Vendor CVEs
Oretnom23
All CVEs
1,064 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-31650 | Cri | 0.62 | 9.6 | 0.01 | Apr 15, 2024 | A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter. | ||
| CVE-2022-25395 | Cri | 0.62 | 9.6 | 0.01 | Mar 2, 2022 | Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app. | ||
| CVE-2025-70141 | Cri | 0.61 | 9.4 | 0.01 | Feb 18, 2026 | SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An… | ||
| CVE-2024-34226 | Cri | 0.61 | 9.4 | 0.01 | May 14, 2024 | SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters. | ||
| CVE-2024-31545 | Cri | 0.61 | 9.4 | 0.01 | Apr 22, 2024 | Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/manage_user&id=6. | ||
| CVE-2024-32167 | Cri | 0.59 | 9.1 | 0.01 | Jun 10, 2024 | Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files. | ||
| CVE-2024-31547 | Cri | 0.59 | 9.1 | 0.01 | Apr 19, 2024 | Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php. | ||
| CVE-2022-31945 | Cri | 0.59 | 9.1 | 0.01 | Jun 2, 2022 | Rescue Dispatch Management System v1.0 is vulnerable to Delete any file via /rdms/classes/Master.php?f=delete_img. | ||
| CVE-2026-30531 | Hig | 0.57 | 8.8 | 0.00 | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize user input supplied to the "name" parameter. This allows an authenticated attacker… | ||
| CVE-2026-30529 | Hig | 0.57 | 8.8 | 0.00 | Mar 27, 2026 | A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an authenticated attacker… | ||
| CVE-2025-40728 | Hig | 0.57 | 8.8 | 0.00 | Jun 16, 2025 | SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter in the /customer_support/manage_user.php endpoint. | ||
| CVE-2025-45956 | Hig | 0.57 | 8.8 | 0.00 | Apr 29, 2025 | A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arbitrary SQL commands via the "id" parameter | ||
| CVE-2024-54818 | Hig | 0.57 | 8.8 | 0.01 | Jan 8, 2025 | SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list. | ||
| CVE-2024-48427 | Hig | 0.57 | 8.8 | 0.01 | Oct 24, 2024 | A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id | ||
| CVE-2024-44739 | Hig | 0.57 | 8.8 | 0.01 | Sep 6, 2024 | Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=. | ||
| CVE-2024-37857 | Hig | 0.57 | 8.8 | 0.01 | Jul 29, 2024 | SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php. | ||
| CVE-2024-34221 | Hig | 0.57 | 8.8 | 0.01 | May 14, 2024 | Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation. | ||
| CVE-2024-33247 | Hig | 0.57 | 8.8 | 0.01 | Apr 25, 2024 | Sourcecodester Employee Task Management System v1.0 is vulnerable to SQL Injection via admin-manage-user.php. | ||
| CVE-2023-49982 | Hig | 0.57 | 8.8 | 0.01 | Mar 21, 2024 | Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts. | ||
| CVE-2023-49978 | Hig | 0.57 | 8.8 | 0.01 | Mar 21, 2024 | Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators. | ||
| CVE-2023-49548 | Hig | 0.57 | 8.8 | 0.01 | Mar 5, 2024 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user. | ||
| CVE-2023-49546 | Hig | 0.57 | 8.8 | 0.01 | Mar 5, 2024 | Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php. | ||
| CVE-2023-50070 | Hig | 0.57 | 8.8 | 0.01 | Dec 29, 2023 | Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject. | ||
| CVE-2023-29627 | Hig | 0.57 | 8.8 | 0.01 | Apr 14, 2023 | Online Pizza Ordering v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. | ||
| CVE-2023-29625 | Hig | 0.57 | 8.8 | 0.01 | Apr 14, 2023 | Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. | ||
| CVE-2023-29621 | Hig | 0.57 | 8.8 | 0.01 | Apr 14, 2023 | Purchase Order Management v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. | ||
| CVE-2023-24732 | Hig | 0.57 | 8.8 | 0.01 | Mar 15, 2023 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function. | ||
