Total
18411 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2025-13263 | 1 Oretnom23 | 1 Online Magazine Management System | 2025-11-19 | 6.5 MEDIUM | 6.3 MEDIUM |
| A vulnerability was identified in SourceCodester Online Magazine Management System 1.0. Affected by this issue is some unknown functionality of the file /categories.php. The manipulation of the argument c leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. | |||||
| CVE-2025-13264 | 1 Oretnom23 | 1 Online Magazine Management System | 2025-11-19 | 6.5 MEDIUM | 6.3 MEDIUM |
| A security flaw has been discovered in SourceCodester Online Magazine Management System 1.0. This affects an unknown part of the file /view_magazine.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be exploited. | |||||
| CVE-2025-13269 | 1 Campcodes | 1 School Fees Payment Management System | 2025-11-19 | 6.5 MEDIUM | 6.3 MEDIUM |
| A vulnerability has been found in Campcodes School Fees Payment Management System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_payment. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | |||||
| CVE-2025-13270 | 1 Campcodes | 1 School Fees Payment Management System | 2025-11-19 | 6.5 MEDIUM | 6.3 MEDIUM |
| A vulnerability was found in Campcodes School Fees Payment Management System 1.0. This affects an unknown function of the file /ajax.php?action=save_course. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. | |||||
| CVE-2025-13271 | 1 Campcodes | 1 School Fees Payment Management System | 2025-11-19 | 7.5 HIGH | 7.3 HIGH |
| A vulnerability was determined in Campcodes School Fees Payment Management System 1.0. This impacts an unknown function of the file /ajax.php?action=login. This manipulation of the argument Username causes sql injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. | |||||
| CVE-2025-13272 | 1 Campcodes | 1 School Fees Payment Management System | 2025-11-19 | 7.5 HIGH | 7.3 HIGH |
| A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Affected is an unknown function of the file /manage_course.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used. | |||||
| CVE-2025-13277 | 1 Fabian | 1 Nero Social Networking Site | 2025-11-19 | 7.5 HIGH | 7.3 HIGH |
| A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of the file /friendsphoto.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | |||||
| CVE-2025-13278 | 1 Projectworlds | 1 Advanced Library Management System | 2025-11-19 | 6.5 MEDIUM | 6.3 MEDIUM |
| A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /borrowed_book_search.php. Such manipulation of the argument datefrom/dateto leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | |||||
| CVE-2025-13279 | 1 Fabian | 1 Nero Social Networking Site | 2025-11-19 | 6.5 MEDIUM | 6.3 MEDIUM |
| A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used. | |||||
| CVE-2025-13285 | 1 Angeljudesuarez | 1 Online Voting System | 2025-11-19 | 7.5 HIGH | 7.3 HIGH |
| A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of the file /login.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used. | |||||
| CVE-2025-13286 | 1 Angeljudesuarez | 1 Online Voting System | 2025-11-19 | 6.5 MEDIUM | 6.3 MEDIUM |
| A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_user. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited. | |||||
| CVE-2025-13287 | 1 Angeljudesuarez | 1 Online Voting System | 2025-11-19 | 6.5 MEDIUM | 6.3 MEDIUM |
| A weakness has been identified in itsourcecode Online Voting System 1.0. This affects an unknown function of the file /index.php?page=categories. Executing manipulation of the argument id/category can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited. | |||||
| CVE-2025-13289 | 1 1000projects | 1 Design \& Development Of Student Database Management System | 2025-11-19 | 6.5 MEDIUM | 6.3 MEDIUM |
| A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is an unknown function of the file /TeacherLogin/Academics/SubjectDetails.php. The manipulation of the argument SubCode results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. | |||||
| CVE-2024-44641 | 1 Phpgurukul | 1 Small Crm | 2025-11-19 | N/A | 6.5 MEDIUM |
| PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php. | |||||
| CVE-2024-44644 | 1 Phpgurukul | 1 Small Crm | 2025-11-19 | N/A | 6.5 MEDIUM |
| PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php. | |||||
| CVE-2024-44648 | 1 Phpgurukul | 1 Small Crm | 2025-11-19 | N/A | 6.5 MEDIUM |
| PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php. | |||||
| CVE-2024-44652 | 1 Kashipara | 1 Ecommerce Website | 2025-11-19 | N/A | 6.5 MEDIUM |
| Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php. | |||||
| CVE-2025-13290 | 1 Fabian | 1 Simple Food Ordering System | 2025-11-19 | 6.5 MEDIUM | 6.3 MEDIUM |
| A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown functionality of the file /saveorder.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |||||
| CVE-2024-44651 | 1 Kashipara | 1 Ecommerce Website | 2025-11-19 | N/A | 6.5 MEDIUM |
| Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php. | |||||
| CVE-2024-44653 | 1 Kashipara | 1 Ecommerce Website | 2025-11-19 | N/A | 6.5 MEDIUM |
| Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php. | |||||
