Vendor CVEs
Oretnom23
All CVEs
1,064 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30077 | Cri | 0.64 | 9.8 | 0.01 | May 4, 2023 | Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id. | ||
| CVE-2023-30204 | Cri | 0.64 | 9.8 | 0.01 | May 3, 2023 | Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /php-jms/edit_judge.php. | ||
| CVE-2023-29622 | Cri | 0.64 | 9.8 | 0.02 | Apr 14, 2023 | Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php. | ||
| CVE-2023-24655 | Cri | 0.64 | 9.8 | 0.01 | Mar 23, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function. | ||
| CVE-2023-24646 | Cri | 0.64 | 9.8 | 0.01 | Feb 13, 2023 | An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file. | ||
| CVE-2023-24202 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php. | ||
| CVE-2023-24201 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php. | ||
| CVE-2023-24200 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php. | ||
| CVE-2023-24199 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php. | ||
| CVE-2023-24198 | Cri | 0.64 | 9.8 | 0.01 | Feb 6, 2023 | Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters. | ||
| CVE-2020-29297 | Cri | 0.64 | 9.8 | 0.01 | Jan 20, 2023 | Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0. | ||
| CVE-2022-44151 | Cri | 0.64 | 9.8 | 0.01 | Nov 30, 2022 | Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php. | ||
| CVE-2022-44400 | Cri | 0.64 | 9.8 | 0.01 | Nov 28, 2022 | Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info. | ||
| CVE-2022-44139 | Cri | 0.64 | 9.8 | 0.01 | Nov 23, 2022 | Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php. | ||
| CVE-2022-43262 | Cri | 0.64 | 9.8 | 0.01 | Nov 16, 2022 | Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php. | ||
| CVE-2022-43058 | Cri | 0.64 | 9.8 | 0.01 | Nov 9, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity. | ||
| CVE-2022-36609 | Cri | 0.64 | 9.8 | 0.01 | Sep 2, 2022 | Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php. | ||
| CVE-2022-36759 | Cri | 0.64 | 9.8 | 0.01 | Sep 2, 2022 | Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=. | ||
| CVE-2022-36706 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_stockout.php. | ||
| CVE-2022-36705 | Cri | 0.64 | 9.8 | 0.01 | Aug 28, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_waste.php. | ||
| CVE-2022-36683 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment. | ||
| CVE-2022-36682 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student. | ||
| CVE-2022-36680 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule. | ||
| CVE-2022-36679 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user. | ||
| CVE-2022-36678 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2022 | Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category. | ||
| CVE-2022-36697 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste. | ||
| CVE-2022-36696 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockout. | ||
| CVE-2022-36695 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin. | ||
| CVE-2022-36693 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item. | ||
| CVE-2022-36692 | Cri | 0.64 | 9.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category. | ||
| CVE-2022-36242 | Cri | 0.64 | 9.8 | 0.01 | Aug 16, 2022 | Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=. | ||
| CVE-2022-36750 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2022 | Clinic's Patient Management System v1.0 is vulnerable to SQL injection via /pms/update_user.php?id=. | ||
| CVE-2022-36270 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2022 | Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php. | ||
| CVE-2022-32337 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=. | ||
| CVE-2022-32352 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_admission. | ||
| CVE-2022-32336 | Cri | 0.64 | 9.8 | 0.01 | Jun 14, 2022 | Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=. | ||
| CVE-2022-31993 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_service. | ||
| CVE-2022-31990 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_product. | ||
| CVE-2022-31989 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=user/manage_user&id=. | ||
| CVE-2022-32002 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/courts/manage_court.php?id=. | ||
| CVE-2022-31978 | Cri | 0.64 | 9.8 | 0.07 | Jun 2, 2022 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry. | ||
| CVE-2022-31977 | Cri | 0.64 | 9.8 | 0.07 | Jun 2, 2022 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team. | ||
| CVE-2022-31976 | Cri | 0.64 | 9.8 | 0.07 | Jun 2, 2022 | Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request. | ||
| CVE-2022-31969 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=user/manage_user&id=. | ||
| CVE-2022-31965 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/respondent_types/manage_respondent_type.php?id=. | ||
| CVE-2022-31964 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/respondent_types/view_respondent_type.php?id=. | ||
| CVE-2022-31962 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/view_incident.php?id=. | ||
| CVE-2022-31961 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/manage_incident.php?id=. | ||
| CVE-2022-31959 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/teams/manage_team.php?id=. | ||
| CVE-2022-31957 | Cri | 0.64 | 9.8 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/teams/view_team.php?id=. |
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 by oretnom23 was discovered to vulnerable to SQL injection via /php-jms/review_result.php?mainevent_id=, mainevent_id.
