VYPR

Vendor CVEs

Carmelo

All CVEs

162 total · sorted by risk
  • CVE-2024-28279HigMay 14, 2024
    risk 0.47cvss 7.3epss 0.00

    Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.

  • CVE-2026-4533MedMar 22, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file all-tickets.php. The manipulation of the argument Status results in sql injection. It is possible to launch the attack remotely. The…

  • CVE-2026-3745MedMar 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in code-projects Student Web Portal 1.0. Affected is an unknown function of the file profile.php. The manipulation of the argument User results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

  • CVE-2025-14834MedDec 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in code-projects Simple Stock System 1.0. This affects an unknown function of the file /checkuser.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be launched remotely. The exploit has been made…

  • CVE-2025-14589MedDec 13, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in code-projects Prison Management System 2.0. This issue affects some unknown processing of the file /admin/search.php. Executing a manipulation of the argument keyname can lead to sql injection. The attack may be performed from remote. The…

  • CVE-2025-14230MedDec 8, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in code-projects Daily Time Recording System 4.5.0. The impacted element is an unknown function of the file /admin/add_payroll.php. Performing manipulation of the argument detail_Id results in sql injection. The attack can be initiated remotely. The…

  • CVE-2025-14222MedDec 8, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file /print_personnel_report.php. This manipulation of the argument per_id causes sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-14203MedDec 7, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in code-projects Question Paper Generator up to 1.0. This vulnerability affects unknown code of the file /selectquestionuser.php. This manipulation of the argument subid causes sql injection. Remote exploitation of the attack is possible. The exploit has…

  • CVE-2025-14195MedDec 7, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in code-projects Employee Profile Management System 1.0. Impacted is an unknown function of the file /profiling/add_file_query.php. The manipulation of the argument per_file results in unrestricted upload. The attack may be launched remotely.…

  • CVE-2025-14193MedDec 7, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in code-projects Employee Profile Management System 1.0. This vulnerability affects unknown code of the file /view_personnel.php. Executing a manipulation of the argument per_id can lead to sql injection. The attack can be launched remotely. The…

  • CVE-2025-13396MedNov 19, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This manipulation of the argument OfficeName causes sql injection. The attack may be initiated remotely. The exploit has been made…

  • CVE-2025-13303MedNov 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /search-edit.php. This manipulation of the argument Consignment causes sql injection. The attack can be initiated remotely. The exploit…

  • CVE-2025-12263MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /edit_judge.php. The manipulation of the argument judge_id leads to sql injection. The attack may be initiated remotely. The exploit is publicly available…

  • CVE-2025-12262MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in code-projects Online Event Judging System 1.0. This impacts an unknown function of the file /edit_criteria.php. Executing manipulation of the argument crit_id can lead to sql injection. The attack can be launched remotely. The exploit has been…

  • CVE-2025-12256MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in code-projects Online Event Judging System 1.0. This vulnerability affects unknown code of the file /edit_contestant.php. Executing manipulation of the argument contestant_id can lead to sql injection. The attack can be executed remotely. The…

  • CVE-2025-12255MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown part of the file /add_contestant.php. Performing manipulation of the argument fullname results in sql injection. Remote exploitation of the attack is possible. The…

  • CVE-2025-12254MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in code-projects Online Event Judging System 1.0. Affected by this issue is some unknown functionality of the file /add_judge.php. Such manipulation of the argument fullname leads to sql injection. The attack may be launched remotely. The exploit…

  • CVE-2025-12252MedOct 27, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in code-projects Online Event Judging System 1.0. Affected is an unknown function of the file /ajax/action.php. The manipulation of the argument content results in sql injection. The attack can be launched remotely. The exploit has been made public and…

  • CVE-2025-11553MedOct 9, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /add-courier.php. Executing manipulation of the argument Shippername can lead to sql injection. The attack can be launched…

  • CVE-2025-11551MedOct 9, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in code-projects Student Result Manager 1.0. This affects an unknown function of the file src/students/Database.java. This manipulation of the argument roll/name/gpa causes sql injection. It is possible to initiate the attack remotely. The exploit…

  • CVE-2025-8165MedJul 25, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in code-projects Food Review System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/approve_reservation.php. The manipulation of the argument occasion leads to sql injection. The attack may be initiated…

  • CVE-2025-8018MedJul 22, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in code-projects Food Ordering Review System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /user/reservation_page.php. The manipulation of the argument reg_Id leads to sql injection. The…

  • CVE-2025-7181MedJul 8, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, was found in code-projects Staff Audit System 1.0. Affected is an unknown function of the file /test.php. The manipulation of the argument uploadedfile leads to unrestricted upload. It is possible to launch the attack remotely.…

  • CVE-2025-6890MedJun 30, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /ticketConfirmation.php. The manipulation of the argument Date leads to sql injection. The attack may be initiated…

  • CVE-2025-6884MedJun 30, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability, which was classified as critical, has been found in code-projects Staff Audit System 1.0. This issue affects some unknown processing of the file /search_index.php. The manipulation of the argument Search leads to sql injection. The attack may be initiated…

  • CVE-2025-6883MedJun 30, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability classified as critical was found in code-projects Staff Audit System 1.0. This vulnerability affects unknown code of the file /update_index.php. The manipulation of the argument updateid leads to sql injection. The attack can be initiated remotely. The exploit…

  • CVE-2024-0460MedJan 12, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in code-projects Faculty Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/pages/student-print.php. The manipulation leads to sql injection. The attack may be initiated remotely. The exploit…

  • CVE-2023-7130MedDec 31, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability has been found in code-projects College Notes Gallery 2.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument user leads to sql injection. The exploit has been disclosed to…

  • CVE-2023-7131MedDec 28, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in code-projects Intern Membership Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /user_registration/ of the component User Registration. The manipulation of the argument userName leads…

  • CVE-2025-56280MedSep 16, 2025
    risk 0.35cvss 5.4epss 0.00

    code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the area where users submit reservation information.

