mayurik

275 tracked vulnerabilities.

CVE-2024-11860 MEDIUM
SourceCodester Best House Rental Management System 1.0 - Auth Bypass
Nov 27, 2024
CVSS 6.5
EPSS 0.00
CVE-2024-11743 MEDIUM
SourceCodester Best House Rental Management System 1.0 - CSRF
Nov 26, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-11742 LOW
SourceCodester Best House Rental Management System 1.0 - XSS
Nov 26, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-11214 MEDIUM
Best Employee Management System 1.0 - Unrestricted File Upload via Profile Image Parameter
Nov 14, 2024
CVSS 4.7
EPSS 0.00
CVE-2024-11213 MEDIUM
Best Employee Management System 1.0 - SQL Injection via /admin/edit_role.php id Parameter
Nov 14, 2024
CVSS 4.7
EPSS 0.00
CVE-2024-11212 MEDIUM
Best Employee Management System 1.0 - SQL Injection via Barcode Parameter
Nov 14, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-11102 LOW
Hospital Management System 1.0 - Stored Cross-Site Scripting via Edit Doctor Name Parameter
Nov 12, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-11073 MEDIUM
Hospital Management System 1.0 - Unauthenticated IDOR via Patient ID
Nov 11, 2024
CVSS 4.3
EPSS 0.00
CVE-2024-10450 MEDIUM
SourceCodester Kortex Lite Advocate Office Management System 1.0 - SQL Injection via POST Parameter Handler
Oct 28, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-10407 MEDIUM
SourceCodester Petrol Pump Management Software 1.0 - SQL Injection via edit_customer.php id Parameter
Oct 27, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-10406 MEDIUM
SourceCodester Petrol Pump Management Software 1.0 - SQL Injection via /admin/edit_fuel.php id Parameter
Oct 26, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-48581 CRITICAL
Best Courier Management System 1.0 - Remote Code Execution via Admin Class File Upload
Oct 25, 2024
CVSS 9.8
EPSS 0.03
CVE-2024-48580 CRITICAL
Best Courier Management System 1.0 - SQL Injection via Login Email Parameter
Oct 25, 2024
CVSS 9.8
EPSS 0.02
CVE-2024-48579 CRITICAL
Best House Rental Management System 1.0 - SQL Injection via Login Username Parameter
Oct 25, 2024
CVSS 9.8
EPSS 0.02
CVE-2024-10380 MEDIUM
SourceCodester Petrol Pump Management Software 1.0 - SQL Injection via drop_services Parameter
Oct 25, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-10355 MEDIUM
SourceCodester Petrol Pump Management Software 1.0 - SQL Injection via /admin/invoice.php id Parameter
Oct 25, 2024
CVSS 4.7
EPSS 0.01
CVE-2024-10354 MEDIUM
SourceCodester Petrol Pump Management Software 1.0 - SQL Injection via /admin/print.php id Parameter
Oct 25, 2024
CVSS 4.7
EPSS 0.00
CVE-2024-10349 MEDIUM
Best House Rental Management System 1.0 - SQL Injection via delete_tenant id Parameter
Oct 24, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-10348 LOW
Best House Rental Management System 1.0 - Cross-Site Scripting via Tenant Details Last Name Parameter
Oct 24, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-48411 CRITICAL
Online Tours and Travels Management System 1.0 - SQL Injection via Forget Password Email Parameter
Oct 15, 2024
CVSS 9.8
EPSS 0.00
CVE-2024-46077 MEDIUM
Online Tours and Travels Management System 1.0 - Stored Cross-Site Scripting via travellers.php Parameters
Oct 04, 2024
CVSS 5.4
EPSS 0.00
CVE-2024-9328 MEDIUM
Advocate Office Management System 1.0 - SQL Injection via edit_client.php id Parameter
Sep 29, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-9323 LOW
SourceCodester Inventory Management System 1.0 - Cross-Site Scripting in add_staff.php
Sep 29, 2024
CVSS 3.5
EPSS 0.00
CVE-2024-9318 MEDIUM
Advocate Office Management System 1.0 - SQL Injection via /control/activate.php id Parameter
Sep 28, 2024
CVSS 6.3
EPSS 0.00
CVE-2024-9296 HIGH
Advocate Office Management System 1.0 - SQL Injection via /control/forgot_pass.php Username Parameter
Sep 28, 2024
CVSS 7.3
EPSS 0.00