CVE-2026-10299
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the fil
CVSS
3.8
Bajo
EPSS
0.3%
p19
KEV
—
Exploit Today
6
0-100
Publicado: 1 jun 2026 · Última mod.: 22 jul 2026 · CWE-99
0.3%EPSS · 30 días0.3%
2026-07-302026-08-26
A weakness has been identified in code-projects Online Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimings.php. This manipulation of the argument delid causes improper control of resource identifiers. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
- code-projects.orghttps://code-projects.org/
- github.comhttps://github.com/Carm3nc1ta/vuln-test/blob/main/Online%20Hospital%20Management%20System%20has%20IDOR%20vulnerability%20in%20viewdoctortimings_php.md
- vuldb.comhttps://vuldb.com/cve/CVE-2026-10299
- vuldb.comhttps://vuldb.com/submit/827505
- vuldb.comhttps://vuldb.com/vuln/367592
- vuldb.comhttps://vuldb.com/vuln/367592/cti
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-815245.4 MED—
———A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to pass without sanitization when the driver composes the target namespace for an operation. An application that incorporates untrusted input into these name components can have operations directed at a resource other than the one intended.6hCVE-2026-815216.5 MED—
———The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserved separator character without escaping it before the name is used to build the target namespace for the operation. An application that passes untrusted input as a database name could therefore have the write directed at a database and collection other than the ones it intended. Only the Client.BulkWrite API is affected.6hCVE-2026-629107.2 ALT49.7%
——15Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.13dCVE-2026-151866.3 MED34.2%
——10A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Portal Endpoint. The manipulation of the argument orderId leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor deleted the GitHub issue for this vulnerability without any explanation.49dCVE-2026-122074.3 MED13.1%
——4A security flaw has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5380834216b09ed. Impacted is the function actionGetPatientById of the file app\modules\medical\port\rest\controllers\PatientController.php of the component HTTP REST API. The manipulation of the argument ID results in improper control of resource identifiers. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure but did not respond in any way.35dCVE-2026-106244.3 MED15.1%
——5A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unknown functionality of the file /detailview.php of the component Employee View Page. Such manipulation of the argument employeeid leads to improper control of resource identifiers. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.36d