Vulnerabilities (CVE)

Filtered by vendor Oretnom23 Subscribe
Total 760 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-6867 1 Oretnom23 1 Simple Company Website 2026-04-29 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in SourceCodester Simple Company Website 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/services/manage.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-6868 1 Oretnom23 1 Simple Company Website 2026-04-29 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/clients/manage.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-6872 1 Oretnom23 1 Simple Company Website 2026-04-29 5.8 MEDIUM 4.7 MEDIUM
A vulnerability classified as critical was found in SourceCodester Simple Company Website 1.0. This vulnerability affects unknown code of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument img leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-13468 1 Oretnom23 1 Alumni Management System 2026-04-29 5.5 MEDIUM 5.4 MEDIUM
A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete Handler. Executing manipulation of the argument ID can lead to missing authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.
CVE-2026-1745 1 Oretnom23 1 Medical Certificate Generator App 2026-04-29 5.0 MEDIUM 4.3 MEDIUM
A vulnerability was determined in SourceCodester Medical Certificate Generator App 1.0. This affects an unknown part. This manipulation causes cross-site request forgery. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.
CVE-2026-3746 1 Oretnom23 1 Simple Responsive Tourism Website 2026-04-29 7.5 HIGH 7.3 HIGH
A vulnerability was determined in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /tourism/classes/Login.php?f=login of the component Login. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-6870 1 Oretnom23 1 Simple Company Website 2026-04-29 5.8 MEDIUM 4.7 MEDIUM
A vulnerability was found in SourceCodester Simple Company Website 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /classes/Content.php?f=service. The manipulation of the argument img leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2026-2159 1 Oretnom23 1 Simple Responsive Tourism Website 2026-04-29 5.0 MEDIUM 4.3 MEDIUM
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected is an unknown function of the file /tourism/classes/Master.php?f=register of the component Registration. Executing a manipulation of the argument firstname/lastname/username can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been published and may be used.
CVE-2025-13346 1 Oretnom23 1 Train Station Ticketing System 2026-04-29 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the file /ajax.php?action=save_station. Performing manipulation of the argument id/station results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
CVE-2025-10418 1 Oretnom23 1 Student Grading System 2026-04-29 6.5 MEDIUM 6.3 MEDIUM
A weakness has been identified in SourceCodester Student Grading System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_students.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be exploited.
CVE-2025-10420 1 Oretnom23 1 Student Grading System 2026-04-29 6.5 MEDIUM 6.3 MEDIUM
A vulnerability was detected in SourceCodester Student Grading System 1.0. This affects an unknown part of the file /form137.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
CVE-2026-3771 1 Oretnom23 1 Resort Reservation System 2026-04-29 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. This vulnerability affects unknown code of the file /accomodation.php. Such manipulation of the argument q leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
CVE-2025-10400 1 Oretnom23 1 Food Ordering Management System 2026-04-29 6.5 MEDIUM 6.3 MEDIUM
A security vulnerability has been detected in SourceCodester Food Ordering Management System 1.0. Impacted is an unknown function of the file /routers/ticket-message.php. Such manipulation of the argument ticket_id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.
CVE-2025-13345 1 Oretnom23 1 Train Station Ticketing System 2026-04-29 6.5 MEDIUM 6.3 MEDIUM
A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue is some unknown functionality of the file /ajax.php?action=save_ticket. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
CVE-2026-2848 1 Oretnom23 1 Simple Responsive Tourism Website 2026-04-29 7.5 HIGH 7.3 HIGH
A flaw has been found in SourceCodester Simple Responsive Tourism Website 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Master.php?f=register of the component Registration. This manipulation of the argument Username causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
CVE-2025-9305 1 Oretnom23 1 Online Bank Management System 2026-04-29 7.5 HIGH 7.3 HIGH
A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is an unknown function of the file /bank/mnotice.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
CVE-2025-2655 1 Oretnom23 1 Ac Repair And Services System 2026-04-29 7.5 HIGH 7.3 HIGH
A vulnerability was detected in SourceCodester AC Repair and Services System 1.0. The affected element is the function save_users/delete_users of the file /classes/Users.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. Other parameters might be affected as well.
CVE-2026-3800 1 Oretnom23 1 Resort Reservation System 2026-04-29 6.5 MEDIUM 6.3 MEDIUM
A vulnerability has been found in SourceCodester/janobe Resort Reservation System 1.0. Affected is the function doInsert of the file /controller.php?action=add. Such manipulation of the argument image leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-13451 1 Oretnom23 1 Online Shop Project 2026-04-29 7.5 HIGH 7.3 HIGH
A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
CVE-2024-7219 1 Oretnom23 1 School Log Management System 2026-04-29 7.5 HIGH 7.3 HIGH
A vulnerability has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/ajax.php?action=login. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.