Vendor CVEs
Oretnom23
All CVEs
1,064 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29983 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=. | ||
| CVE-2022-29982 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/maintenance/manage_service.php?id=. | ||
| CVE-2022-29981 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete. | ||
| CVE-2022-29980 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=user/manage_user&id=. | ||
| CVE-2022-29979 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation. | ||
| CVE-2022-29751 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client. | ||
| CVE-2022-29749 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice. | ||
| CVE-2022-29748 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=. | ||
| CVE-2022-29747 | Cri | 0.64 | 9.8 | 0.02 | May 12, 2022 | Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id. | ||
| CVE-2022-28417 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase. | ||
| CVE-2022-28416 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase. | ||
| CVE-2022-28415 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection. | ||
| CVE-2022-28413 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Car Driving School Management System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_enrollment. | ||
| CVE-2022-28412 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Car Driving School Managment System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_package. | ||
| CVE-2022-28411 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent. | ||
| CVE-2022-28410 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent. | ||
| CVE-2022-28029 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type. | ||
| CVE-2022-28028 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity. | ||
| CVE-2022-28026 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=student_p&id=. | ||
| CVE-2022-28025 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year. | ||
| CVE-2022-28024 | Cri | 0.64 | 9.8 | 0.01 | Apr 21, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade. | ||
| CVE-2022-28023 | Cri | 0.64 | 9.8 | 0.03 | Apr 21, 2022 | Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_supplier. | ||
| CVE-2022-28022 | Cri | 0.64 | 9.8 | 0.03 | Apr 21, 2022 | Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_item. | ||
| CVE-2022-28468 | Cri | 0.64 | 9.8 | 0.02 | Apr 5, 2022 | Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter. | ||
| CVE-2022-28116 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2022 | Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | ||
| CVE-2022-28115 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2022 | Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | ||
| CVE-2022-27304 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2022 | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter. | ||
| CVE-2022-27123 | Cri | 0.64 | 9.8 | 0.01 | Apr 5, 2022 | Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter. | ||
| CVE-2022-24231 | Cri | 0.64 | 9.8 | 0.02 | Apr 5, 2022 | Simple Student Information System v1.0 was discovered to contain a SQL injection vulnerability via add/Student. | ||
| CVE-2022-26646 | Cri | 0.64 | 9.8 | 0.01 | Mar 30, 2022 | Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter. | ||
| CVE-2022-26645 | Cri | 0.64 | 9.8 | 0.02 | Mar 30, 2022 | A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function. | ||
| CVE-2022-26283 | Cri | 0.64 | 9.8 | 0.02 | Mar 21, 2022 | Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests. | ||
| CVE-2022-26170 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. | ||
| CVE-2022-26169 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter. | ||
| CVE-2022-25399 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter. | ||
| CVE-2022-25396 | Cri | 0.64 | 9.8 | 0.01 | Mar 2, 2022 | Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter. | ||
| CVE-2022-25096 | Cri | 0.64 | 9.8 | 0.02 | Feb 26, 2022 | Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php. | ||
| CVE-2021-45435 | Cri | 0.64 | 9.8 | 0.01 | Jan 28, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php. | ||
| CVE-2021-46427 | Cri | 0.64 | 9.8 | 0.02 | Jan 27, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php. | ||
| CVE-2021-41659 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2022 | SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field. | ||
| CVE-2021-40596 | Cri | 0.64 | 9.8 | 0.01 | Jan 24, 2022 | SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter. | ||
| CVE-2021-40247 | Cri | 0.64 | 9.8 | 0.03 | Jan 21, 2022 | SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field. | ||
| CVE-2021-46309 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter. | ||
| CVE-2021-46200 | Cri | 0.64 | 9.8 | 0.02 | Jan 21, 2022 | An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php. | ||
| CVE-2021-45255 | Cri | 0.64 | 9.8 | 0.02 | Dec 21, 2021 | The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted… | ||
| CVE-2021-45253 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2021 | The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The… | ||
| CVE-2021-45252 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2021 | Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this… | ||
| CVE-2021-41931 | Cri | 0.64 | 9.8 | 0.01 | Nov 17, 2021 | The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. These two requests resulted… | ||
| CVE-2021-41644 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2021 | Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters. | ||
| CVE-2021-42169 | Cri | 0.64 | 9.8 | 0.03 | Oct 22, 2021 | The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no… |
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/view_invoice&id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/maintenance/manage_service.php?id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Users.php?f=delete.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=user/manage_user&id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_designation.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_client.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/classes/Master.php?f=delete_invoice.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via \cms\admin?page=client/manage_client&id=.
