Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hashenudara

First CVE: Aug 26, 2022Active for: 4 yearsTotal CVEs: 9

Hashenudara's vulnerability footprint centers on its eDoc Doctor Appointment System, a web-based medical scheduling and documentation platform vulnerable to application-layer weaknesses. The disclosures skew strongly toward critical-severity outcomes and recur across input-handling and request-validation flaws, including SQL injection, cross-site scripting, CSRF, and improper input validation, reflecting the exposure surface typical of healthcare web applications handling patient data and appointment workflows. Current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hashenudara over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 26, 2022
3 years ago
Most Recent CVE
Dec 11, 2025
225 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-36545CRITICAL
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/settings.php.
Aug 26, 20229.831NONO
CVE-2022-36544CRITICAL
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/booking.php.
Aug 26, 20229.831NONO
CVE-2025-65358CRITICAL
Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at /admin/appointment.php.
Dec 2, 20259.830NONO
CVE-2022-36546HIGH
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a Cross-Site Request Forgery (CSRF) via /patient/settings.php.
Aug 26, 20228.828NONO
CVE-2025-66918HIGH
edoc-doctor-appointment-system v1.0.1 is vulnerable to Cross Site Scripting (XSS) in admin/add-session.php via the "title" parameter.
Dec 11, 20258.827NONO
CVE-2022-36543CRITICAL
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a SQL injection vulnerability via the id parameter at /patient/doctors.php.
Aug 26, 20229.824NONO
CVE-2022-36542MEDIUM
An access control issue in the component /ip/admin/ of Edoc-doctor-appointment-system v1.0.1 allows attackers to arbitrarily edit, read, and delete Administrator data.
Aug 26, 20226.523NONO
CVE-2022-36547MEDIUM
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability at /patient/index.php. This vulnerability allows attackers to e
Aug 26, 20226.122NONO
CVE-2022-36548MEDIUM
Edoc-doctor-appointment-system v1.0.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability at /patient/settings.php. This vulnerability allows attackers to e
Aug 26, 20225.421NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
33%
22%
44%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low2 (22.2%)
High1 (11.1%)
None6 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hashenudara.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hashenudara — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hashenudara's Products

View all 1 CNAs →

Top CWEs