Vendor CVEs
Oretnom23
All CVEs
1,064 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-40471 | Cri | 0.68 | 9.8 | 0.20 | Oct 31, 2022 | Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php | ||
| CVE-2023-33592 | Cri | 0.67 | 9.8 | 0.04 | Jun 28, 2023 | Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information. | ||
| CVE-2023-34581 | Cri | 0.67 | 9.8 | 0.03 | Jun 12, 2023 | Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2 | ||
| CVE-2021-44653 | Cri | 0.67 | 9.8 | 0.06 | Dec 15, 2021 | Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application. | ||
| CVE-2021-42580 | Cri | 0.67 | 9.8 | 0.10 | Nov 15, 2021 | Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution. | ||
| CVE-2021-43140 | Cri | 0.67 | 9.8 | 0.05 | Nov 3, 2021 | SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login. | ||
| CVE-2022-28021 | Cri | 0.66 | 9.8 | 0.24 | Apr 21, 2022 | Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user. | ||
| CVE-2026-30533 | Cri | 0.64 | 9.8 | 0.00 | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter. | ||
| CVE-2026-30532 | Cri | 0.64 | 9.8 | 0.00 | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter. | ||
| CVE-2026-30530 | Cri | 0.64 | 9.8 | 0.00 | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject… | ||
| CVE-2026-26707 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php. | ||
| CVE-2026-26706 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php. | ||
| CVE-2026-26705 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php. | ||
| CVE-2026-26704 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php. | ||
| CVE-2026-26708 | Cri | 0.64 | 9.8 | 0.00 | Mar 2, 2026 | sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php. | ||
| CVE-2025-40682 | Cri | 0.64 | 9.8 | 0.00 | Jul 29, 2025 | SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the “city” and “state” parameters in the /controller/ccity.php endpoint. | ||
| CVE-2025-44192 | Cri | 0.64 | 9.8 | 0.00 | Apr 30, 2025 | SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance. | ||
| CVE-2023-44752 | Cri | 0.64 | 9.8 | 0.01 | Apr 22, 2025 | An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php. | ||
| CVE-2024-40073 | Cri | 0.64 | 9.8 | 0.00 | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4. | ||
| CVE-2024-40072 | Cri | 0.64 | 9.8 | 0.00 | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1. | ||
| CVE-2024-40071 | Cri | 0.64 | 9.8 | 0.01 | Apr 16, 2025 | Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2024-52675 | Cri | 0.64 | 9.8 | 0.01 | Nov 19, 2024 | SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php. | ||
| CVE-2024-50766 | Cri | 0.64 | 9.8 | 0.01 | Nov 7, 2024 | SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter. | ||
| CVE-2024-46293 | Cri | 0.64 | 9.8 | 0.00 | Sep 30, 2024 | Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does… | ||
| CVE-2024-34480 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2024 | SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection. | ||
| CVE-2024-34479 | Cri | 0.64 | 9.8 | 0.01 | Aug 7, 2024 | SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection. | ||
| CVE-2024-37858 | Cri | 0.64 | 9.8 | 0.01 | Jul 29, 2024 | SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php. | ||
| CVE-2024-40394 | Cri | 0.64 | 9.8 | 0.01 | Jul 16, 2024 | Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax.php. | ||
| CVE-2024-34833 | Cri | 0.64 | 9.8 | 0.02 | Jun 17, 2024 | Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability… | ||
| CVE-2024-35469 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2024 | A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter. | ||
| CVE-2024-31546 | Cri | 0.64 | 9.8 | 0.01 | Apr 19, 2024 | Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_damage.php. | ||
| CVE-2023-49970 | Cri | 0.64 | 9.8 | 0.01 | Mar 5, 2024 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket. | ||
| CVE-2023-49547 | Cri | 0.64 | 9.8 | 0.01 | Mar 5, 2024 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login. | ||
| CVE-2023-51801 | Cri | 0.64 | 9.8 | 0.01 | Feb 29, 2024 | SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages. | ||
| CVE-2024-25217 | Cri | 0.64 | 9.8 | 0.01 | Feb 14, 2024 | Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product. | ||
| CVE-2023-30016 | Cri | 0.64 | 9.8 | 0.01 | Jan 12, 2024 | SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_details_edit.php. | ||
| CVE-2023-30015 | Cri | 0.64 | 9.8 | 0.01 | Jan 12, 2024 | SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via txtsearch parameter in review_search.php. | ||
| CVE-2023-30014 | Cri | 0.64 | 9.8 | 0.01 | Jan 12, 2024 | SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_stat_update.php. | ||
| CVE-2023-38965 | Cri | 0.64 | 9.8 | 0.01 | Nov 3, 2023 | Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI. | ||
| CVE-2023-46435 | Cri | 0.64 | 9.8 | 0.01 | Oct 26, 2023 | Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id. | ||
| CVE-2023-30415 | Cri | 0.64 | 9.8 | 0.01 | Sep 28, 2023 | Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php. | ||
| CVE-2023-43457 | Cri | 0.64 | 9.8 | 0.01 | Sep 25, 2023 | An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint. | ||
| CVE-2023-31704 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2023 | Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role. | ||
| CVE-2023-34548 | Cri | 0.64 | 9.8 | 0.01 | Jun 16, 2023 | Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter. | ||
| CVE-2023-31752 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php. | ||
| CVE-2023-29985 | Cri | 0.64 | 9.8 | 0.01 | May 18, 2023 | Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability. | ||
| CVE-2023-31857 | Cri | 0.64 | 9.8 | 0.02 | May 16, 2023 | Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save. | ||
| CVE-2023-30247 | Cri | 0.64 | 9.8 | 0.01 | May 12, 2023 | File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the update_settings parameter. | ||
| CVE-2023-30122 | Cri | 0.64 | 9.8 | 0.01 | May 5, 2023 | An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||
| CVE-2023-30203 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php. |
- risk 0.68cvss 9.8epss 0.20
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php
- risk 0.67cvss 9.8epss 0.04
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
- risk 0.67cvss 9.8epss 0.03
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&id=2
- risk 0.67cvss 9.8epss 0.06
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application.