- risk 0.64cvss 9.8epss 0.02
Simple Client Management System 1.0 is vulnerable to SQL Injection via /cms/admin/?page=invoice/manage_invoice&id= // Leak place ---> id.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_phase.
- risk 0.64cvss 9.8epss 0.01
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via /hocms/classes/Master.php?f=delete_collection.
- risk 0.64cvss 9.8epss 0.01
Car Driving School Management System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_enrollment.
- risk 0.64cvss 9.8epss 0.01
Car Driving School Managment System v1.0 was discovered to contain a SQL injection vulnerability via /cdsms/classes/Master.php?f=delete_package.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/admin/?page=agents/manage_agent.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Users.php?f=delete_agent.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_type.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity.
- risk 0.64cvss 9.8epss 0.01
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=student_p&id=.
- risk 0.64cvss 9.8epss 0.01
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year.
- risk 0.64cvss 9.8epss 0.01
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade.
- risk 0.64cvss 9.8epss 0.03
Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_supplier.
- risk 0.64cvss 9.8epss 0.03
Purchase Order Management System v1.0 was discovered to contain a SQL injection vulnerability via /purchase_order/classes/Master.php?f=delete_item.
- risk 0.64cvss 9.8epss 0.02
Payroll Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
- risk 0.64cvss 9.8epss 0.01
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
- risk 0.64cvss 9.8epss 0.01
Online Sports Complex Booking v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
- risk 0.64cvss 9.8epss 0.01
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
- risk 0.64cvss 9.8epss 0.01
Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter.
- risk 0.64cvss 9.8epss 0.02
Simple Student Information System v1.0 was discovered to contain a SQL injection vulnerability via add/Student.
- risk 0.64cvss 9.8epss 0.01
Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.
- risk 0.64cvss 9.8epss 0.02
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
- risk 0.64cvss 9.8epss 0.02
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
- risk 0.64cvss 9.8epss 0.01
Simple Mobile Comparison Website v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
- risk 0.64cvss 9.8epss 0.01
Air Cargo Management System v1.0 was discovered to contain a SQL injection vulnerability via the ref_code parameter.
- risk 0.64cvss 9.8epss 0.01
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
- risk 0.64cvss 9.8epss 0.01
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain a SQL injection vulnerability via the search parameter.
- risk 0.64cvss 9.8epss 0.02
Home Owners Collection Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in /members/view_member.php.
- risk 0.64cvss 9.8epss 0.01
An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Simple Chatbot Application 1.0 via the message parameter in Master.php.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter.
- risk 0.64cvss 9.8epss 0.03
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.
- risk 0.64cvss 9.8epss 0.02
An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.
- risk 0.64cvss 9.8epss 0.02
The email parameter from ajax.php of Video Sharing Website 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The application interacted…
- risk 0.64cvss 9.8epss 0.01
The id parameter in view_storage.php from Simple Cold Storage Management System 1.0 appears to be vulnerable to SQL injection attacks. A payload injects a SQL sub-query that calls MySQL's load_file function with a UNC file path that references a URL on an external domain. The…
- risk 0.64cvss 9.8epss 0.01
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this…
- risk 0.64cvss 9.8epss 0.01
The Company's Recruitment Management System in id=2 of the parameter from view_vacancy app on-page appears to be vulnerable to SQL injection. The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter. These two requests resulted…
- risk 0.64cvss 9.8epss 0.02
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.
- risk 0.64cvss 9.8epss 0.03
The Simple Payroll System with Dynamic Tax Bracket in PHP using SQLite Free Source Code (by: oretnom23 ) is vulnerable from remote SQL-Injection-Bypass-Authentication for the admin account. The parameter (username) from the login form is not protected correctly and there is no…
Page 4 of 22