2021-03-24
Doctor Appointment System HIGH 7.5
CVE-2021-27320EPSS 9%

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via firstnam…

No fix yet
Fix from $1,950 2021-03-24
Doctor Appointment System HIGH 7.5
CVE-2021-27315EPSS 8%

Blind SQL injection in contactus.php in Doctor Appointment System 1.0 allows an unauthenticated attacker to insert malicious SQL queries via the comm…

No fix yet
Fix from $1,950 2021-03-24
Doctor Appointment System HIGH 7.5
CVE-2021-27316EPSS 8%

Blind SQL injection in contactus.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via lastname…

No fix yet
Fix from $1,950 2021-03-24
Doctor Appointment System CRITICAL 9.8
CVE-2021-27314EPSS 12%

SQL injection in admin.php in doctor appointment system 1.0 allows an unauthenticated attacker to insert malicious SQL queries via username parameter…

No fix yet
Fix from $2,300 2021-03-05
Doctor Appointment System MEDIUM 6.1
CVE-2021-27317

Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or …

No fix yet
Fix from $1,600 2021-03-01
Doctor Appointment System MEDIUM 6.1
CVE-2021-27318

Cross Site Scripting (XSS) vulnerability in contactus.php in Doctor Appointment System 1.0 allows remote attackers to inject arbitrary web script or …

No fix yet
Fix from $1,600 2021-03-01
Doctor Appointment System MEDIUM 6.5
CVE-2021-27124EPSS 6%

SQL injection in the expertise parameter in search_result.php in Doctor Appointment System v1.0 allows an authenticated patient user to dump the data…

No fix yet
Fix from $1,600 2021-02-18