Vulnerabilities (CVE)

Filtered by vendor Phpgurukul Subscribe
Total 903 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-37690 1 Phpgurukul 1 Maid Hiring Management System 2023-11-14 N/A 4.8 MEDIUM
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Search Maid page.
CVE-2023-37688 1 Phpgurukul 1 Maid Hiring Management System 2023-11-14 N/A 4.8 MEDIUM
Maid Hiring Management System v1.0 was discovered to contain a SQL injection vulnerability in the Admin page.
CVE-2023-37745 1 Phpgurukul 1 Maid Hiring Management System 2023-11-14 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Description of the /admin/aboutus.php component.
CVE-2023-37686 1 Phpgurukul 1 Online Nurse Hiring System 2023-11-14 N/A 4.8 MEDIUM
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Add Nurse Page in the Admin portal.
CVE-2023-37684 1 Phpgurukul 1 Online Nurse Hiring System 2023-11-14 N/A 4.8 MEDIUM
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Details of the Admin portal.
CVE-2023-37685 1 Phpgurukul 1 Online Nurse Hiring System 2023-11-14 N/A 4.8 MEDIUM
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Search Report Page of the Admin portal.
CVE-2023-37683 1 Phpgurukul 1 Online Nurse Hiring System 2023-11-14 N/A 4.8 MEDIUM
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the Profile Page of the Admin.
CVE-2023-37687 1 Phpgurukul 1 Online Nurse Hiring System 2023-11-14 N/A 7.2 HIGH
Online Nurse Hiring System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the View Request of Nurse Page in the Admin portal.
CVE-2021-26762 1 Phpgurukul 1 Student Record System 2023-11-14 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the cid parameter to edit-course.php.
CVE-2021-26765 1 Phpgurukul 1 Student Record System 2023-11-14 7.5 HIGH 9.8 CRITICAL
SQL injection vulnerability in PHPGurukul Student Record System 4.0 allows remote attackers to execute arbitrary SQL statements, via the sid parameter to edit-sub.php.
CVE-2021-26764 1 Phpgurukul 1 Student Record System 2023-11-14 6.5 MEDIUM 8.8 HIGH
SQL injection vulnerability in PHPGurukul Student Record System v 4.0 allows remote attackers to execute arbitrary SQL statements, via the id parameter to edit-std.php.
CVE-2021-42224 1 Phpgurukul 1 Ifsc Code Finder 2023-11-14 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability exists in IFSC Code Finder Project 1.0 via the searchifsccode POST parameter in /search.php.
CVE-2020-35151 1 Phpgurukul 1 Online Marriage Registration System 2023-11-14 6.5 MEDIUM 8.8 HIGH
The Online Marriage Registration System 1.0 post parameter "searchdata" in the user/search.php request is vulnerable to Time Based Sql Injection.
CVE-2020-26052 1 Phpgurukul 1 Online Marriage Registration System 2023-11-14 3.5 LOW 5.4 MEDIUM
Online Marriage Registration System 1.0 is affected by stored cross-site scripting (XSS) vulnerabilities in multiple parameters.
CVE-2020-23466 1 Phpgurukul 1 Online Marriage Registration System 2023-11-14 N/A 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in the phpgurukul Online Marriage Registration System 1.0 allows attackers to run arbitrary code via the wzipcode field.
CVE-2021-28424 1 Phpgurukul 1 Teachers Record Management System 2023-11-14 3.5 LOW 5.4 MEDIUM
A stored cross-site scripting (XSS) vulnerability in Teachers Record Management System 1.0 allows remote authenticated users to inject arbitrary web script or HTML via the 'email' POST parameter in adminprofile.php.
CVE-2021-26822 1 Phpgurukul 1 Teachers Record Management System 2023-11-14 7.5 HIGH 9.8 CRITICAL
Teachers Record Management System 1.0 is affected by a SQL injection vulnerability in 'searchteacher' POST parameter in search-teacher.php. This vulnerability can be exploited by a remote unauthenticated attacker to leak sensitive information and perform code execution attacks.
CVE-2021-44315 1 Phpgurukul 1 Bus Pass Management System 2023-11-14 5.0 MEDIUM 7.5 HIGH
In Bus Pass Management System v1.0, Directory Listing/Browsing is enabled on the web server which allows an attacker to view the sensitive files of the application, for example: Any file which contains sensitive information of the user or server.
CVE-2022-36198 1 Phpgurukul 1 Bus Pass Management System 2023-11-14 N/A 9.8 CRITICAL
Multiple SQL injections detected in Bus Pass Management System 1.0 via buspassms/admin/view-enquiry.php, buspassms/admin/pass-bwdates-reports-details.php, buspassms/admin/changeimage.php, buspassms/admin/search-pass.php, buspassms/admin/edit-category-detail.php, and buspassms/admin/edit-pass-detail.php
CVE-2022-29008 1 Phpgurukul 1 Bus Pass Management System 2023-11-14 4.0 MEDIUM 6.5 MEDIUM
An insecure direct object reference (IDOR) vulnerability in the viewid parameter of Bus Pass Management System v1.0 allows attackers to access sensitive information.