Search Results (342456 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-13242 2 Code-projects, Fabian 2 Hospital Information System, Student Information System 2025-11-19 7.3 High
A vulnerability has been found in code-projects Student Information System 2.0. This issue affects some unknown processing of the file /register.php. The manipulation leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-13243 2 Code-projects, Fabian 2 Student Information System, Student Information System 2025-11-19 6.3 Medium
A vulnerability was found in code-projects Student Information System 2.0. Impacted is an unknown function of the file /editprofile.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used.
CVE-2025-13244 2 Code-projects, Fabian 2 Student Information System, Student Information System 2025-11-19 4.3 Medium
A vulnerability was determined in code-projects Student Information System 2.0. The affected element is an unknown function of the file /register.php. This manipulation causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-13245 2 Code-projects, Fabian 2 Student Information System, Student Information System 2025-11-19 3.5 Low
A vulnerability was identified in code-projects Student Information System 2.0. The impacted element is an unknown function of the file /editprofile.php. Such manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
CVE-2025-13257 2 Itsourcecode, Janobe 2 Inventory Management System, Inventory Management System 2025-11-19 7.3 High
A security vulnerability has been detected in itsourcecode Inventory Management System 1.0. The affected element is an unknown function of the file /admin/user/index.php?view=edit. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
CVE-2025-13263 2 Oretnom23, Sourcecodester 2 Online Magazine Management System, Online Magazine Management System 2025-11-19 6.3 Medium
A vulnerability was identified in SourceCodester Online Magazine Management System 1.0. Affected by this issue is some unknown functionality of the file /categories.php. The manipulation of the argument c leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
CVE-2025-13264 2 Oretnom23, Sourcecodester 2 Online Magazine Management System, Online Magazine Management System 2025-11-19 6.3 Medium
A security flaw has been discovered in SourceCodester Online Magazine Management System 1.0. This affects an unknown part of the file /view_magazine.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be exploited.
CVE-2025-13277 2 Code-projects, Fabian 2 Social Networking Site, Nero Social Networking Site 2025-11-19 7.3 High
A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of the file /friendsphoto.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used.
CVE-2025-13279 2 Code-projects, Fabian 2 Social Networking Site, Nero Social Networking Site 2025-11-19 6.3 Medium
A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function of the file /profilefriends.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
CVE-2025-13285 2 Angeljudesuarez, Itsourcecode 2 Online Voting System, Online Voting System 2025-11-19 7.3 High
A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of the file /login.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.
CVE-2025-13286 2 Angeljudesuarez, Itsourcecode 2 Online Voting System, Online Voting System 2025-11-19 6.3 Medium
A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=save_user. Performing manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.
CVE-2025-13287 2 Angeljudesuarez, Itsourcecode 2 Online Voting System, Online Voting System 2025-11-19 6.3 Medium
A weakness has been identified in itsourcecode Online Voting System 1.0. This affects an unknown function of the file /index.php?page=categories. Executing manipulation of the argument id/category can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be exploited.
CVE-2025-64046 1 Openrapid 1 Rapidcms 2025-11-19 6.1 Medium
OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.
CVE-2024-44641 1 Phpgurukul 1 Small Crm 2025-11-19 6.5 Medium
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the oldpass parameter in change-password.php.
CVE-2024-44644 1 Phpgurukul 1 Small Crm 2025-11-19 6.5 Medium
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via the frm_id and aremark parameters in manage-tickets.php.
CVE-2024-44647 1 Phpgurukul 1 Small Crm 2025-11-19 6.1 Medium
PHPGurukul Small CRM 3.0 is vulnerable to Cross Site Scripting (XSS) via the aremark parameter in manage-tickets.php.
CVE-2024-44648 1 Phpgurukul 1 Small Crm 2025-11-19 6.5 Medium
PHPGurukul Small CRM 3.0 is vulnerable to SQL Injection via id and adminremark parameters in quote-details.php.
CVE-2024-44652 1 Kashipara 1 Ecommerce Website 2025-11-19 6.5 Medium
Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address parameters in user_register.php.
CVE-2024-46334 1 Kashipara 1 School Management System 2025-11-19 6.1 Medium
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.
CVE-2024-46336 1 Kashipara 1 School Management System 2025-11-19 6.1 Medium
kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.