Vendor CVEs
Mayurik
All CVEs
338 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-27747 | Cri | 0.69 | 9.8 | 0.24 | Mar 1, 2024 | File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component. | ||
| CVE-2024-27746 | Cri | 0.68 | 9.8 | 0.13 | Mar 1, 2024 | SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component. | ||
| CVE-2023-44755 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2025 | Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php. | ||
| CVE-2025-1875 | Cri | 0.64 | 9.8 | 0.00 | Mar 3, 2025 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php. | ||
| CVE-2025-1874 | Cri | 0.64 | 9.8 | 0.00 | Mar 3, 2025 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php. | ||
| CVE-2025-1873 | Cri | 0.64 | 9.8 | 0.00 | Mar 3, 2025 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php. | ||
| CVE-2025-1872 | Cri | 0.64 | 9.8 | 0.00 | Mar 3, 2025 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in admin/add-subadmins.php. | ||
| CVE-2025-1871 | Cri | 0.64 | 9.8 | 0.00 | Mar 3, 2025 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php. | ||
| CVE-2025-1870 | Cri | 0.64 | 9.8 | 0.00 | Mar 3, 2025 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php. | ||
| CVE-2025-1869 | Cri | 0.64 | 9.8 | 0.00 | Mar 3, 2025 | SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php. | ||
| CVE-2024-48581 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2024 | File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component. | ||
| CVE-2024-48580 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2024 | SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request. | ||
| CVE-2024-48579 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2024 | SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request. | ||
| CVE-2024-48411 | Cri | 0.64 | 9.8 | 0.01 | Oct 15, 2024 | itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php. | ||
| CVE-2024-46377 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2024 | Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php. | ||
| CVE-2024-46376 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2024 | Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php. | ||
| CVE-2024-46375 | Cri | 0.64 | 9.8 | 0.01 | Sep 18, 2024 | Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php. | ||
| CVE-2024-46374 | Cri | 0.64 | 9.8 | 0.00 | Sep 18, 2024 | Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php. | ||
| CVE-2024-44430 | Cri | 0.64 | 9.8 | 0.01 | Sep 13, 2024 | SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload to the kortex_lite/control/register_case.php interface | ||
| CVE-2024-36568 | Cri | 0.64 | 9.8 | 0.01 | Jun 3, 2024 | Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=. | ||
| CVE-2024-28613 | Cri | 0.64 | 9.8 | 0.01 | Apr 24, 2024 | SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component. | ||
| CVE-2024-28557 | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2024 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php. | ||
| CVE-2024-28556 | Cri | 0.64 | 9.8 | 0.01 | Apr 15, 2024 | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php. | ||
| CVE-2024-29303 | Cri | 0.64 | 9.8 | 0.01 | Mar 26, 2024 | The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection | ||
| CVE-2023-48823 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2023 | A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload via the email parameter during login. | ||
| CVE-2023-46980 | Cri | 0.64 | 9.8 | 0.02 | Nov 3, 2023 | An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter. | ||
| CVE-2023-46007 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2023 | Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_staff.php. | ||
| CVE-2023-46006 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2023 | Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php. | ||
| CVE-2023-46005 | Cri | 0.64 | 9.8 | 0.01 | Oct 18, 2023 | Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_branch.php. | ||
| CVE-2022-44401 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2022 | Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php. | ||
| CVE-2022-43135 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php. | ||
| CVE-2022-42021 | Cri | 0.64 | 9.8 | 0.01 | Oct 20, 2022 | Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=. | ||
| CVE-2022-36161 | Cri | 0.64 | 9.8 | 0.01 | Jul 26, 2022 | Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | ||
| CVE-2025-60316 | Cri | 0.61 | 9.4 | 0.00 | Oct 9, 2025 | SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter. | ||
| CVE-2023-53734 | Hig | 0.57 | — | 0.01 | Dec 4, 2025 | dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access. | ||
| CVE-2024-40475 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2024 | SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_report.php, /rental/invoices.php, /rental/tenants.php, and /rental/users.php. | ||
| CVE-2024-28558 | Hig | 0.57 | 8.8 | 0.01 | Apr 15, 2024 | SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin/app/web_crud.php. | ||
| CVE-2023-46449 | Hig | 0.57 | 8.8 | 0.01 | Oct 26, 2023 | Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function. | ||
| CVE-2022-37184 | Hig | 0.57 | 8.8 | 0.01 | Aug 31, 2022 | The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authenticated malicious user, can upload a dangerous RCE or LCE exploit file. | ||
| CVE-2025-63298 | Hig | 0.53 | 8.2 | 0.00 | Oct 30, 2025 | A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage this flaw by submitting a specially crafted POST request,… | ||
| CVE-2024-36569 | Hig | 0.53 | 8.1 | 0.01 | Jun 3, 2024 | Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php. | ||
| CVE-2024-40476 | Hig | 0.52 | 8.0 | 0.00 | Aug 12, 2024 | A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacker tricking the administrator into adding/modifying/deleting valid tenant data via a crafted HTML page, as demonstrated by a Delete… | ||
| CVE-2024-39210 | Hig | 0.49 | 7.5 | 0.01 | Jul 5, 2024 | Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php. This vulnerability allows attackers to read arbitrary PHP files and access other sensitive information within the application. | ||
| CVE-2024-28320 | Hig | 0.49 | 7.6 | 0.01 | Apr 29, 2024 | Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php. | ||
| CVE-2024-29302 | Hig | 0.49 | 7.5 | 0.01 | Mar 26, 2024 | SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php. | ||
| CVE-2024-29301 | Hig | 0.49 | 7.5 | 0.01 | Mar 26, 2024 | SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id= | ||
| CVE-2023-49980 | Hig | 0.49 | 7.5 | 0.01 | Mar 21, 2024 | A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization. | ||
| CVE-2023-49979 | Hig | 0.49 | 7.5 | 0.01 | Mar 21, 2024 | A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization. | ||
| CVE-2024-9296 | Hig | 0.48 | 7.3 | 0.01 | Sep 28, 2024 | A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /control/forgot_pass.php. The manipulation of the argument username leads to sql injection. It is possible to launch… | ||
| CVE-2024-9295 | Hig | 0.48 | 7.3 | 0.01 | Sep 28, 2024 | A vulnerability was found in SourceCodester Advocate Office Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /control/login.php. The manipulation of the argument username leads to sql injection. The attack may be initiated… |
- risk 0.69cvss 9.8epss 0.24
File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email Image parameter in the profile.php component.
