VYPR

Vendor CVEs

Rems

All CVEs

51 total · sorted by risk
  • CVE-2024-40472CriAug 12, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."

  • CVE-2024-25211CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php.

  • CVE-2024-25210CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php.

  • CVE-2024-25209CriFeb 14, 2024
    risk 0.64cvss 9.8epss 0.01

    Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/delete-resident.php.

  • CVE-2024-24142CriFeb 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.

  • CVE-2024-26517CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the delete-task.php component.

  • CVE-2025-63716MedNov 7, 2025
    risk 0.42cvss 6.5epss 0.00

    The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changing operations. The application lacks CSRF protection mechanisms such as anti-CSRF tokens or same-origin verification for critical endpoints.

  • CVE-2025-10410MedSep 14, 2025
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in SourceCodester Link Status Checker 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argument proxy leads to server-side request forgery. The attack may be initiated remotely. The exploit has…

  • CVE-2025-1168MedFeb 11, 2025
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-contact.php. The manipulation of the argument contact leads to sql injection. The attack can…

  • CVE-2024-9975MedOct 15, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The…

  • CVE-2024-9319MedSep 29, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in SourceCodester Online Timesheet App 1.0. This affects an unknown part of the file /endpoint/delete-timesheet.php. The manipulation of the argument timesheet leads to sql injection. It is possible to initiate the…

  • CVE-2024-9093MedSep 23, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Profile Registration without Reload Refresh 1.0. This affects an unknown part of the file del.php of the component GET Parameter Handler. The manipulation of the argument list leads to sql injection. It is…

  • CVE-2024-8564MedSep 7, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/update.php. The manipulation of the argument tbl_person_id/first_name/middle_name/last_name leads to sql injection. The…

  • CVE-2024-8561MedSep 7, 2024
    risk 0.41cvss 6.3epss 0.00

    A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete.php of the component Delete Person Handler. The manipulation of the argument person leads to sql…

  • CVE-2024-7811MedAug 15, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical has been found in SourceCodester Daily Expenses Monitoring App 1.0. This affects an unknown part of the file /endpoint/delete-expense.php. The manipulation of the argument expense leads to sql injection. It is possible to initiate the…

  • CVE-2024-7792MedAug 14, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been classified as critical. Affected is an unknown function of the file /endpoint/delete-task.php. The manipulation of the argument task leads to sql injection. It is possible to launch the attack…

  • CVE-2024-7643MedAug 12, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Leads Manager Tool 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /endpoint/delete-leads.php of the component Delete Leads Handler. The manipulation of the argument leads leads to sql…

  • CVE-2024-4967MedMay 16, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to sql injection. The…

  • CVE-2024-3797MedApr 15, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-bookmark.php?bookmark=1. The manipulation of the argument bookmark leads to sql injection. The attack…

  • CVE-2024-3129MedApr 1, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in SourceCodester Image Accordion Gallery App 1.0. It has been classified as critical. This affects an unknown part of the file /endpoint/add-image.php. The manipulation of the argument image_name leads to unrestricted upload. It is possible to initiate…

  • CVE-2025-63640MedNov 7, 2025
    risk 0.40cvss 6.1epss 0.00

    Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields when creating an "Upcoming Reminder", allowing an attacker to inject arbitrary potentially malicious HTML/JavaScript code that executes in…

  • CVE-2025-60313MedOct 8, 2025
    risk 0.40cvss 6.1epss 0.00

    Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input field. This allows a remote attacker to execute arbitrary code.

  • CVE-2025-60312MedOct 7, 2025
    risk 0.40cvss 6.1epss 0.00

    Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" field, allowing a remote attacker to inject arbitrary HTML/JavaScript code that executes in the victim's browser upon clicking the "Convert to HTML" button.

  • CVE-2024-28276MedMay 14, 2024
    risk 0.40cvss 6.1epss 0.00

    Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.

  • CVE-2024-27719MedMar 28, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to the Frequently Asked Question field in the Add FAQ function.

  • CVE-2023-43292MedMar 12, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in My Food Recipe Using PHP with Source Code v.1.0 allows a local attacker to execute arbitrary code via a crafted payload to the Recipe Name, Procedure, and ingredients parameters.

  • CVE-2025-57117MedSep 15, 2025
    risk 0.35cvss 5.4epss 0.00

    A Clickjacking vulnerability exists in Rems' Employee Management System 1.0. This flaw allows remote attackers to execute arbitrary JavaScript on the department.php page by injecting a malicious payload into the Department Name field under Add Department.

