Code Projects
Products
273- 57 CVEs
- 47 CVEs
- 39 CVEs
- 36 CVEs
- 32 CVEs
- 28 CVEs
- 27 CVEs
- 26 CVEs
- 25 CVEs
- 24 CVEs
- 24 CVEs
- 24 CVEs
- 23 CVEs
- 21 CVEs
- 21 CVEs
- 19 CVEs
- 19 CVEs
- 18 CVEs
- 18 CVEs
- 18 CVEs
- 17 CVEs
- 16 CVEs
- 16 CVEs
- 15 CVEs
- 15 CVEs
- 15 CVEs
- 15 CVEs
- 14 CVEs
- 14 CVEs
- 13 CVEs
- View all 273 products →
Recent CVEs
1,456| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30887 | Cri | 0.66 | 9.8 | 0.26 | May 20, 2022 | Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file. | ||
| CVE-2026-26713 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php. | ||
| CVE-2026-26712 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php. | ||
| CVE-2026-26711 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php. | ||
| CVE-2026-26710 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php. | ||
| CVE-2026-26709 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php. | ||
| CVE-2026-26696 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php. | ||
| CVE-2026-26695 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php. | ||
| CVE-2026-26694 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php. | ||
| CVE-2025-70152 | Cri | 0.64 | 9.8 | 0.00 | Feb 18, 2026 | code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters… | ||
| CVE-2025-69564 | Cri | 0.64 | 9.8 | 0.00 | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password, confirm_password, Role, Branch, and Activate parameters. | ||
| CVE-2025-69563 | Cri | 0.64 | 9.8 | 0.00 | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter. | ||
| CVE-2025-69562 | Cri | 0.64 | 9.8 | 0.00 | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter. | ||
| CVE-2025-69559 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2026 | code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php. | ||
| CVE-2025-69565 | Cri | 0.64 | 9.8 | 0.00 | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php. | ||
| CVE-2025-60736 | Cri | 0.64 | 9.8 | 0.00 | Dec 2, 2025 | code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter. | ||
| CVE-2025-63622 | Cri | 0.64 | 9.8 | 0.00 | Oct 29, 2025 | A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/admin/subcategory.php. This manipulation of the argument category causes SQL injection. | ||
| CVE-2025-60306 | Cri | 0.64 | 9.9 | 0.00 | Oct 10, 2025 | code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations. | ||
| CVE-2025-40731 | Cri | 0.64 | 9.8 | 0.00 | Jun 30, 2025 | SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, update and delete databases through the pname, pprice and id parameters in /update.php. | ||
| CVE-2025-29369 | Cri | 0.64 | 9.8 | 0.01 | Apr 3, 2025 | Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1. |
- risk 0.66cvss 9.8epss 0.26
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.
- risk 0.64cvss 9.8epss 0.01
code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters…
- risk 0.64cvss 9.8epss 0.00
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password, confirm_password, Role, Branch, and Activate parameters.
- risk 0.64cvss 9.8epss 0.00
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter.
- risk 0.64cvss 9.8epss 0.00
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter.
- risk 0.64cvss 9.8epss 0.01
code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.
- risk 0.64cvss 9.8epss 0.00
A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/admin/subcategory.php. This manipulation of the argument category causes SQL injection.
- risk 0.64cvss 9.9epss 0.00
code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, update and delete databases through the pname, pprice and id parameters in /update.php.
- risk 0.64cvss 9.8epss 0.01
Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1.