Vulnerabilities (CVE)

Filtered by vendor Oretnom23 Subscribe
Total 761 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-24729 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 8.8 HIGH
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the address parameter in the user profile update function.
CVE-2023-24728 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 8.8 HIGH
Simple Customer Relationship Management System v1.0 as discovered to contain a SQL injection vulnerability via the contact parameter in the user profile update function.
CVE-2023-24656 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 8.8 HIGH
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the subject parameter under the Create Ticket function.
CVE-2023-24655 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 9.8 CRITICAL
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Profile Update function.
CVE-2023-24654 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 8.8 HIGH
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter under the Request a Quote function.
CVE-2023-24653 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 8.8 HIGH
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the oldpass parameter under the Change Password function.
CVE-2023-24652 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 8.8 HIGH
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the Description parameter under the Create ticket function.
CVE-2023-24651 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 5.4 MEDIUM
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter on the registration page.
CVE-2023-24647 1 Oretnom23 1 Online Food Ordering System 2026-06-17 N/A 7.5 HIGH
Food Ordering System v2.0 was discovered to contain a SQL injection vulnerability via the email parameter.
CVE-2023-24646 1 Oretnom23 1 Online Food Ordering System 2026-06-17 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /fos/admin/ajax.php of Food Ordering System v2.0 allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2023-24364 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 8.8 HIGH
Simple Customer Relationship Management System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter under the Admin Panel.
CVE-2023-24204 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 5.4 MEDIUM
SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.
CVE-2023-24203 1 Oretnom23 1 Simple Customer Relationship Management System 2026-06-17 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).
CVE-2023-24202 1 Oretnom23 1 Raffle Draw System 2026-06-17 N/A 9.8 CRITICAL
Raffle Draw System v1.0 was discovered to contain a local file inclusion vulnerability via the page parameter in index.php.
CVE-2023-24201 1 Oretnom23 1 Raffle Draw System 2026-06-17 N/A 9.8 CRITICAL
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at get_ticket.php.
CVE-2023-24200 1 Oretnom23 1 Raffle Draw System 2026-06-17 N/A 9.8 CRITICAL
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at save_ticket.php.
CVE-2023-24199 1 Oretnom23 1 Raffle Draw System 2026-06-17 N/A 9.8 CRITICAL
Raffle Draw System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at delete_ticket.php.
CVE-2023-24198 1 Oretnom23 1 Raffle Draw System 2026-06-17 N/A 9.8 CRITICAL
Raffle Draw System v1.0 was discovered to contain multiple SQL injection vulnerabilities at save_winner.php via the ticket_id and draw parameters.
CVE-2023-24197 1 Oretnom23 1 Online Food Ordering System 2026-06-17 N/A 6.1 MEDIUM
Online Food Ordering System v2 was discovered to contain a SQL injection vulnerability via the id parameter at view_order.php.
CVE-2023-24195 1 Oretnom23 1 Online Food Ordering System 2026-06-17 N/A 6.1 MEDIUM
Online Food Ordering System v2 was discovered to contain a cross-site scripting (XSS) vulnerability via the page parameter in index.php.