VYPR

Vendor CVEs

Oretnom23

All CVEs

1,064 total · sorted by risk
  • CVE-2021-41645HigOct 29, 2021
    risk 0.57cvss 8.8epss 0.03

    Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field. .

  • CVE-2023-33676HigMar 7, 2024
    risk 0.55cvss 8.4epss 0.01

    Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*" which can be escalated to the remote command execution.

  • CVE-2026-30534HigMar 27, 2026
    risk 0.54cvss 8.3epss 0.00

    A SQL Injection vulnerability exists in SourceCodester Online Food Ordering System v1.0 in admin/manage_category.php via the "id" parameter.

  • CVE-2024-33303HigMay 2, 2024
    risk 0.53cvss 8.2epss 0.01

    SourceCodester Product Show Room 1.0 is vulnerable to Cross Site Scripting (XSS) via "First Name" under Add Users.

  • CVE-2023-44824HigOct 17, 2023
    risk 0.51cvss 7.8epss 0.00

    An issue in Expense Management System v.1.0 allows a local attacker to execute arbitrary code via a crafted file uploaded to the sign-up.php component.

  • CVE-2023-33440HigMay 26, 2023
    risk 0.51cvss 7.2epss 0.15

    Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.

  • CVE-2022-25115HigMar 2, 2022
    risk 0.51cvss 7.8epss 0.02

    A remote code execution (RCE) vulnerability in the Avatar parameter under /admin/?page=user/manage_user of Home Owners Collection Management System v1.0 allows attackers to execute arbitrary code via a crafted PNG file.

  • CVE-2025-63891HigNov 14, 2025
    risk 0.49cvss 7.5epss 0.00

    Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenticated HTTP GET request to…

  • CVE-2025-44193HigApr 30, 2025
    risk 0.49cvss 7.6epss 0.00

    SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint.

  • CVE-2024-34220HigMay 14, 2024
    risk 0.49cvss 7.5epss 0.01

    Sourcecodester Human Resource Management System 1.0 is vulnerable to SQL Injection via the 'leave' parameter.

  • CVE-2023-49981HigMar 21, 2024
    risk 0.49cvss 7.5epss 0.01

    A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.

  • CVE-2023-33677HigMar 6, 2024
    risk 0.49cvss 7.5epss 0.00

    Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".

  • CVE-2023-49545HigMar 1, 2024
    risk 0.49cvss 7.5epss 0.01

    A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.

  • CVE-2024-0264HigJan 7, 2024
    risk 0.49cvss 7.3epss 0.18

    A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /LoginRegistration.php. The manipulation of the argument formToken leads to authorization bypass. The attack can be…

  • CVE-2023-29626HigApr 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Yoga Class Registration System 1.0 was discovered to contain a SQL injection vulnerability via the cid parameter at /admin/login.php.

  • CVE-2023-24647HigFeb 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.

  • CVE-2022-34067HigJul 26, 2022
    risk 0.49cvss 7.5epss 0.01

    Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.

  • CVE-2022-25393HigMar 2, 2022
    risk 0.49cvss 7.5epss 0.01

    Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

  • CVE-2021-44600HigDec 23, 2021
    risk 0.49cvss 7.5epss 0.01

    The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through the password parameter. The predictive tests of this application interacted with that domain, indicating that the injected SQL query was…

  • CVE-2021-38758HigAug 16, 2021
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in Online Catering Reservation System 1.0 exists due to lack of validation in index.php.

  • CVE-2024-9818HigOct 10, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Online Veterinary Appointment System 1.0. Affected is an unknown function of the file /admin/categories/manage_category.php. The manipulation of the argument id leads to sql injection. It is possible to…

  • CVE-2024-8565HigSep 7, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodesters Clinics Patient Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /print_diseases.php. The manipulation of the argument disease/from/to leads to sql injection. The attack may…

  • CVE-2024-8343HigAug 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Sentiment Based Movie Rating System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save_client of the component User Registration Handler. The manipulation of the argument email…

  • CVE-2024-8340HigAug 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Electric Billing Management System 1.0. This affects an unknown part of the file /Actions.php?a=login. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack…

