VYPR

Vendor CVEs

Code Projects

All CVEs

1,463 total · sorted by risk
  • CVE-2024-11077HigNov 11, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in code-projects Job Recruitment 1.0. Affected is an unknown function of the file /index.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has…

  • CVE-2024-10988HigNov 8, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in code-projects E-Health Care System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /Doctor/doctor_login.php. The manipulation of the argument email leads to sql injection. The attack may be…

  • CVE-2024-10733HigNov 3, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in code-projects Restaurant Order System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument uid leads to sql injection. The attack may be launched remotely. The…

  • CVE-2024-10702HigNov 2, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in code-projects Simple Car Rental System 1.0. Affected is an unknown function of the file /signup.php. The manipulation of the argument fname leads to sql injection. It is possible to launch the attack remotely. The exploit…

  • CVE-2024-9797HigOct 10, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file register.php. The manipulation of the argument user leads to sql injection. It is possible to launch the attack remotely. The exploit…

  • CVE-2024-9034HigSep 20, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The attack may be launched…

  • CVE-2024-28279HigMay 14, 2024
    risk 0.47cvss 7.3epss 0.00

    Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.

  • CVE-2024-1826HigFeb 23, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file Source/librarian/user/student/login.php. The manipulation of the argument username/password leads to sql injection. The attack can…

  • CVE-2024-1820HigFeb 23, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability was found in code-projects Crime Reporting System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file inchargelogin.php. The manipulation of the argument email/password leads to sql injection. The attack can be initiated…

  • CVE-2024-0474HigJan 12, 2024
    risk 0.47cvss 7.3epss 0.01

    A vulnerability classified as critical was found in code-projects Dormitory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login.php. The manipulation of the argument username leads to sql injection. The attack can be launched…

  • CVE-2022-30404HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    College Management System v1.0 is vulnerable to SQL Injection via /College_Management_System/admin/display-teacher.php?teacher_id=.

  • CVE-2024-57487MedJan 13, 2025
    risk 0.45cvss 6.5epss 0.03

    In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.

  • CVE-2025-28121MedApr 21, 2025
    risk 0.43cvss 6.1epss 0.01

    code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.

  • CVE-2026-19345MedAug 9, 2026
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manipulation of the argument task_id/val results in missing authorization. It is possible to launch the attack remotely. The exploit…

  • CVE-2025-44135MedApr 24, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the parameter username will cause SQL injection attacks.

  • CVE-2025-44134MedApr 24, 2025
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of parameter class will lead to SQL injection attacks.

  • CVE-2024-57488MedJan 13, 2025
    risk 0.42cvss 6.5epss 0.00

    Code-Projects Online Car Rental System 1.0 is vulnerable to Cross Site Scripting (XSS) via the vehicalorcview parameter in /admin/edit-vehicle.php.

  • CVE-2023-7137MedDec 28, 2023
    risk 0.42cvss 6.3epss 0.17

    A vulnerability, which was classified as critical, has been found in code-projects Client Details System 1.0. Affected by this issue is some unknown functionality of the component HTTP POST Request Handler. The manipulation of the argument uemail leads to sql injection. The…

  • CVE-2023-46023MedNov 14, 2023
    risk 0.42cvss 6.5epss 0.01

    SQL injection vulnerability in addTask.php in Code-Projects Simple Task List 1.0 allows attackers to obtain sensitive information via the 'status' parameter.

  • CVE-2026-19923MedAug 16, 2026
    risk 0.41cvss 6.3epss

    A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing a manipulation of the argument total_count can lead to sql injection. The attack can be launched remotely. The exploit has been…

  • CVE-2026-19921MedAug 16, 2026
    risk 0.41cvss 6.3epss

    A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /homeaction.php. Such manipulation of the argument cat_id leads to sql injection. It is possible to launch the attack remotely. The…

  • CVE-2026-19920MedAug 16, 2026
    risk 0.41cvss 6.3epss

    A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulation of the argument proId causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly…

  • CVE-2026-19917MedAug 15, 2026
    risk 0.41cvss 6.3epss

    A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. Executing a manipulation of the argument checkbox can lead to sql injection. The attack can be executed remotely. The exploit has…

  • CVE-2026-11495MedJun 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in CodeAstro Ingredients Stock Management System 1.0. This impacts an unknown function of the file /Ingredients-Stock/add_stock.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit is now…

  • CVE-2026-10209MedJun 1, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in code-projects Online Hospital Management System 1.0. Affected is an unknown function of the file appointmentdetail.php of the component Appointment Handler. The manipulation of the argument editid leads to sql injection. The attack is possible…