  • CVE-2025-56276MedSep 16, 2025
    risk 0.35cvss 5.4epss 0.00

    code-projects Food Ordering Review System 1.0 is vulnerable to Cross Site Scripting (XSS) in the registration function. An attacker enters malicious JavaScript code as a username, which triggers the XSS vulnerability when the admin views user information, resulting in the…

  • CVE-2026-4532MedMar 22, 2026
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in code-projects Simple Food Ordering System up to 1.0. Affected by this vulnerability is an unknown functionality of the file /food/sql/food.sql of the component Database Backup Handler. The manipulation leads to files or directories…

  • CVE-2026-26698MedMar 2, 2026
    risk 0.32cvss 4.9epss 0.00

    code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/modal_edit.php.

  • CVE-2026-26697MedMar 2, 2026
    risk 0.32cvss 4.9epss 0.00

    code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_view.php?teacherID=.

  • CVE-2026-3711MedMar 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was detected in code-projects Simple Flight Ticket Booking System 1.0. Affected is an unknown function of the file /Adminupdate.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp results in sql injection. The…

  • CVE-2026-3710MedMar 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in code-projects Simple Flight Ticket Booking System 1.0. This impacts an unknown function of the file /Adminadd.php. The manipulation of the argument flightno/airplaneid/departure/dtime/arrival/atime/ec/ep/bc/bp leads to sql injection.…

  • CVE-2026-0850MedJan 11, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /admin/delete_activity.php. Executing a manipulation of the argument activity_id can lead to sql injection. The attack may be launched remotely.…

  • CVE-2026-0729MedJan 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was detected in code-projects Intern Membership Management System 1.0. Impacted is an unknown function of the file /intern/admin/add_activity.php. Performing a manipulation of the argument Title results in sql injection. Remote exploitation of the attack is…

  • CVE-2026-0728MedJan 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in code-projects Intern Membership Management System 1.0. This issue affects some unknown processing of the file /intern/admin/delete_admin.php. Such manipulation of the argument admin_id leads to sql injection. The attack may be…

  • CVE-2026-0701MedJan 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was identified in code-projects Intern Membership Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /intern/admin/add_admin.php. The manipulation of the argument Username leads to sql injection. The attack is possible…

  • CVE-2026-0699MedJan 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in code-projects Intern Membership Management System 1.0. This impacts an unknown function of the file /intern/admin/edit_activity.php. Performing a manipulation of the argument activity_id results in sql injection. Remote exploitation of the attack is…

  • CVE-2026-0698MedJan 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in code-projects Intern Membership Management System 1.0. This affects an unknown function of the file /intern/admin/edit_students.php. Such manipulation of the argument admin_id leads to sql injection. The attack may be launched remotely. The…

  • CVE-2026-0697MedJan 8, 2026
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in code-projects Intern Membership Management System 1.0. The impacted element is an unknown function of the file /intern/admin/edit_admin.php. This manipulation of the argument admin_id causes sql injection. The attack may be initiated remotely. The…

  • CVE-2025-14642MedDec 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability has been found in code-projects Computer Laboratory System 1.0. Impacted is an unknown function of the file technical_staff_pic.php. Such manipulation of the argument image leads to unrestricted upload. The attack may be launched remotely. The exploit has been…

  • CVE-2025-14641MedDec 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in code-projects Computer Laboratory System 1.0. This issue affects some unknown processing of the file admin/admin_pic.php. This manipulation of the argument image causes unrestricted upload. The attack may be initiated remotely. The exploit has been…

  • CVE-2025-13302MedNov 17, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument ManagerName leads to sql injection. The attack can be launched remotely. The exploit is publicly…

  • CVE-2023-7096MedDec 25, 2023
    risk 0.31cvss 4.7epss 0.01

    A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the file /admin/php/crud.php. This manipulation of the argument fieldname/tablename causes sql injection. The attack is possible to be carried out remotely. The…

  • CVE-2026-3763MedMar 8, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in code-projects Simple Flight Ticket Booking System 1.0. The affected element is an unknown function of the file showhistory.php. The manipulation results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made…

  • CVE-2025-14962MedDec 19, 2025
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in code-projects Simple Stock System 1.0. The impacted element is an unknown function of the file /market/chatuser.php. This manipulation causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been published and may…

  • CVE-2025-14531MedDec 11, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in code-projects Rental Management System 2.0. This affects an unknown function of the file Transaction.java of the component Log Handler. Performing manipulation results in crlf injection. The attack can be initiated remotely. The exploit has been made…