Vulnerabilities (CVE)

Filtered by vendor Oretnom23 Subscribe
Total 761 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28026 1 Oretnom23 1 Student Grading System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=student_p&id=.
CVE-2022-28025 1 Oretnom23 1 Student Grading System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year.
CVE-2022-28024 1 Oretnom23 1 Student Grading System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade.
CVE-2022-27304 1 Oretnom23 1 Student Grading System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
CVE-2022-26283 1 Oretnom23 1 Simple Subscription Website 2026-06-17 7.5 HIGH 9.8 CRITICAL
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.
CVE-2021-46309 1 Oretnom23 1 Employee And Visitor Gate Pass Logging System 2026-06-17 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.
CVE-2021-46200 1 Oretnom23 1 Simple Music Cloud Community System 2026-06-17 10.0 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.
CVE-2021-45435 1 Oretnom23 1 Simple Cold Storage Management System 2026-06-17 7.5 HIGH 9.8 CRITICAL
An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php.
CVE-2021-45252 1 Oretnom23 1 Simple Forum\/discussion System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability.
CVE-2021-44653 1 Oretnom23 1 Online Magazine Management System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application.
CVE-2021-44600 1 Oretnom23 1 Simple Online Men\'s Salon Management System 2026-06-17 5.0 MEDIUM 7.5 HIGH
The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through the password parameter. The predictive tests of this application interacted with that domain, indicating that the injected SQL query was executed. The attacker can retrieve all authentication and information about the users of this system.
CVE-2021-43141 1 Oretnom23 1 Simple Subscription Website 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.
CVE-2021-43140 1 Oretnom23 1 Simple Subscription Website 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
CVE-2021-42580 1 Oretnom23 1 Online Learning System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.
CVE-2021-41659 1 Oretnom23 1 Banking System 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.
CVE-2021-41645 1 Oretnom23 1 Budget And Expense Tracker System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field. .
CVE-2021-41644 1 Oretnom23 1 Online Food Ordering System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that bypasses the image upload filters.
CVE-2021-41434 1 Oretnom23 1 Expense Management System 2026-06-17 N/A 5.4 MEDIUM
A stored Cross-Site Scripting (XSS) vulnerability exists in version 1.0 of the Expense Management System application that allows for arbitrary execution of JavaScript commands through index.php.
CVE-2021-40596 1 Oretnom23 1 Online Learning System 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter.
CVE-2021-40247 1 Oretnom23 1 Budget And Expense Tracker System 2026-06-17 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.