VYPR

Vendor CVEs

Mayurik

All CVEs

338 total · sorted by risk
  • CVE-2023-4179MedAug 6, 2023
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected is an unknown function of the file /vm/doctor/doctors.php?action=view. The manipulation of the argument id leads to sql injection. It is…

  • CVE-2025-60318MedOct 8, 2025
    risk 0.40cvss 6.1epss 0.00

    SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the fname (First Name) and lname (Last Name) fields.

  • CVE-2025-61087MedOct 2, 2025
    risk 0.40cvss 6.1epss 0.00

    SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name field under Customer Management Section.

  • CVE-2023-44753MedApr 22, 2025
    risk 0.40cvss 6.1epss 0.00

    A stored cross-site scripting (XSS) vulnerability fin Student Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the email parameter on the profile.php page.

  • CVE-2023-48206MedDec 7, 2023
    risk 0.40cvss 6.1epss 0.01

    A Cross Site Scripting (XSS) vulnerability in GaatiTrack Courier Management System 1.0 allows a remote attacker to inject JavaScript via the page parameter to login.php or header.php.

  • CVE-2022-44279MedNov 29, 2022
    risk 0.40cvss 6.1epss 0.01

    Garage Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via /garage/php_action/createBrand.php.

  • CVE-2023-6898MedDec 17, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Best Courier Management System 1.0. Affected is an unknown function of the file manage_user.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and…

  • CVE-2023-6765MedDec 13, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been rated as critical. This issue affects the function prepare of the file email_setup.php. The manipulation of the argument name leads to sql injection. The exploit has been…

  • CVE-2023-5272MedSep 29, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Best Courier Management System 1.0. This affects an unknown part of the file edit_parcel.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The exploit…

  • CVE-2023-5271MedSep 29, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file edit_parcel.php. The manipulation of the argument email leads to sql injection. The exploit has been…

  • CVE-2023-5270MedSep 29, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file view_parcel.php. The manipulation of the argument id leads to sql injection. The exploit has…

  • CVE-2023-5269MedSep 29, 2023
    risk 0.36cvss 5.5epss 0.01

    A vulnerability was found in SourceCodester Best Courier Management System 1.0. It has been classified as critical. Affected is an unknown function of the file parcel_list.php of the component GET Parameter Handler. The manipulation of the argument id/s leads to sql injection.…

  • CVE-2025-44185MedMay 15, 2025
    risk 0.35cvss 5.4epss 0.00

    SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_pass.php via the password parameter.

  • CVE-2025-44186MedMay 14, 2025
    risk 0.35cvss 5.4epss 0.00

    SourceCodester Best Employee Management System 1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/Operation/User.php page.

  • CVE-2025-1599MedFeb 24, 2025
    risk 0.35cvss 5.4epss 0.01

    A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/app/profile_crud.php. The manipulation of the argument old_cat_img leads to path traversal:…

  • CVE-2024-55000MedJan 14, 2025
    risk 0.35cvss 5.4epss 0.00

    Sourcecodester House Rental Management system v1.0 is vulnerable to Cross Site Scripting (XSS) in rental/manage_categories.php.

  • CVE-2024-46077MedOct 4, 2024
    risk 0.35cvss 5.4epss 0.00

    itsourcecode Online Tours and Travels Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via a crafted payload to the val-username, val-email, val-suggestions, val-digits and state_name parameters in travellers.php.

  • CVE-2024-40474MedAug 12, 2024
    risk 0.35cvss 5.4epss 0.01

    A Reflected Cross Site Scripting (XSS) vulnerability was found in "edit-cate.php" in SourceCodester House Rental Management System v1.0.

  • CVE-2024-40473MedAug 12, 2024
    risk 0.35cvss 5.4epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability was found in "manage_houses.php" in SourceCodester Best House Rental Management System v1.0. It allows remote attackers to execute arbitrary code via "House_no" and "Description" parameter fields.

  • CVE-2024-2076MedMar 1, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in CodeAstro House Rental Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file booking.php/owner.php/tenant.php. The manipulation leads to missing authentication. The attack may be…

  • CVE-2023-46974MedDec 7, 2023
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitrary code via a crafted payload to the page parameter in the URL.

  • CVE-2023-46451MedOct 31, 2023
    risk 0.35cvss 5.4epss 0.00

    Best Courier Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the change username field.

  • CVE-2023-46450MedOct 26, 2023
    risk 0.35cvss 5.4epss 0.00

    Sourcecodester Free and Open Source inventory management system 1.0 is vulnerable to Cross Site Scripting (XSS) via the Add supplier function.

