VYPR

Vendor CVEs

Oretnom23

All CVEs

1,064 total · sorted by risk
  • CVE-2022-30402HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_sub_category&id=.

  • CVE-2022-30400HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/orders/view_order.php?view=user&id=.

  • CVE-2022-30399HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=maintenance/manage_category&id=.

  • CVE-2022-30398HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=orders/view_order&id=.

  • CVE-2022-30396HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=inventory/manage_inventory&id=.

  • CVE-2022-30393HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Merchandise Online Store v1.0 is vulnerable to SQL Injection via /vloggers_merch/admin/?page=product/manage_product&id=.

  • CVE-2022-30379HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Sourcecodester Simple Social Networking Site v1.0 is vulnerable to SQL Injection via /sns/admin/?page=user/manage_user&id=.

  • CVE-2022-30374HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/?page=transactions/manage_transaction&id=.

  • CVE-2022-30373HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/manage_cargo_type.php?id=.

  • CVE-2022-30372HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/classes/Master.php?f=delete_cargo.

  • CVE-2022-30371HigMay 13, 2022
    risk 0.47cvss 7.2epss 0.01

    Air Cargo Management System 1.0 is vulnerable to SQL Injection via /acms/admin/cargo_types/view_cargo_type.php?id=.

  • CVE-2023-49983MedMar 21, 2024
    risk 0.44cvss 6.8epss 0.01

    A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.

  • CVE-2023-1826MedApr 4, 2023
    risk 0.44cvss 6.3epss 0.04

    A vulnerability, which was classified as critical, was found in SourceCodester Online Computer and Laptop Store 1.0. This affects an unknown part of the file php-ocls\admin\system_info\index.php. The manipulation of the argument img leads to unrestricted upload. It is possible…

  • CVE-2022-2297MedJul 12, 2022
    risk 0.44cvss 6.3epss 0.03

    A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0. Affected is an unknown function of the file /pms/update_user.php?user_id=1. The manipulation of the argument profile_picture with the input <?php phpinfo();?>…

  • CVE-2024-0265MedJan 7, 2024
    risk 0.43cvss 6.3epss 0.21

    A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /index.php of the component GET Parameter Handler. The manipulation of the argument page leads to file inclusion. The…

  • CVE-2026-30523MedApr 1, 2026
    risk 0.42cvss 6.5epss 0.00

    A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to the lack of proper input validation. The application allows administrators to define "Loan Plans" which determine the duration of a loan (in months). However, the backend fails to validate…

  • CVE-2026-30522MedApr 1, 2026
    risk 0.42cvss 6.5epss 0.00

    A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific penalty rates for overdue payments. While the frontend interface prevents users…

  • CVE-2026-30521MedMar 31, 2026
    risk 0.42cvss 6.5epss 0.00

    A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific interest rates. While the frontend interface prevents users from entering…

  • CVE-2024-57522MedFeb 3, 2025
    risk 0.42cvss 6.4epss 0.01

    SourceCodester Packers and Movers Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in Users.php. An attacker can inject a malicious script into the username or name field during user creation.

  • CVE-2024-51030MedNov 8, 2024
    risk 0.42cvss 6.5epss 0.01

    A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, leading to unauthorized access and potential compromise of sensitive data within the…

  • CVE-2024-41332MedAug 12, 2024
    risk 0.42cvss 6.5epss 0.01

    Incorrect access control in the delete_category function of Sourcecodester Computer Laboratory Management System v1.0 allows authenticated attackers with low-level privileges to arbitrarily delete categories.

  • CVE-2023-49985MedMar 21, 2024
    risk 0.42cvss 6.5epss 0.00

    A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname parameter.

  • CVE-2023-1467MedMar 17, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Student Study Center Desk Management System 1.0. Affected is an unknown function of the file Master.php?f=delete_img of the component POST Parameter Handler. The manipulation of the argument path with the…

  • CVE-2023-27073MedMar 14, 2023
    risk 0.42cvss 6.5epss 0.00

    A Cross-Site Request Forgery (CSRF) in Online Food Ordering System v1.0 allows attackers to change user details and credentials via a crafted POST request.

  • CVE-2022-44280MedNov 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Automotive Shop Management System v1.0 is vulnerable to Delete any file via /asms/classes/Master.php?f=delete_img.

  • CVE-2022-43351MedNov 7, 2022
    risk 0.42cvss 6.5epss 0.01

    Sanitization Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.

  • CVE-2022-36687MedAug 29, 2022
    risk 0.42cvss 6.5epss 0.01

    Ingredients Stock Management System v1.0 was discovered to contain an arbitrary file deletion vulnerability via the component /classes/Master.php?f=delete_img.