| CVE-2023-24731 | Hig | 0.57 | 8.8 | 0.01 | Mar 15, 2023 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function. | ||
| CVE-2023-24730 | Hig | 0.57 | 8.8 | 0.01 | Mar 15, 2023 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function. | ||
| CVE-2023-24729 | Hig | 0.57 | 8.8 | 0.01 | Mar 15, 2023 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function. | ||
| CVE-2023-24728 | Hig | 0.57 | 8.8 | 0.01 | Mar 15, 2023 | Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function. | ||
| CVE-2023-24656 | Hig | 0.57 | 8.8 | 0.01 | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket function. | ||
| CVE-2023-24654 | Hig | 0.57 | 8.8 | 0.01 | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function. | ||
| CVE-2023-24653 | Hig | 0.57 | 8.8 | 0.01 | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function. | ||
| CVE-2023-24652 | Hig | 0.57 | 8.8 | 0.01 | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function. | ||
| CVE-2023-24364 | Hig | 0.57 | 8.8 | 0.01 | Feb 27, 2023 | Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel. | ||
| CVE-2022-43318 | Hig | 0.57 | 8.8 | 0.01 | Nov 7, 2022 | Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the stateedit parameter at /hrm/state.php. | ||
| CVE-2022-43226 | Hig | 0.57 | 8.8 | 0.01 | Nov 2, 2022 | Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment. | ||
| CVE-2022-42070 | Hig | 0.57 | 8.8 | 0.00 | Oct 14, 2022 | Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF). | ||
| CVE-2022-36690 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user&id=. | ||
| CVE-2022-36689 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/waste&month=. | ||
| CVE-2022-36688 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockout&month=. | ||
| CVE-2022-36686 | Hig | 0.57 | 8.8 | 0.01 | Aug 29, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockin&month=. | ||
| CVE-2022-36703 | Hig | 0.57 | 8.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /stocks/manage_stockin.php. | ||
| CVE-2022-36701 | Hig | 0.57 | 8.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/view_item.php. | ||
| CVE-2022-36700 | Hig | 0.57 | 8.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/manage_item.php. | ||
| CVE-2022-36699 | Hig | 0.57 | 8.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/manage_category.php. | ||
| CVE-2022-36698 | Hig | 0.57 | 8.8 | 0.01 | Aug 25, 2022 | Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/view_category.php. | ||
| CVE-2022-31879 | Hig | 0.57 | 8.8 | 0.01 | Jul 26, 2022 | Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter. | ||
| CVE-2022-32415 | Hig | 0.57 | 8.8 | 0.01 | Jul 14, 2022 | Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/?p=products/view_product&id=. |
- risk 0.62cvss 9.6epss 0.01
A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.
- risk 0.62cvss 9.6epss 0.01
Cosmetics and Beauty Product Online Store v1.0 was discovered to contain multiple reflected cross-site scripting (XSS) attacks via the search parameter under the /cbpos/ app.
- risk 0.61cvss 9.4epss 0.01
SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An…
- risk 0.61cvss 9.4epss 0.01
SQL injection vulnerability in /php-sqlite-vms/?page=manage_visitor&id=1 in SourceCodester Visitor Management System 1.0 allow attackers to execute arbitrary SQL commands via the id parameters.
- risk 0.61cvss 9.4epss 0.01
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/?page=user/manage_user&id=6.
- risk 0.59cvss 9.1epss 0.01
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.
- risk 0.59cvss 9.1epss 0.01
Computer Laboratory Management System v1.0 is vulnerable to SQL Injection via the "id" parameter of /admin/item/view_item.php.
- risk 0.59cvss 9.1epss 0.01
Rescue Dispatch Management System v1.0 is vulnerable to Delete any file via /rdms/classes/Master.php?f=delete_img.
