VYPR

Vendor CVEs

Carmelo

All CVEs

162 total · sorted by risk
  • CVE-2026-26713CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.

  • CVE-2026-26712CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.

  • CVE-2026-26711CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.

  • CVE-2026-26710CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.

  • CVE-2026-26709CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.

  • CVE-2026-26696CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.

  • CVE-2026-26695CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.

  • CVE-2026-26694CriMar 2, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.

  • CVE-2025-69559CriJan 27, 2026
    risk 0.64cvss 9.8epss 0.01

    code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.

  • CVE-2025-60307CriOct 10, 2025
    risk 0.64cvss 9.8epss 0.00

    code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on the login page can bypass login attempts.

  • CVE-2025-29369CriApr 3, 2025
    risk 0.64cvss 9.8epss 0.01

    Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1.

  • CVE-2025-25914CriMar 17, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parameter

  • CVE-2024-25250CriMar 13, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.

  • CVE-2024-25251HigFeb 22, 2024
    risk 0.57cvss 8.8epss 0.01

    code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.

  • CVE-2022-32405HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/view_prison.php:4

  • CVE-2022-32403HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/inmates/manage_record.php:4

  • CVE-2022-32402HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/prisons/manage_prison.php:4

  • CVE-2022-32399HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/crimes/view_crime.php:4

  • CVE-2022-32398HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/manage_cell.php:4

  • CVE-2022-32397HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/visits/view_visit.php:4

  • CVE-2022-32392HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/manage_action.php:4

  • CVE-2022-32391HigJun 24, 2022
    risk 0.57cvss 8.8epss 0.01

    Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/actions/view_action.php:4

  • CVE-2024-24100HigFeb 27, 2024
    risk 0.54cvss 8.3epss 0.01

    Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.

  • CVE-2025-52327HigAug 1, 2025
    risk 0.51cvss 7.8epss 0.00

    SQL Injection vulnerability in Restaurant Order System 1.0 allows a local attacker to obtain sensitive information via the payment.php file

  • CVE-2024-24105HigMar 13, 2024
    risk 0.51cvss 7.8epss 0.00

    SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalidation.php.

  • CVE-2024-24096HigFeb 27, 2024
    risk 0.51cvss 7.8epss 0.00

    Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.

  • CVE-2024-10608HigNov 1, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Courier Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /login.php. The manipulation of the argument txtusername leads to sql injection. The attack may be initiated remotely.…

  • CVE-2024-10607HigNov 1, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Courier Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /track-result.php. The manipulation of the argument Consignment leads to sql injection. The attack can be initiated…

  • CVE-2023-6652HigDec 10, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Matrimonial Site 1.0. It has been declared as critical. Affected by this vulnerability is the function register of the file /register.php. The manipulation leads to sql injection. The attack can be launched remotely. The exploit has…

  • CVE-2023-6651HigDec 10, 2023
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in code-projects Matrimonial Site 1.0. It has been classified as critical. Affected is an unknown function of the file /auth/auth.php?user=1. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely.…

  • CVE-2026-5019HigMar 29, 2026
    risk 0.47cvss 7.3epss 0.01

    A security vulnerability has been detected in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file all-orders.php of the component Parameter Handler. The manipulation of the argument Status leads to sql injection. The…

  • CVE-2026-5018HigMar 28, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in code-projects Simple Food Order System 1.0. Affected is an unknown function of the file register-router.php of the component Parameter Handler. Executing a manipulation of the argument Name can lead to sql injection. The attack can be launched…

  • CVE-2026-5017HigMar 28, 2026
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in code-projects Simple Food Order System 1.0. This impacts an unknown function of the file /all-tickets.php of the component Parameter Handler. Performing a manipulation of the argument Status results in sql injection. The attack can be…

  • CVE-2026-4319HigMar 17, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was identified in code-projects Simple Food Order System 1.0. Affected by this vulnerability is an unknown functionality of the file /routers/add-item.php. Such manipulation of the argument price leads to sql injection. The attack can be launched remotely. The…

  • CVE-2026-3744HigMar 8, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in code-projects Student Web Portal 1.0. This impacts the function valreg_passwdation of the file signup.php. The manipulation of the argument reg_passwd leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed…

  • CVE-2026-3736HigMar 8, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this issue is some unknown functionality of the file SearchResultRoundtrip.php. Performing a manipulation of the argument from results in sql injection. The attack may be initiated…

  • CVE-2026-3735HigMar 8, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in code-projects Simple Flight Ticket Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file SearchResultOneway.php. Such manipulation of the argument from leads to sql injection. The attack can be launched…

  • CVE-2026-3723HigMar 8, 2026
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /Admindelete.php. The manipulation of the argument flightno results in sql injection. The attack may be performed from remote. The exploit…

  • CVE-2026-3709HigMar 8, 2026
    risk 0.47cvss 7.3epss 0.01

    A weakness has been identified in code-projects Simple Flight Ticket Booking System 1.0. This affects an unknown function of the file /register.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has…

  • CVE-2026-3708HigMar 8, 2026
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in code-projects Simple Flight Ticket Booking System 1.0. The impacted element is an unknown function of the file /login.php. Performing a manipulation of the argument Username results in sql injection. The attack may be initiated remotely.…

  • CVE-2026-3705HigMar 8, 2026
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. This issue affects some unknown processing of the file /Adminsearch.php. The manipulation of the argument flightno results in sql injection. It is possible to launch the attack remotely. The…

  • CVE-2026-2158HigFeb 8, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was detected in code-projects Student Web Portal 1.0. This impacts an unknown function of the file /check_user.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely.

  • CVE-2026-0700HigJan 8, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/check_admin.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely.…

  • CVE-2025-15243HigDec 30, 2025
    risk 0.47cvss 7.3epss 0.00

    A flaw has been found in code-projects Simple Stock System 1.0. This affects an unknown function of the file /market/login.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been published and…

  • CVE-2025-15011HigDec 22, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was found in code-projects Simple Stock System 1.0. Impacted is an unknown function of the file /logout.php. The manipulation of the argument uname results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.

  • CVE-2025-14968HigDec 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A security flaw has been discovered in code-projects Simple Stock System 1.0. Affected by this issue is some unknown functionality of the file /market/update.php. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit…

  • CVE-2025-14959HigDec 19, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in code-projects Simple Stock System 1.0. This issue affects some unknown processing of the file /market/signup.php. Executing a manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has…

  • CVE-2025-14647HigDec 14, 2025
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipulation of the argument bookisbn causes sql injection. It is possible to initiate the attack remotely. The exploit has been made…

  • CVE-2025-14590HigDec 13, 2025
    risk 0.47cvss 7.3epss 0.00

    A security vulnerability has been detected in code-projects Prison Management System 2.0. Impacted is an unknown function of the file /admin/search1.php. The manipulation of the argument keyname leads to sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-14223HigDec 8, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown functionality of the file /request.php. Such manipulation of the argument staff_id leads to sql injection. The attack may be launched remotely. The exploit has…

Page 1 of 4