- risk 0.68cvss 9.8epss 0.13
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the email address parameter in the index.php component.
- risk 0.64cvss 9.8epss 0.01
Sacco Management system v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /sacco/ajax.php.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "searchtitle" parameter in search.php.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "description" parameter in admin/add-category.php.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagetitle" and "pagedescription" parameters in admin/contactus.php.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "sadminusername" parameter in admin/add-subadmins.php.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "category" and "subcategory" parameters in admin/add-subcategory.php.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "pagedescription" parameter in admin/aboutus.php.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability have been found in 101news affecting version 1.0 through the "username" parameter in admin/check_avalability.php.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email parameter of the login request.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.
- risk 0.64cvss 9.8epss 0.01
itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to SQL Injection (SQLI) via a crafted payload to the val-email parameter in forget_password.php.
- risk 0.64cvss 9.8epss 0.01
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/admin_class.php.
- risk 0.64cvss 9.8epss 0.01
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/admin_class.php.
- risk 0.64cvss 9.8epss 0.01
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_class.php.
- risk 0.64cvss 9.8epss 0.00
Best House Rental Management System 1.0 contains a SQL injection vulnerability in the delete_category() function of the file rental/admin_class.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker to execute arbitrary code and obtain sensitive information via a crafted payload to the kortex_lite/control/register_case.php interface
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in PHP Task Management System v.1.0 allows a remote attacker to escalate privileges and obtain sensitive information via the task_id parameter of the task-details.php, and edit-task.php component.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin-manage-user.php.
- risk 0.64cvss 9.8epss 0.01
The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection
- risk 0.64cvss 9.8epss 0.01
A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload via the email parameter during login.
- risk 0.64cvss 9.8epss 0.02
An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_staff.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_user.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Best Courier Management System 1.0 is vulnerable to SQL Injection via the parameter id in /edit_branch.php.
- risk 0.64cvss 9.8epss 0.01
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via /tour/admin/file.php.
- risk 0.64cvss 9.8epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at /diagnostic/login.php.
- risk 0.64cvss 9.8epss 0.01
Best Student Result Management System v1.0 is vulnerable to SQL Injection via /upresult/upresult/notice-details.php?nid=.
- risk 0.64cvss 9.8epss 0.01
Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
- risk 0.61cvss 9.4epss 0.00
SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID parameter.
- risk 0.57cvss —epss 0.01
dawa-pharma-1.0 allows unauthenticated attackers to execute SQL queries on the server, allowing them to access sensitive information and potentially gain administrative access.
- risk 0.57cvss 8.8epss 0.01
SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_report.php, /rental/invoices.php, /rental/tenants.php, and /rental/users.php.
- risk 0.57cvss 8.8epss 0.01
SQL Injection vulnerability in sourcecodester Petrol pump management software v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to admin/app/web_crud.php.
- risk 0.57cvss 8.8epss 0.01
Sourcecodester Free and Open Source inventory management system v1.0 is vulnerable to Incorrect Access Control. An arbitrary user can change the password of another user and takeover the account via IDOR in the password change function.
- risk 0.57cvss 8.8epss 0.01
The application manage_website.php on Garage Management System 1.0 is vulnerable to Shell File Upload. The already authenticated malicious user, can upload a dangerous RCE or LCE exploit file.
- risk 0.53cvss 8.2epss 0.00
A path traversal vulnerability was identified in SourceCodester Pet Grooming Management System 1.0, affecting the admin/manage_website.php component. An authenticated user with administrative privileges can leverage this flaw by submitting a specially crafted POST request,…
- risk 0.53cvss 8.1epss 0.01
Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via editClientImage.php.
- risk 0.52cvss 8.0epss 0.00
A Cross-Site Request Forgery (CSRF) vulnerability was found in SourceCodester Best House Rental Management System v1.0. This could lead to an attacker tricking the administrator into adding/modifying/deleting valid tenant data via a crafted HTML page, as demonstrated by a Delete…
- risk 0.49cvss 7.5epss 0.01
Best House Rental Management System v1.0 was discovered to contain an arbitrary file read vulnerability via the Page parameter at index.php. This vulnerability allows attackers to read arbitrary PHP files and access other sensitive information within the application.
- risk 0.49cvss 7.6epss 0.01
Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows attackers to manipulate user parameters for unauthorized access and modifications via crafted POST request to /patient/edit-user.php.
- risk 0.49cvss 7.5epss 0.01
SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.
- risk 0.49cvss 7.5epss 0.01
SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-admin.php?admin_id=
- risk 0.49cvss 7.5epss 0.01
A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.
- risk 0.49cvss 7.5epss 0.01
A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in SourceCodester Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /control/forgot_pass.php. The manipulation of the argument username leads to sql injection. It is possible to launch…
- risk 0.48cvss 7.3epss 0.01
A vulnerability was found in SourceCodester Advocate Office Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /control/login.php. The manipulation of the argument username leads to sql injection. The attack may be initiated…
Page 1 of 7