Vendor CVEs
Mayurik
All CVEs
338 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-43061 | Hig | 0.47 | 7.2 | 0.01 | Nov 3, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-41551 | Hig | 0.47 | 7.2 | 0.01 | Nov 2, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php. | ||
| CVE-2022-43331 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php_action/printOrder.php. | ||
| CVE-2022-43330 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php. | ||
| CVE-2022-43329 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php. | ||
| CVE-2022-43328 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php. | ||
| CVE-2022-43233 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchSelectedUser.php. | ||
| CVE-2022-43232 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchOrderData.php. | ||
| CVE-2022-43231 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-43276 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /php_action/fetchSelectedfood.php. | ||
| CVE-2022-43275 | Hig | 0.47 | 7.2 | 0.01 | Oct 28, 2022 | Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-42218 | Hig | 0.47 | 7.2 | 0.01 | Oct 18, 2022 | Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php. | ||
| CVE-2022-41537 | Hig | 0.47 | 7.2 | 0.01 | Oct 18, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /user_operations/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-41504 | Hig | 0.47 | 7.2 | 0.01 | Oct 18, 2022 | An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-42143 | Hig | 0.47 | 7.2 | 0.01 | Oct 17, 2022 | Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php. | ||
| CVE-2022-42142 | Hig | 0.47 | 7.2 | 0.01 | Oct 17, 2022 | Online Tours & Travels Management System v1.0 is vulnerable to Arbitrary code execution via ip/tour/admin/operations/update_settings.php. | ||
| CVE-2022-41498 | Hig | 0.47 | 7.2 | 0.01 | Oct 17, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php. | ||
| CVE-2022-41416 | Hig | 0.47 | 7.2 | 0.01 | Oct 14, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /user/update_booking.php. | ||
| CVE-2022-41536 | Hig | 0.47 | 7.2 | 0.01 | Oct 14, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_user.php. | ||
| CVE-2022-41535 | Hig | 0.47 | 7.2 | 0.01 | Oct 14, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_borrower.php. | ||
| CVE-2022-41534 | Hig | 0.47 | 7.2 | 0.01 | Oct 13, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-41533 | Hig | 0.47 | 7.2 | 0.01 | Oct 13, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-41532 | Hig | 0.47 | 7.2 | 0.01 | Oct 12, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_plan. | ||
| CVE-2022-41530 | Hig | 0.47 | 7.2 | 0.01 | Oct 12, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_borrower. | ||
| CVE-2022-42074 | Hig | 0.47 | 7.2 | 0.01 | Oct 7, 2022 | Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=. | ||
| CVE-2022-42073 | Hig | 0.47 | 7.2 | 0.01 | Oct 7, 2022 | Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=. | ||
| CVE-2022-41515 | Hig | 0.47 | 7.2 | 0.01 | Oct 7, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_payment. | ||
| CVE-2022-41514 | Hig | 0.47 | 7.2 | 0.01 | Oct 7, 2022 | Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_loan. | ||
| CVE-2022-41513 | Hig | 0.47 | 7.2 | 0.01 | Oct 7, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /diagnostic/edittest.php. | ||
| CVE-2022-41512 | Hig | 0.47 | 7.2 | 0.01 | Oct 7, 2022 | An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2022-41440 | Hig | 0.47 | 7.2 | 0.01 | Sep 30, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php. | ||
| CVE-2022-41439 | Hig | 0.47 | 7.2 | 0.01 | Sep 30, 2022 | Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php. | ||
| CVE-2022-41437 | Hig | 0.47 | 7.2 | 0.01 | Sep 30, 2022 | Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php. | ||
| CVE-2022-40354 | Hig | 0.47 | 7.2 | 0.01 | Sep 27, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php. | ||
| CVE-2022-40353 | Hig | 0.47 | 7.2 | 0.01 | Sep 27, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/up_booking.php. | ||
| CVE-2022-40352 | Hig | 0.47 | 7.2 | 0.01 | Sep 27, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_traveller.php. | ||
| CVE-2022-40099 | Hig | 0.47 | 7.2 | 0.01 | Sep 26, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense_category.php. | ||
| CVE-2022-40098 | Hig | 0.47 | 7.2 | 0.01 | Sep 26, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense.php. | ||
| CVE-2022-40097 | Hig | 0.47 | 7.2 | 0.01 | Sep 26, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_currency.php. | ||
| CVE-2022-40093 | Hig | 0.47 | 7.2 | 0.01 | Sep 23, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php. | ||
| CVE-2022-40092 | Hig | 0.47 | 7.2 | 0.01 | Sep 23, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_payment.php. | ||
| CVE-2022-40091 | Hig | 0.47 | 7.2 | 0.01 | Sep 23, 2022 | Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_packages.php. | ||
| CVE-2022-38877 | Hig | 0.47 | 7.2 | 0.01 | Sep 16, 2022 | Garage Management System v1.0 is vulnerable to Arbitrary code execution via ip/garage/php_action/editProductImage.php?id=1. | ||
| CVE-2022-38610 | Hig | 0.47 | 7.2 | 0.01 | Sep 12, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editclient.php. | ||
| CVE-2022-38606 | Hig | 0.47 | 7.2 | 0.01 | Sep 12, 2022 | Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editcategory.php. | ||
| CVE-2024-27744 | Med | 0.43 | 6.1 | 0.01 | Mar 1, 2024 | Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component. | ||
| CVE-2024-27743 | Med | 0.43 | 6.1 | 0.01 | Mar 1, 2024 | Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter in the add_invoices.php component. | ||
