Vulnerabilities (CVE)

Filtered by vendor Janobe Subscribe
Total 169 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28422 1 Janobe 1 Baby Care System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin/posts.php&action=edit.
CVE-2022-28421 1 Janobe 1 Baby Care System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via /admin.php?id=posts&action=display&value=1&postid=.
CVE-2022-28420 1 Janobe 1 Baby Care System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Baby Care System v1.0 was discovered to contain a SQL injection vulnerability via BabyCare/admin.php?id=theme&setid=.
CVE-2021-41646 1 Janobe 1 Online Reviewer System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Online Reviewer System 1.0 by uploading a maliciously crafted PHP file that bypasses the image upload filters..
CVE-2021-27130 1 Janobe 1 Online Reviewer System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Online Reviewer System 1.0 contains a SQL injection vulnerability through authentication bypass, which may lead to a reverse shell upload.
CVE-2021-25780 1 Janobe 1 Baby Care System 2026-06-17 6.5 MEDIUM 7.2 HIGH
An arbitrary file upload vulnerability has been identified in posts.php in Baby Care System 1.0. The vulnerability could be exploited by an remote attacker to upload content to the server, including PHP files, which could result in command execution and obtaining a shell.
CVE-2021-25779 1 Janobe 1 Baby Care System 2026-06-17 7.5 HIGH 9.8 CRITICAL
Baby Care System v1.0 is vulnerable to SQL injection via the 'id' parameter on the contentsectionpage.php page.
CVE-2020-35752 1 Janobe 1 Baby Care System 2026-06-17 3.5 LOW 5.4 MEDIUM
Baby Care System 1.0 is affected by a cross-site scripting (XSS) vulnerability in the Edit Page tab through the Post title parameter.
CVE-2020-29239 1 Janobe 1 Online Voting System 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Online Birth Certificate System Project V 1.0 is affected by cross-site scripting (XSS). This vulnerability can result in an attacker injecting the XSS payload in the User Registration section. When an admin visits the View Detail of Application section from the admin panel, the attacker can able to steal the cookie according to the crafted payload.