- risk 0.67cvss 9.8epss 0.10
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.
- risk 0.67cvss 9.8epss 0.05
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
- risk 0.66cvss 9.8epss 0.24
Purchase Order Management System v1.0 was discovered to contain a remote code execution (RCE) vulnerability via /purchase_order/admin/?page=user.
- risk 0.64cvss 9.8epss 0.00
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/manage_product.php file via the "id" parameter.
- risk 0.64cvss 9.8epss 0.00
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the admin/view_product.php file via the "id" parameter.
- risk 0.64cvss 9.8epss 0.00
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_customer action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an attacker to inject…
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_supplier.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_receipt.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_product.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/view_category.php.
- risk 0.64cvss 9.8epss 0.00
sourcecodester Pharmacy Point of Sale System v1.0 is vulnerable to SQL Injection in /pharmacy/manage_user.php.
- risk 0.64cvss 9.8epss 0.00
SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, create, update and delete databases via the “city” and “state” parameters in the /controller/ccity.php endpoint.
- risk 0.64cvss 9.8epss 0.00
SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_clearance.
- risk 0.64cvss 9.8epss 0.01
An issue in Student Study Center Desk Management System v1.0 allows attackers to bypass authentication via a crafted GET request to /php-sscdms/admin/login.php.
- risk 0.64cvss 9.8epss 0.00
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the template parameter at id_generator/admin/?page=generate&template=4.
- risk 0.64cvss 9.8epss 0.00
Sourcecodester Online ID Generator System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at id_generator/admin/?page=generate/index&id=1.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Sentiment Based Movie Rating System 1.0 is vulnerable to SQL Injection in /msrps/movies.php.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Survey Application System 1.0 is vulnerable to SQL Injection in takeSurvey.php via the id parameter.
- risk 0.64cvss 9.8epss 0.00
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Incorrect Access Control. There is a lack of authorization checks for admin operations. Specifically, an attacker can perform admin-level actions without possessing a valid session token. The application does…
- risk 0.64cvss 9.8epss 0.01
SourceCodester Computer Laboratory Management System 1.0 allows admin/category/view_category.php id SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Computer Laboratory Management System 1.0 allows classes/Master.php id SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via the id parameter to php-lfis/admin/categories/manage_category.php.
- risk 0.64cvss 9.8epss 0.01
Simple Library Management System Project Using PHP/MySQL v1.0 was discovered to contain an arbitrary file upload vulnerability via the component ajax.php.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability…
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability in /hrm/user/ in SourceCodester Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via the password parameter.
- risk 0.64cvss 9.8epss 0.01
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/damage/view_damage.php.
- risk 0.64cvss 9.8epss 0.01
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the subject parameter at /customer_support/ajax.php?action=save_ticket.
- risk 0.64cvss 9.8epss 0.01
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the username parameter at /customer_support/ajax.php?action=login.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages.
- risk 0.64cvss 9.8epss 0.01
Online Medicine Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /omos/?p=products/view_product.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_details_edit.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via txtsearch parameter in review_search.php.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in oretnom23 Judging Management System v1.0, allows remote attackers to execute arbitrary code and obtain sensitive information via sub_event_id parameter in sub_event_stat_update.php.
- risk 0.64cvss 9.8epss 0.01
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Packers and Movers Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /inquiries/view_inquiry.php.
- risk 0.64cvss 9.8epss 0.01
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privileges to the administrator's role.
- risk 0.64cvss 9.8epss 0.01
Simple Customer Relationship Management 1.0 is vulnerable to SQL Injection via the email parameter.
- risk 0.64cvss 9.8epss 0.01
SourceCodester Employee and Visitor Gate Pass Logging System v1.0 is vulnerable to SQL Injection via /employee_gatepass/classes/Login.php.
- risk 0.64cvss 9.8epss 0.01
Sourcecodester Student Study Center Desk Management System v1.0 admin\reports\index.php#date_from has a SQL Injection vulnerability.
- risk 0.64cvss 9.8epss 0.02
Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution. The vulnerability path is /classes/Users.php?f=save.
- risk 0.64cvss 9.8epss 0.01
File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the update_settings parameter.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /admin/ajax.php?action=save_menu of Online Food Ordering System v2.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the event_id parameter at /php-jms/result_sheet.php.
Page 1 of 22