  • CVE-2022-31973MedJun 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Online Fire Reporting System v1.0 is vulnerable to Delete any file via /ofrs/classes/Master.php?f=delete_img.

  • CVE-2022-31966MedJun 2, 2022
    risk 0.42cvss 6.5epss 0.01

    ChatBot App with Suggestion v1.0 is vulnerable to Delete any file via /simple_chat_bot/classes/Master.php?f=delete_img.

  • CVE-2022-31342MedJun 2, 2022
    risk 0.42cvss 6.5epss 0.01

    Online Car Wash Booking System v1.0 is vulnerable to Delete any file via /ocwbs/classes/Master.php?f=delete_img.

  • CVE-2022-30408MedMay 13, 2022
    risk 0.42cvss 6.5epss 0.01

    Covid-19 Travel Pass Management System v1.0 is vulnerable to file deletion via /ctpms/classes/Master.php?f=delete_img.

  • CVE-2022-30381MedMay 13, 2022
    risk 0.42cvss 6.5epss 0.01

    Merchandise Online Store v1.0 is vulnerable to file deletion via /vloggers_merch/classes/Master.php?f=delete_img.

  • CVE-2022-30367MedMay 13, 2022
    risk 0.42cvss 6.5epss 0.01

    Air Cargo Management System v1.0 is vulnerable to file deletion via /acms/classes/Master.php?f=delete_img.

  • CVE-2026-3806MedMar 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in SourceCodester/janobe Resort Reservation System 1.0. This issue affects some unknown processing of the file /room_rates.php. This manipulation of the argument q causes sql injection. The attack can be initiated remotely. The exploit has been…

  • CVE-2026-3800MedMar 9, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit…

  • CVE-2026-3771MedMar 8, 2026
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. This vulnerability affects unknown code of the file /accomodation.php. Such manipulation of the argument q leads to sql injection. The attack may be performed from remote. The exploit has been…

  • CVE-2025-13347MedNov 18, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of the file /ajax.php?action=save_user. Executing manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit…

  • CVE-2025-13346MedNov 18, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the file /ajax.php?action=save_station. Performing manipulation of the argument id/station results in sql injection. The attack may be initiated remotely. The…

  • CVE-2025-13345MedNov 18, 2025
    risk 0.41cvss 6.3epss 0.01

    A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_ticket. Such manipulation leads to sql injection. The attack can be launched remotely. The…

  • CVE-2025-13264MedNov 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in SourceCodester Online Magazine Management System 1.0. This affects an unknown part of the file /view_magazine.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been…

  • CVE-2025-13263MedNov 17, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in SourceCodester Online Magazine Management System 1.0. Affected by this issue is some unknown functionality of the file /categories.php. The manipulation of the argument c leads to sql injection. The attack is possible to be carried out remotely.…

  • CVE-2025-13059MedNov 12, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown function of the file /manage_career.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possible. The exploit has…

  • CVE-2025-10790MedSep 22, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in SourceCodester Simple Forum Discussion System 1.0. This affects an unknown function of the file /ajax.php?action=save_category. The manipulation of the argument Description results in sql injection. The attack can be executed remotely. The…

  • CVE-2025-10421MedSep 15, 2025
    risk 0.41cvss 6.3epss 0.00

    A flaw has been found in SourceCodester Student Grading System 1.0. This vulnerability affects unknown code of the file /update_account.php. Executing manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published…

  • CVE-2025-10420MedSep 15, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was detected in SourceCodester Student Grading System 1.0. This affects an unknown part of the file /form137.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

  • CVE-2025-10419MedSep 15, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in SourceCodester Student Grading System 1.0. Affected by this issue is some unknown functionality of the file /del_promote.php. Such manipulation of the argument sy leads to sql injection. The attack can be launched remotely. The…

  • CVE-2025-10418MedSep 15, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in SourceCodester Student Grading System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_students.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit…

  • CVE-2025-10409MedSep 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A weakness has been identified in SourceCodester Student Grading System 1.0. This affects an unknown part of the file /rms.php?page=users. Executing manipulation of the argument fname can lead to sql injection. The attack can be launched remotely. The exploit has been made…

  • CVE-2025-10408MedSep 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in SourceCodester Student Grading System 1.0. Affected by this issue is some unknown functionality of the file /edit_user.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated remotely. The…

  • CVE-2025-10407MedSep 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was identified in SourceCodester Student Grading System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_user.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The…

Page 11 of 22