- risk 0.64cvss 9.8epss 0.01
Judging Management System v1.0 was discovered to contain a SQL injection vulnerability via the judge_id parameter at /php-jms/edit_judge.php.
- risk 0.64cvss 9.8epss 0.02
Purchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /purchase_order/admin/login.php.
- risk 0.64cvss 9.8epss 0.01
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.
- risk 0.64cvss 9.8epss 0.01
Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.
- risk 0.64cvss 9.8epss 0.01
Multiple SQL Injection vulnerabilities in tourist5 Online-food-ordering-system 1.0.
- risk 0.64cvss 9.8epss 0.01
Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.
- risk 0.64cvss 9.8epss 0.01
Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order/admin/?page=system_info.
- risk 0.64cvss 9.8epss 0.01
Apartment Visitor Management System v1.0 is vulnerable to SQL Injection via /avms/index.php.
- risk 0.64cvss 9.8epss 0.01
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at /hrm/controller/login.php.
- risk 0.64cvss 9.8epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms//classes/Master.php?f=delete_activity.
- risk 0.64cvss 9.8epss 0.01
Clinic's Patient Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /pms/update_patient.php.
- risk 0.64cvss 9.8epss 0.01
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the component /dishes.php?res_id=.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_stockout.php.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id parameter at /stocks/manage_waste.php.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user.
- risk 0.64cvss 9.8epss 0.01
Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_waste.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockout.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_stockin.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_item.
- risk 0.64cvss 9.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category.
- risk 0.64cvss 9.8epss 0.01
Clinic's Patient Management System v1.0 is vulnerable to SQL Injection via /pms/update_medicine.php?id=.
- risk 0.64cvss 9.8epss 0.01
Clinic's Patient Management System v1.0 is vulnerable to SQL injection via /pms/update_user.php?id=.
- risk 0.64cvss 9.8epss 0.01
Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.
- risk 0.64cvss 9.8epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/admin/patients/manage_patient.php?id=.
- risk 0.64cvss 9.8epss 0.01
Hospital's Patient Records Management System v1.0 is vulnerable to SQL Injection via /hprms/classes/Master.php?f=delete_patient_admission.
- risk 0.64cvss 9.8epss 0.01
Fast Food Ordering System v1.0 is vulnerable to SQL Injection via /ffos/admin/menus/view_menu.php?id=.
- risk 0.64cvss 9.8epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/classes/Master.php?f=delete_service.
- risk 0.64cvss 9.8epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via bcms/classes/Master.php?f=delete_product.
- risk 0.64cvss 9.8epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.01
Badminton Center Management System v1.0 is vulnerable to SQL Injection via /bcms/admin/courts/manage_court.php?id=.
- risk 0.64cvss 9.8epss 0.07
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_inquiry.
- risk 0.64cvss 9.8epss 0.07
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_team.
- risk 0.64cvss 9.8epss 0.07
Online Fire Reporting System v1.0 is vulnerable to SQL Injection via /ofrs/classes/Master.php?f=delete_request.
- risk 0.64cvss 9.8epss 0.01
ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/respondent_types/manage_respondent_type.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/respondent_types/view_respondent_type.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/view_incident.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/incidents/manage_incident.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/admin/teams/manage_team.php?id=.
- risk 0.64cvss 9.8epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via rdms/admin/teams/view_team.php?id=.
Page 2 of 22