Vulnerabilities (CVE)

Filtered by vendor Oretnom23 Subscribe
Total 625 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-38965 1 Oretnom23 1 Lost And Found Information System 2023-11-13 N/A 9.8 CRITICAL
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
CVE-2023-46435 1 Oretnom23 1 Packers And Movers Management System 2023-10-30 N/A 9.8 CRITICAL
Sourcecodester Packers and Movers Management System v1.0 is vulnerable to SQL Injection via mpms/?p=services/view_service&id.
CVE-2021-45252 1 Oretnom23 1 Simple Forum\/discussion System 2023-10-18 7.5 HIGH 9.8 CRITICAL
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability.
CVE-2022-37796 1 Oretnom23 1 Simple Online Book Store System 2023-10-18 N/A 5.4 MEDIUM
In Simple Online Book Store System 1.0 in /admin_book.php the Title, Author, and Description parameters are vulnerable to Cross Site Scripting(XSS).
CVE-2021-44653 1 Oretnom23 1 Online Magazine Management System 2023-10-18 7.5 HIGH 9.8 CRITICAL
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application.