Vendor CVEs
Code Projects
All CVEs
1,456 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-30887 | Cri | 0.66 | 9.8 | 0.26 | May 20, 2022 | Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file. | ||
| CVE-2026-26713 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php. | ||
| CVE-2026-26712 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php. | ||
| CVE-2026-26711 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php. | ||
| CVE-2026-26710 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php. | ||
| CVE-2026-26709 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php. | ||
| CVE-2026-26696 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php. | ||
| CVE-2026-26695 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php. | ||
| CVE-2026-26694 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2026 | code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php. | ||
| CVE-2025-70152 | Cri | 0.64 | 9.8 | 0.00 | Feb 18, 2026 | code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters… | ||
| CVE-2025-69564 | Cri | 0.64 | 9.8 | 0.00 | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password, confirm_password, Role, Branch, and Activate parameters. | ||
| CVE-2025-69563 | Cri | 0.64 | 9.8 | 0.00 | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter. | ||
| CVE-2025-69562 | Cri | 0.64 | 9.8 | 0.00 | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter. | ||
| CVE-2025-69559 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2026 | code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php. | ||
| CVE-2025-69565 | Cri | 0.64 | 9.8 | 0.00 | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php. | ||
| CVE-2025-60736 | Cri | 0.64 | 9.8 | 0.00 | Dec 2, 2025 | code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter. | ||
| CVE-2025-63622 | Cri | 0.64 | 9.8 | 0.00 | Oct 29, 2025 | A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/admin/subcategory.php. This manipulation of the argument category causes SQL injection. | ||
| CVE-2025-60306 | Cri | 0.64 | 9.9 | 0.00 | Oct 10, 2025 | code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations. | ||
| CVE-2025-40731 | Cri | 0.64 | 9.8 | 0.00 | Jun 30, 2025 | SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, update and delete databases through the pname, pprice and id parameters in /update.php. | ||
| CVE-2025-29369 | Cri | 0.64 | 9.8 | 0.01 | Apr 3, 2025 | Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1. | ||
| CVE-2024-34955 | Cri | 0.64 | 9.8 | 0.01 | May 15, 2024 | Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter. | ||
| CVE-2024-25250 | Cri | 0.64 | 9.8 | 0.01 | Mar 13, 2024 | SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page. | ||
| CVE-2023-41505 | Cri | 0.64 | 9.8 | 0.01 | Mar 13, 2024 | An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2024-24101 | Cri | 0.64 | 9.8 | 0.00 | Mar 12, 2024 | Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update. | ||
| CVE-2024-24093 | Cri | 0.64 | 9.8 | 0.01 | Mar 12, 2024 | SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information. | ||
| CVE-2023-41503 | Cri | 0.64 | 9.8 | 0.01 | Mar 7, 2024 | Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function. | ||
| CVE-2023-41014 | Cri | 0.64 | 9.8 | 0.01 | Mar 7, 2024 | code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer." | ||
| CVE-2024-24095 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2024 | Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection. | ||
| CVE-2023-41506 | Cri | 0.64 | 9.8 | 0.01 | Feb 27, 2024 | An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2024-25223 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php. | ||
| CVE-2024-25222 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php. | ||
| CVE-2024-25220 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php. | ||
| CVE-2024-25316 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2. | ||
| CVE-2024-25315 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2. | ||
| CVE-2024-25314 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2. | ||
| CVE-2024-25307 | Cri | 0.64 | 9.8 | 0.01 | Feb 9, 2024 | Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1." | ||
| CVE-2023-48078 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2023 | SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands via the 'title' parameter. | ||
| CVE-2023-37069 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2023 | Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the login id and password… | ||
| CVE-2023-37068 | Cri | 0.64 | 9.8 | 0.01 | Aug 9, 2023 | Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username… | ||
| CVE-2023-37627 | Cri | 0.64 | 9.8 | 0.01 | Jul 12, 2023 | Code-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker can bypass the admin panel and view order records, add items, delete items etc. | ||
| CVE-2022-36669 | Cri | 0.64 | 9.8 | 0.02 | Sep 14, 2022 | Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass. | ||
| CVE-2021-44092 | Cri | 0.64 | 9.8 | 0.01 | Jan 20, 2022 | An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form. | ||
| CVE-2022-28079 | Hig | 0.63 | 8.8 | 0.29 | May 5, 2022 | College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter. | ||
| CVE-2020-28688 | Hig | 0.61 | 8.8 | 0.12 | Nov 17, 2020 | The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files. | ||
| CVE-2020-28687 | Hig | 0.61 | 8.8 | 0.12 | Nov 17, 2020 | The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files. | ||
| CVE-2026-7503 | Hig | 0.57 | 8.8 | 0.00 | Apr 30, 2026 | A vulnerability was detected in code-projects for Plugin 4.1.2cu.5137. The impacted element is the function setWiFiMultipleConfig in the library /lib/cste_modules/wireless.so of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument wepkey2 results in buffer overflow.… | ||
| CVE-2025-70151 | Hig | 0.57 | 8.8 | 0.01 | Feb 18, 2026 | code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the… | ||
| CVE-2024-57668 | Hig | 0.57 | 8.8 | 0.01 | Feb 6, 2025 | In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability. | ||
| CVE-2024-38348 | Hig | 0.57 | 8.8 | 0.00 | Jun 18, 2024 | CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter. | ||
| CVE-2024-38347 | Hig | 0.57 | 8.8 | 0.01 | Jun 18, 2024 | CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information module via the id parameter. |
- risk 0.66cvss 9.8epss 0.26
Pharmacy Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.
