← Back

Oretnom23

oretnom23

761 CVEs • 112 products

Products (112)

Click to collapse
Toggle

CVEs (761)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oretnom23
1Student Grading System
Jun 17, 2026
Apr 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=school_year.
1Oretnom23
1Student Grading System
Jun 17, 2026
Apr 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via /student-grading-system/rms.php?page=grade.
1Oretnom23
1Student Grading System
Jun 17, 2026
Apr 5, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
1Oretnom23
1Banking System
Jul 9, 2026
Mar 30, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.
1Oretnom23
1Banking System
Jul 9, 2026
Mar 30, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.
1Oretnom23
1Banking System
Jul 9, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.
1Oretnom23
1Simple Subscription Website
Jun 17, 2026
Mar 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted...Show more
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint. This vulnerability allows attackers to dump the application's database via crafted HTTP requests.Show less
1Oretnom23
1Simple Cold Storage Management System
Jun 17, 2026
Jan 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Simple Cold Storage Management System using PHP/OOP 1.0 via the username field in login.php.
1Oretnom23
1Banking System
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username or password field.
1Oretnom23
1Online Learning System
Jun 17, 2026
Jan 24, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Login.php in sourcecodester Online Learning System v2 by oretnom23, allows attackers to execute arbitrary SQL commands via the faculty_id parameter.
1Oretnom23
1Budget And Expense Tracker System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username field.
1Oretnom23
1Employee And Visitor Gate Pass Logging System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.
1Oretnom23
1Simple Music Cloud Community System
Jun 17, 2026
Jan 21, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.
1Oretnom23
1Simple Online Men's Salon Management System
Jun 17, 2026
Dec 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through the password parameter. The predictive tests of this application interacted with t...Show more
The password parameter on Simple Online Mens Salon Management System (MSMS) 1.0 appears to be vulnerable to SQL injection attacks through the password parameter. The predictive tests of this application interacted with that domain, indicating that the injected SQL query was executed. The attacker can retrieve all authentication and information about the users of this system.Show less
1Oretnom23
1Simple Forum/discussion System
Jun 17, 2026
Dec 21, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all infor...Show more
Multiple SQL injection vulnerabilities are found on Simple Forum-Discussion System 1.0 For example on three applications which are manage_topic.php, manage_user.php, and ajax.php. The attacker can be retrieving all information from the database of this system by using this vulnerability.Show less
1Oretnom23
1Online Magazine Management System
Jun 17, 2026
Dec 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to...Show more
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel authentication can be bypassed due to SQL injection vulnerability in the login form allowing attacker to gain access as admin to the application.Show less
1Oretnom23
1Online Learning System
Jun 17, 2026
Nov 15, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerabli...Show more
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and authenticated file upload in (Master.php) file , we can craft these two vunlerablities to get unauthenticated remote command execution.Show less
1Oretnom23
1Simple Subscription Website
Jun 17, 2026
Nov 3, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Simple Subscription Website 1.0 via the id parameter in plan_application.
1Oretnom23
1Simple Subscription Website
Jun 17, 2026
Nov 3, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection vulnerability exists in Sourcecodester. Simple Subscription Website 1.0. via the login.
1Oretnom23
1Budget And Expense Tracker System
Jun 17, 2026
Oct 29, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Remote Code Execution (RCE) vulnerability exists in Sourcecodester Budget and Expense Tracker System 1.0 that allows a remote malicious user to inject arbitrary code via the image upload field. .