  • CVE-2024-7798HigAug 15, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=login2. The manipulation of the…

  • CVE-2024-7797HigAug 15, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been classified as critical. Affected is an unknown function of the file /simple-online-bidding-system/bidding/admin/ajax.php?action=login. The manipulation of the argument username leads to sql…

  • CVE-2024-7369HigAug 1, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Simple Realtime Quiz System 1.0 and classified as critical. This issue affects some unknown processing of the file /ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql injection. The…

  • CVE-2024-7366HigAug 1, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Tracking Monitoring Management System 1.0. It has been classified as critical. This affects an unknown part of the file /ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql injection. It…

  • CVE-2024-7286HigJul 31, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Establishment Billing Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/ajax.php?action=login of the component Login. The manipulation of the argument username leads to sql…

  • CVE-2024-7279HigJul 31, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Lot Reservation Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can…

  • CVE-2024-7219HigJul 30, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument Username leads to sql injection. It is possible to…

  • CVE-2024-7164HigJul 28, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester School Fees Payment System 1.0 and classified as critical. This vulnerability affects unknown code of the file /ajax.php?action=login. The manipulation of the argument username leads to sql injection. The attack can be initiated…

  • CVE-2024-6213HigJun 21, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Food Ordering Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file login.php of the component Login Panel. The manipulation of the argument username leads to sql injection. It is…

  • CVE-2024-5976HigJun 13, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. It has been classified as critical. Affected is the function log_employee of the file /classes/Master.php?f=log_employee. The manipulation of the argument employee_code leads to sql…

  • CVE-2024-5896HigJun 12, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Employee and Visitor Gate Pass Logging System 1.0. Affected is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to sql injection. It is possible…

  • CVE-2024-5894HigJun 12, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester Online Eyewear Shop 1.0. This vulnerability affects unknown code of the file manage_product.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has…

  • CVE-2024-5384HigMay 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester Facebook News Feed Like 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument page leads to sql injection. The attack can be initiated remotely. VDB-266302 is the…

  • CVE-2024-5122HigMay 20, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Event Registration System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /registrar/. The manipulation of the argument search leads to sql injection. The attack may be launched…

  • CVE-2024-5118HigMay 20, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Event Registration System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/login.php. The manipulation of the argument username/password leads to sql injection. The attack can be initiated…

  • CVE-2024-5117HigMay 20, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Event Registration System 1.0. This affects an unknown part of the file portal.php. The manipulation of the argument username/password leads to sql injection. It is possible to initiate the attack…

  • CVE-2024-4927HigMay 16, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=save_product. The manipulation leads to…

  • CVE-2024-34224HigMay 14, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.

  • CVE-2024-3376HigApr 6, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part of the file config.php. The manipulation of the argument url leads to execution after redirect. It is possible to initiate the attack…

  • CVE-2024-2930HigMar 27, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file classes/Master.php?f=save_music. The manipulation leads to unrestricted upload. The attack can be launched…

  • CVE-2024-2577HigMar 18, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /update-employee.php. The manipulation of the argument admin_id leads to authorization bypass. The attack can be…

  • CVE-2024-2576HigMar 18, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Employee Task Management System 1.0. This affects an unknown part of the file /update-admin.php. The manipulation of the argument admin_id leads to authorization bypass. It is possible to initiate the…

  • CVE-2024-2575HigMar 18, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task Management System 1.0. Affected by this issue is some unknown functionality of the file /task-details.php. The manipulation of the argument task_id leads to authorization bypass.…

  • CVE-2024-2574HigMar 18, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester Employee Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /edit-task.php. The manipulation of the argument task_id leads to authorization bypass. The attack can…

  • CVE-2024-2573HigMar 18, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Employee Task Management System 1.0. Affected is an unknown function of the file /task-info.php. The manipulation leads to execution after redirect. It is possible to launch the attack remotely. The exploit…

  • CVE-2024-2572HigMar 18, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in SourceCodester Employee Task Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /task-details.php. The manipulation leads to execution after redirect. The attack may be initiated remotely. The…

Page 6 of 22