- risk 0.64cvss 9.8epss 0.01
code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters…
- risk 0.64cvss 9.8epss 0.00
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Address, email, UserName, Password, confirm_password, Role, Branch, and Activate parameters.
- risk 0.64cvss 9.8epss 0.00
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password parameter.
- risk 0.64cvss 9.8epss 0.00
code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid parameter.
- risk 0.64cvss 9.8epss 0.01
code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.
- risk 0.64cvss 9.8epss 0.00
code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.
- risk 0.64cvss 9.8epss 0.00
A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the file /cms/admin/subcategory.php. This manipulation of the argument category causes SQL injection.
- risk 0.64cvss 9.9epss 0.00
code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privilege sessions and perform sensitive operations.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability in Daily Expense Manager v1.0. This vulnerability allows an attacker to retrieve, create, update and delete databases through the pname, pprice and id parameters in /update.php.
- risk 0.64cvss 9.8epss 0.01
Code-Projects Matrimonial Site V1.0 is vulnerable to SQL Injection in /view_profile.php?id=1.
- risk 0.64cvss 9.8epss 0.01
Code-projects Budget Management 1.0 is vulnerable to SQL Injection via the delete parameter.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.00
Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Eligibility Information Update.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information.
- risk 0.64cvss 9.8epss 0.01
Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.
- risk 0.64cvss 9.8epss 0.01
code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via the Username parameter for "Employer."
- risk 0.64cvss 9.8epss 0.01
Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the Update/Edit Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
Simple Admin Panel App v1.0 was discovered to contain a SQL injection vulnerability via the orderID parameter at /adminView/viewEachOrder.php.
- risk 0.64cvss 9.8epss 0.01
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID parameter at /TaskManager/EditProject.php.
- risk 0.64cvss 9.8epss 0.01
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID parameter at /TaskManager/EditTask.php.
- risk 0.64cvss 9.8epss 0.01
Code-projects Hotel Managment System 1.0 allows SQL Injection via the 'eid' parameter in Hotel/admin/usersettingdel.php?eid=2.
- risk 0.64cvss 9.8epss 0.01
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'rid' parameter in Hotel/admin/roombook.php?rid=2.
- risk 0.64cvss 9.8epss 0.01
Code-projects Hotel Managment System 1.0, allows SQL Injection via the 'sid' parameter in Hotel/admin/show.php?sid=2.
- risk 0.64cvss 9.8epss 0.01
Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in add.php in Simple CRUD Functionality v1.0 allows attackers to run arbitrary SQL commands via the 'title' parameter.
- risk 0.64cvss 9.8epss 0.01
Code-Projects Online Hospital Management System V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to manipulate the SQL queries executed by the application. The application fails to properly validate user-supplied input in the login id and password…
- risk 0.64cvss 9.8epss 0.01
Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulation. This vulnerability arises due to insufficient validation of user-supplied input in the username…
- risk 0.64cvss 9.8epss 0.01
Code-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker can bypass the admin panel and view order records, add items, delete items etc.
- risk 0.64cvss 9.8epss 0.02
Hospital Information System version 1.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in code-projects Pharmacy Management 1.0 via the username parameter in the administer login form.
- risk 0.63cvss 8.8epss 0.29
College Management System v1.0 was discovered to contain a SQL injection vulnerability via the course_code parameter.
- risk 0.61cvss 8.8epss 0.12
The add artwork functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
- risk 0.61cvss 8.8epss 0.12
The edit profile functionality in ARTWORKS GALLERY IN PHP, CSS, JAVASCRIPT, AND MYSQL 1.0 allows remote attackers to upload arbitrary files.
- risk 0.57cvss 8.8epss 0.00
A vulnerability was detected in code-projects for Plugin 4.1.2cu.5137. The impacted element is the function setWiFiMultipleConfig in the library /lib/cste_modules/wireless.so of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument wepkey2 results in buffer overflow.…
- risk 0.57cvss 8.8epss 0.01
code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the…
- risk 0.57cvss 8.8epss 0.01
In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload vulnerability.
- risk 0.57cvss 8.8epss 0.00
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Staff Info module via the searvalu parameter.
- risk 0.57cvss 8.8epss 0.01
CodeProjects Health Care hospital Management System v1.0 was discovered to contain a SQL injection vulnerability in the Room Information module via the id parameter.
Page 1 of 30