Rickxy
Products
3- 6 CVEs
- 4 CVEs
- 2 CVEs
Recent CVEs
11| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-41524 | Hig | 0.57 | 8.8 | 0.00 | Aug 7, 2025 | Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php. | ||
| CVE-2023-41523 | Hig | 0.57 | 8.8 | 0.00 | Aug 7, 2025 | Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php. | ||
| CVE-2023-41522 | Hig | 0.57 | 8.8 | 0.00 | Aug 7, 2025 | Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters. | ||
| CVE-2023-41520 | Hig | 0.57 | 8.8 | 0.00 | Aug 7, 2025 | Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters. | ||
| CVE-2026-6602 | Hig | 0.47 | 7.3 | 0.00 | Apr 20, 2026 | A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the file /backend/admin/his_admin_account.php. The manipulation of the argument ad_dpic results in unrestricted upload. The attack… | ||
| CVE-2022-4088 | Hig | 0.47 | 7.3 | 0.01 | Nov 24, 2022 | A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched… | ||
| CVE-2025-63497 | Hig | 0.46 | 7.1 | 0.00 | Nov 10, 2025 | The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization,… | ||
| CVE-2023-41519 | Med | 0.40 | 6.1 | 0.00 | Aug 7, 2025 | Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php. | ||
| CVE-2022-4052 | Med | 0.31 | 4.7 | 0.01 | Nov 17, 2022 | A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some unknown processing of the file /Admin/createClass.php. The manipulation of the argument Id leads to sql injection. The attack may be initiated remotely. The… | ||
| CVE-2022-4090 | Med | 0.28 | 4.3 | 0.00 | Nov 24, 2022 | A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_transac.php?action=add. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit… | ||
| CVE-2022-4089 | Med | 0.28 | 4.3 | 0.00 | Nov 24, 2022 | A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The manipulation of the argument user leads to cross site scripting. The attack can be initiated… |
- risk 0.57cvss 8.8epss 0.00
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the username parameter at index.php.
- risk 0.57cvss 8.8epss 0.00
Student Attendance Management System v1 was discovered to contain a SQL injection vulnerability via the emailAddress parameter at createClassTeacher.php.
- risk 0.57cvss 8.8epss 0.00
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createStudents.php via the Id, firstname, and admissionNumber parameters.
- risk 0.57cvss 8.8epss 0.00
Student Attendance Management System v1 was discovered to contain multiple SQL injection vulnerabilities in createClassArms.php via the classId and classArmName parameters.
- risk 0.47cvss 7.3epss 0.00
A vulnerability was found in rickxy Hospital Management System up to 88a4290d957dc5bdde8a56e5ad451ad14f7f90f4. Affected is an unknown function of the file /backend/admin/his_admin_account.php. The manipulation of the argument ad_dpic results in unrestricted upload. The attack…
- risk 0.47cvss 7.3epss 0.01
A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql injection. The attack may be launched…
- risk 0.46cvss 7.1epss 0.00
The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System version 1.0 contains an SQL injection vulnerability. The pat_number GET parameter is directly concatenated into SQL queries without proper sanitization,…
- risk 0.40cvss 6.1epss 0.00
Student Attendance Management System v1 was discovered to contain a cross-site scripting (XSS) vulnerability via the sessionName parameter at createSessionTerm.php.
- risk 0.31cvss 4.7epss 0.01
A vulnerability was found in Student Attendance Management System and classified as critical. This issue affects some unknown processing of the file /Admin/createClass.php. The manipulation of the argument Id leads to sql injection. The attack may be initiated remotely. The…
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in rickxy Stock Management System and classified as problematic. This issue affects some unknown processing of the file us_transac.php?action=add. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit…
- risk 0.28cvss 4.3epss 0.00
A vulnerability was found in rickxy Stock Management System. It has been declared as problematic. This vulnerability affects unknown code of the file /pages/processlogin.php. The manipulation of the argument user leads to cross site scripting. The attack can be initiated…