  • CVE-2026-10170MedMay 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in code-projects Visitor Management System 1.0. Affected by this issue is some unknown functionality of the file /vms/php/phone_0.php. This manipulation of the argument phone causes sql injection. The attack may be initiated remotely. The exploit has been…

  • CVE-2026-9451MedMay 25, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in code-projects Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /process/applyleaveprocess.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely.…

  • CVE-2026-9450MedMay 25, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in code-projects Employee Management System 1.0. Affected is an unknown function of the file /psubmit.php. The manipulation of the argument pid results in sql injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-9449MedMay 25, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in code-projects Employee Management System 1.0. This impacts an unknown function of the file /changepassemp.php. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might…

  • CVE-2026-8125MedMay 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in code-projects Simple Chat System 1.0. This vulnerability affects unknown code of the file sendMessage.php. The manipulation of the argument type/length/business parameter validity results in sql injection. The attack may be launched remotely. The…

  • CVE-2026-7732MedMay 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The manipulation results in unrestricted upload. The attack can be executed remotely. The exploit is now public and may be used.

  • CVE-2026-7731MedMay 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. The affected element is an unknown function of the file get_state.php. The manipulation of the argument G_STATE_ID leads to sql injection. Remote exploitation of the attack is possible.…

  • CVE-2026-7716MedMay 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in code-projects Gym Management System In PHP and Windows NT 1.0. This vulnerability affects unknown code of the file /index.php. Performing a manipulation of the argument day results in sql injection. The attack can be initiated remotely. The exploit…

  • CVE-2026-7229MedApr 28, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in code-projects Coaching Management System 1.0. This affects an unknown function of the file /cims/modules/admin/reply.php of the component POST Handler. Performing a manipulation of the argument complaintreply results in sql injection. It is possible…

  • CVE-2026-7118MedApr 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in code-projects Employee Management System 1.0. The affected element is an unknown function of the file 370project/cancel.php. The manipulation of the argument id/token leads to sql injection. The attack is possible to be carried out…

  • CVE-2026-7117MedApr 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in code-projects Employee Management System 1.0. Impacted is an unknown function of the file 370project/approve.php. Executing a manipulation of the argument id/token can lead to sql injection. The attack can be executed remotely. The exploit has…

  • CVE-2026-7115MedApr 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file 370project/delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit is publicly…

  • CVE-2026-7114MedApr 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was determined in code-projects Employee Management System 1.0. This affects an unknown part of the file 370project/edit.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed…

  • CVE-2026-7107MedApr 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in code-projects Invoice System in Laravel 1.0. The impacted element is an unknown function of the file /company. This manipulation of the argument logo causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has…

  • CVE-2026-7093MedApr 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in code-projects Invoice System in Laravel 1.0. Affected by this vulnerability is an unknown functionality of the file /invoice/ of the component Invoice Endpoint. Performing a manipulation of the argument ID results in improper authorization. The…

  • CVE-2026-7092MedApr 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in code-projects Invoice System in Laravel 1.0. Affected is an unknown function of the file /profile/ of the component Profile Handler. Such manipulation of the argument ID leads to improper authorization. The attack can be executed remotely. The…

  • CVE-2026-7091MedApr 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in code-projects Invoice System in Laravel 1.0. This impacts an unknown function of the file /user of the component User Management Handler. This manipulation causes improper authorization. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2026-6202MedApr 13, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipulation of the argument tags results in sql injection. The attack may be initiated remotely. The exploit has been released to the…

  • CVE-2026-6006MedApr 10, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in code-projects Patient Record Management System 1.0. The impacted element is an unknown function of the file /edit_hpatient.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has…

  • CVE-2026-6005MedApr 10, 2026
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in code-projects Patient Record Management System 1.0. The affected element is an unknown function of the file /hematology_print.php. Executing a manipulation of the argument hem_id can lead to sql injection. It is possible to launch the attack remotely.…

  • CVE-2026-5649MedApr 6, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in code-projects Online Application System for Admission 1.0. This issue affects some unknown processing of the file /enrollment/admsnform.php of the component Endpoint. Such manipulation leads to sql injection. The attack can be executed remotely.…

  • CVE-2026-5206MedMar 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the component Payment Handler. The manipulation of the argument Payment_id/Amount/customer_id/payment_type/customer_name leads to sql…

  • CVE-2026-5197MedMar 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in code-projects Student Membership System 1.0. The affected element is an unknown function of the file /delete_user.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public…

  • CVE-2026-5196MedMar 31, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in code-projects Student Membership System 1.0. Impacted is an unknown function of the file /delete_member.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the…

  • CVE-2026-4970MedMar 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in code-projects Social Networking Site 1.0. This affects an unknown function of the file delete_photos.php of the component Endpoint. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The…

Page 14 of 30