  • CVE-2024-1111MedJan 31, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Login System 1.0. Affected by this issue is some unknown functionality of the file add-user.php. The manipulation of the argument qr-code leads to cross site scripting. The attack may…

  • CVE-2025-10088LowSep 8, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was detected in SourceCodester Time Tracker 1.0. The affected element is an unknown function of the file /index.html. Performing manipulation of the argument project-name results in cross site scripting. The attack may be initiated remotely. The exploit is now…

  • CVE-2025-6345LowJun 20, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester My Food Recipe 1.0 and classified as problematic. Affected by this issue is the function addRecipeModal of the file /endpoint/add-recipe.php of the component Add Recipe Page. The manipulation of the argument Name leads to cross site…

  • CVE-2025-1169LowFeb 11, 2025
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Image Compressor Tool 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /image-compressor/compressor.php. The manipulation of the argument image leads to cross site scripting. The attack may…

  • CVE-2024-13069LowDec 31, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Multi Role Login System 1.0. It has been classified as problematic. Affected is an unknown function of the file /endpoint/add-user.php. The manipulation of the argument name leads to cross site scripting. It is possible to launch the…

  • CVE-2024-13021LowDec 29, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in SourceCodester Road Accident Map Marker 1.0. Affected by this issue is some unknown functionality of the file /endpoint/add-mark.php. The manipulation of the argument mark_name/details leads to cross site…

  • CVE-2024-9799LowOct 10, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in SourceCodester Profile Registration without Reload Refresh 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file add.php. The manipulation of the argument email_address/address/company_name/job_…

  • CVE-2024-9320LowSep 29, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in SourceCodester Online Timesheet App 1.0 and classified as problematic. This vulnerability affects unknown code of the file /endpoint/add-timesheet.php of the component Add Timesheet Form. The manipulation of the argument day/task leads to cross…

  • CVE-2024-9092LowSep 23, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Profile Registration without Reload Refresh 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file add.php of the component Registration Form. The manipulation of the argument full_name…

  • CVE-2024-8563LowSep 7, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester PHP CRUD 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/update.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. It is possible to…

  • CVE-2024-8562LowSep 7, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester PHP CRUD 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /endpoint/Add.php. The manipulation of the argument first_name/middle_name/last_name leads to cross site scripting. The attack…

  • CVE-2024-8172LowAug 26, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in SourceCodester QR Code Attendance System 1.0. This issue affects some unknown processing of the file /endpoint/delete-student.php. The manipulation of the argument student/attendance leads to cross site…

  • CVE-2024-8170LowAug 26, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in SourceCodester Zipped Folder Manager App 1.0. This affects an unknown part of the file /endpoint/add-folder.php. The manipulation of the argument folder leads to unrestricted upload. It is possible to initiate the…

  • CVE-2024-8154LowAug 25, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability classified as problematic has been found in SourceCodester QR Code Bookmark System 1.0. Affected is an unknown function of the file /endpoint/update-bookmark.php of the component Parameter Handler. The manipulation of the argument tbl_bookmark_id/name/url leads…

  • CVE-2024-8153LowAug 25, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /endpoint/delete-bookmark.php. The manipulation of the argument bookmark leads to cross site scripting. The attack…

  • CVE-2024-8152LowAug 25, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/add-bookmark.php of the component Parameter Handler. The manipulation of the argument name/url leads to…

  • CVE-2024-8151LowAug 25, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/delete-mark.php. The manipulation of the argument mark leads to cross site scripting. It is possible to initiate…

  • CVE-2024-8142LowAug 25, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /endpoint/delete-calorie.php. The manipulation of the argument calorie leads to cross site scripting. The…

  • CVE-2024-8141LowAug 25, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Daily Calories Monitoring Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-calorie.php. The manipulation of the argument calorie_date/calorie_name leads to cross site scripting. It…

  • CVE-2024-8140LowAug 25, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Task Progress Tracker 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file update-task.php. The manipulation of the argument task_name leads to cross site scripting. The attack may be…

  • CVE-2024-7942LowAug 20, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in SourceCodester Leads Manager Tool 1.0 and classified as problematic. This vulnerability affects unknown code of the file update-leads.php. The manipulation of the argument phone_number leads to cross site scripting. The attack can be initiated…

  • CVE-2024-7793LowAug 14, 2024
    risk 0.23cvss 3.5epss 0.00

    A vulnerability was found in SourceCodester Task Progress Tracker 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /endpoint/add-task.php. The manipulation of the argument task_name leads to cross site scripting.…

  • CVE-2024-7644LowAug 12, 2024
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in SourceCodester Leads Manager Tool 1.0. It has been classified as problematic. This affects an unknown part of the file /endpoint/add-leads.php of the component Add Leads Handler. The manipulation of the argument leads_name/phone_number leads to cross…

Page 1 of 2