  • CVE-2023-4181MedAug 6, 2023
    risk 0.35cvss 5.4epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this issue is some unknown functionality of the file /vm/admin/delete-doctor.php?id=2 of the component Redirect Handler. The…

  • CVE-2024-24407MedMar 28, 2024
    risk 0.34cvss 5.3epss 0.01

    SQL Injection vulnerability in Best Courier management system v.1.0 allows a remote attacker to obtain sensitive information via print_pdets.php component.

  • CVE-2025-12853MedNov 7, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function delete_house of the file /admin_class.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The…

  • CVE-2025-12614MedNov 3, 2025
    risk 0.31cvss 4.7epss 0.00

    A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The…

  • CVE-2025-12598MedNov 2, 2025
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function save_tenant of the file /admin_class.php. Executing manipulation of the argument firstname can lead to sql injection. The attack can be launched remotely. The…

  • CVE-2025-12597MedNov 2, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability is the function save_category of the file /admin_class.php. Performing manipulation of the argument Name results in sql injection. The attack can be initiated…

  • CVE-2025-12226MedOct 27, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in SourceCodester Best House Rental Management System 1.0. Impacted is the function save_house of the file /admin_class.php. Performing manipulation of the argument house_no results in sql injection. Remote exploitation of the attack is possible. The…

  • CVE-2025-10087MedSep 8, 2025
    risk 0.31cvss 4.7epss 0.00

    A security vulnerability has been detected in SourceCodester Pet Grooming Management Software 1.0. Impacted is an unknown function of the file /admin/profit_report.php. Such manipulation of the argument product_id leads to sql injection. The attack can be launched remotely. The…

  • CVE-2025-10081MedSep 8, 2025
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in SourceCodester Pet Management System 1.0. This impacts an unknown function of the file /admin/profile.php. This manipulation of the argument website_image causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been…

  • CVE-2025-44184MedMay 14, 2025
    risk 0.31cvss 4.8epss 0.00

    SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the website_image, fname, lname, contact, username, and address parameters.

  • CVE-2025-1593MedFeb 23, 2025
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /_hr_soft/assets/uploadImage/Profile/ of the component Profile Picture Handler. The manipulation leads to unrestricted upload. It…

  • CVE-2024-11214MedNov 14, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in SourceCodester Best Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/profile.php. The manipulation of the argument website_image leads to unrestricted upload. The attack can be…

  • CVE-2024-11213MedNov 14, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Best Employee Management System 1.0. This affects an unknown part of the file /admin/edit_role.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack…

  • CVE-2024-10355MedOct 25, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/invoice.php. The manipulation of the argument id leads to sql injection. The attack…

  • CVE-2024-10354MedOct 25, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/print.php. The manipulation of the argument id leads to sql injection. The attack can be launched…

  • CVE-2024-40576MedJul 29, 2024
    risk 0.31cvss 4.7epss 0.01

    Cross Site Scripting vulnerability in Best House Rental Management System 1.0 allows a remote attacker to execute arbitrary code via the "House No" and "Description" parameters in the houses page at the index.php component.

  • CVE-2024-3621MedApr 11, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been classified as critical. This affects an unknown part of the file /control/register_case.php. The manipulation of the argument title/case_no/client_name/court/case_type/case_…

  • CVE-2024-3620MedApr 11, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /control/adds.php. The manipulation of the argument name/gender/dob/email/mobile/address…

  • CVE-2024-3619MedApr 11, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /control/addcase_stage.php. The manipulation of the argument cname leads to sql…

  • CVE-2024-3618MedApr 11, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file /control/activate_case.php. The manipulation of the argument id leads to sql injection. It is possible to…

  • CVE-2024-3617MedApr 11, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This issue affects some unknown processing of the file /control/deactivate_case.php. The manipulation of the argument id leads to sql injection.…

  • CVE-2024-2168MedMar 4, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Online Tours & Travels Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/operations/expense_category.php of the component HTTP POST Request Handler. The manipulation of the…

  • CVE-2024-2062MedMar 1, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. This issue affects some unknown processing of the file /admin/edit_categories.php. The manipulation of the argument id leads to sql injection. The attack may…

  • CVE-2024-2061MedMar 1, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical was found in SourceCodester Petrol Pump Management Software 1.0. This vulnerability affects unknown code of the file /admin/edit_supplier.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely.…

  • CVE-2024-2060MedMar 1, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Petrol Pump Management Software 1.0. This affects an unknown part of the file /admin/app/login_crud.php. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack…

  • CVE-2024-2059MedMar 1, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/app/service_crud.php. The manipulation of the argument photo leads to unrestricted upload. The…

  • CVE-2024-2058MedMar 1, 2024
    risk 0.31cvss 4.7epss 0.01

    A vulnerability was found in SourceCodester Petrol Pump Management Software 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/app/product.php. The manipulation of the argument photo leads to unrestricted upload.…

Page 6 of 7