| CVE-2026-5330 | Med | 0.42 | 6.5 | 0.00 | Apr 2, 2026 | A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component User Delete Handler. Performing a manipulation of the argument ID results in… | ||
| CVE-2025-63717 | Med | 0.42 | 6.5 | 0.00 | Nov 7, 2025 | The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The application does not implement adequate anti-CSRF tokens or same-site cookie… | ||
| CVE-2024-11860 | Med | 0.42 | 6.5 | 0.01 | Nov 27, 2024 | A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects an unknown part of the file /rental/ajax.php?action=delete_tenant of the component POST Request Handler. The manipulation of the argument id leads to… |
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability in the component /operations/travellers.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editorder.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /php_action/printOrder.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /print.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /editorder.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchSelectedUser.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the userid parameter at /php_action/fetchOrderData.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain a SQL injection vulnerability via the productId parameter at /php_action/fetchSelectedfood.php.
- risk 0.47cvss 7.2epss 0.01
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 vulnerable to SQL Injection via /sacco_shield/manage_loan.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /user_operations/profile.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
An arbitrary file upload vulnerability in the component /php_action/editProductImage.php of Billing System Project v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 is vulnerable to SQL Injection via /sacco_shield/manage_payment.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 is vulnerable to Arbitrary code execution via ip/tour/admin/operations/update_settings.php.
- risk 0.47cvss 7.2epss 0.01
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editbrand.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /user/update_booking.php.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_user.php.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/manage_borrower.php.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/editProductImage.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_plan.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_borrower.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editcategory.php?id=.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 is vulnerable to SQL Injection via /diagnostic/editclient.php?id=.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_payment.
- risk 0.47cvss 7.2epss 0.01
Open Source SACCO Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /sacco_shield/ajax.php?action=delete_loan.
- risk 0.47cvss 7.2epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /diagnostic/edittest.php.
- risk 0.47cvss 7.2epss 0.01
An arbitrary file upload vulnerability in the component /php_action/editFile.php of Online Diagnostic Lab Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.47cvss 7.2epss 0.01
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/editcategory.php.
- risk 0.47cvss 7.2epss 0.01
Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /phpinventory/edituser.php.
- risk 0.47cvss 7.2epss 0.01
Billing System Project v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the component /php_action/createProduct.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_booking.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/up_booking.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_traveller.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense_category.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_expense.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/update_currency.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_tax.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_payment.php.
- risk 0.47cvss 7.2epss 0.01
Online Tours & Travels Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /tour/admin/update_packages.php.
- risk 0.47cvss 7.2epss 0.01
Garage Management System v1.0 is vulnerable to Arbitrary code execution via ip/garage/php_action/editProductImage.php?id=1.
- risk 0.47cvss 7.2epss 0.01
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editclient.php.
- risk 0.47cvss 7.2epss 0.01
Garage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /garage/editcategory.php.
- risk 0.43cvss 6.1epss 0.01
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the image parameter in the profile.php component.
- risk 0.43cvss 6.1epss 0.01
Cross Site Scripting vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Address parameter in the add_invoices.php component.
- risk 0.42cvss 6.5epss 0.00
A vulnerability was found in SourceCodester/mayuri_k Best Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=delete_user of the component User Delete Handler. Performing a manipulation of the argument ID results in…
- risk 0.42cvss 6.5epss 0.00
The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks. The application does not implement adequate anti-CSRF tokens or same-site cookie…
- risk 0.42cvss 6.5epss 0.01
A vulnerability classified as critical has been found in SourceCodester Best House Rental Management System 1.0. This affects an unknown part of the file /rental/ajax.php?action=delete_tenant of the component POST Request Handler. The manipulation of the argument id leads to…
Page 3 of 7