- risk 0.57cvss 8.8epss 0.00
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_category action). The application fails to properly sanitize user input supplied to the "name" parameter. This allows an authenticated attacker…
- risk 0.57cvss 8.8epss 0.00
A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in the Actions.php file (specifically the save_user action). The application fails to properly sanitize user input supplied to the "username" parameter. This allows an authenticated attacker…
- risk 0.57cvss 8.8epss 0.00
SQL injection vulnerability in Customer Support System v1.0. This vulnerability allows an authenticated attacker to retrieve, create, update and delete databases via the id parameter in the /customer_support/manage_user.php endpoint.
- risk 0.57cvss 8.8epss 0.00
A SQL injection vulnerability in manage_damage.php in Sourcecodester Computer Laboratory Management System v1.0 allows an authenticated attacker to execute arbitrary SQL commands via the "id" parameter
- risk 0.57cvss 8.8epss 0.01
SourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.
- risk 0.57cvss 8.8epss 0.01
A SQL injection vulnerability in Sourcecodester Packers and Movers Management System v1.0 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in /mpms/admin/?page=services/manage_service&id
- risk 0.57cvss 8.8epss 0.01
Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.
- risk 0.57cvss 8.8epss 0.01
SQL Injection vulnerability in Lost and Found Information System 1.0 allows a remote attacker to escalate privileges via id parameter to php-lfis/admin/categories/view_category.php.
- risk 0.57cvss 8.8epss 0.01
Sourcecodester Human Resource Management System 1.0 is vulnerable to Insecure Permissions resulting in privilege escalation.
- risk 0.57cvss 8.8epss 0.01
Sourcecodester Employee Task Management System v1.0 is vulnerable to SQL Injection via admin-manage-user.php.
- risk 0.57cvss 8.8epss 0.01
Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.
- risk 0.57cvss 8.8epss 0.01
Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.
- risk 0.57cvss 8.8epss 0.01
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the lastname parameter at /customer_support/ajax.php?action=save_user.
- risk 0.57cvss 8.8epss 0.01
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the email parameter at /customer_support/ajax.php.
- risk 0.57cvss 8.8epss 0.01
Sourcecodester Customer Support System 1.0 has multiple SQL injection vulnerabilities in /customer_support/ajax.php?action=save_ticket via department_id, customer_id, and subject.
- risk 0.57cvss 8.8epss 0.01
Online Pizza Ordering v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.
- risk 0.57cvss 8.8epss 0.01
Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.
- risk 0.57cvss 8.8epss 0.01
Purchase Order Management v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the gender parameter in the user profile update function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the query parameter in the user profile update function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the company parameter in the user profile update function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function.
- risk 0.57cvss 8.8epss 0.01
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel.
- risk 0.57cvss 8.8epss 0.01
Human Resource Management System v1.0 was discovered to contain a SQL injection vulnerability via the stateedit parameter at /hrm/state.php.
- risk 0.57cvss 8.8epss 0.01
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.
- risk 0.57cvss 8.8epss 0.00
Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).
- risk 0.57cvss 8.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user&id=.
- risk 0.57cvss 8.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/waste&month=.
- risk 0.57cvss 8.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockout&month=.
- risk 0.57cvss 8.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /admin/?page=reports/stockin&month=.
- risk 0.57cvss 8.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /stocks/manage_stockin.php.
- risk 0.57cvss 8.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/view_item.php.
- risk 0.57cvss 8.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /items/manage_item.php.
- risk 0.57cvss 8.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/manage_category.php.
- risk 0.57cvss 8.8epss 0.01
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/view_category.php.
- risk 0.57cvss 8.8epss 0.01
Online Fire Reporting System 1.0 is vulnerable to SQL Injection via the date parameter.
- risk 0.57cvss 8.8epss 0.01
Product Show Room Site v1.0 is vulnerable to SQL Injection via /psrs/?p=products/view_product&id=.
Page 5 of 22