Vulnerability index

Browse CVEs

215 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hospital Management System In Php CRITICAL 9.8
CVE-2023-5053

Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.

No fix yet
Fix from $2,300 2023-09-28
Online Book Store Project HIGH 8.8
CVE-2023-43740

Online Book Store Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'image' parameter of admin_edit.php page, allowing an au…

No fix yet
Fix from $1,950 2023-09-28
Gym Management System Project HIGH 8.8
CVE-2023-5185

Gym Management System Project v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'file' parameter of profile/i.php page, allowing a…

No fix yet
Fix from $1,950 2023-09-28
Online Movie Ticket Booking System MEDIUM 5.4
CVE-2023-44173

Online Movie Ticket Booking System v1.0 is vulnerable to an authenticated Reflected Cross-Site Scripting vulnerability.

No fix yet
Fix from $1,600 2023-09-28
Asset Management System Project In Php CRITICAL 9.8
CVE-2023-43144

Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.

No fix yet
Fix from $2,300 2023-09-22
Online Examination System MEDIUM 6.1
CVE-2022-42066

Online Examination System version 1.0 suffers from a cross site scripting vulnerability via index.php.

No fix yet
Fix from $1,600 2022-10-14
Hospital Management System In Php MEDIUM 5.3
CVE-2021-45852

An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious attackers can add patients without restriction via a…

No fix yet
Fix from $1,600 2022-03-16
Online Movie Ticket Booking System HIGH 7.5
CVE-2021-44866

An issue was discovered in Online-Movie-Ticket-Booking-System 1.0. The file about.php does not perform input validation on the 'id' paramter. An atta…

No fix yet
Fix from $1,950 2022-02-03
Online Shopping Webvsite In Php CRITICAL 9.8
CVE-2021-46024

Projectworlds online-shopping-webvsite-in-php 1.0 suffers from a SQL Injection vulnerability via the "id" parameter in cart_add.php, No login is requ…

No fix yet
Fix from $2,300 2022-01-23
Online Examination System CRITICAL 9.8
CVE-2021-46307

An SQL Injection vulnerability exists in Projectworlds Online Examination System 1.0 via the eid parameter in account.php.

No fix yet
Fix from $2,300 2022-01-21
Online Book Store Project In Php CRITICAL 9.8
CVE-2021-43155

Projectsworlds Online Book Store PHP v1.0 is vulnerable to SQL injection via the "bookisbn" parameter in cart.php.

No fix yet
Fix from $2,300 2021-12-22
Online Shopping System CRITICAL 9.8
CVE-2021-43157

Projectsworlds Online Shopping System PHP 1.0 is vulnerable to SQL injection via the id parameter in cart_remove.php.

No fix yet
Fix from $2,300 2021-12-22
Hospital Management System In Php CRITICAL 9.8
CVE-2021-43628

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the email parameter in hms-staff.php.

No fix yet
Fix from $2,300 2021-12-22
Hospital Management System In Php CRITICAL 9.8
CVE-2021-43629

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in admin_home.php.

No fix yet
Fix from $2,300 2021-12-22
Hospital Management System In Php CRITICAL 9.8
CVE-2021-43631

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via the appointment_no parameter in payment.php.

No fix yet
Fix from $2,300 2021-12-22
Hospital Management System In Php HIGH 8.8
CVE-2021-43630

Projectworlds Hospital Management System v1.0 is vulnerable to SQL injection via multiple parameters in add_patient.php. As a result, an authenticate…

No fix yet
Fix from $1,950 2021-12-22
Online Book Store Project In Php MEDIUM 6.5
CVE-2021-43156

In ProjectWorlds Online Book Store PHP 1.0 a CSRF vulnerability in admin_delete.php allows a remote attacker to delete any book.

No fix yet
Fix from $1,600 2021-12-22
Travel Management System MEDIUM 6.1
CVE-2020-29205

XSS in signup form in Project Worlds Online Examination System 1.0 allows remote attacker to inject arbitrary code via the name field

No fix yet
Fix from $1,600 2021-05-17
Online Book Store Project In Php CRITICAL 9.8
CVE-2020-19108

SQL Injection vulnerability in Online Book Store v1.0 via the pubid parameter to bookPerPub.php, which could let a remote malicious user execute arbi…

No fix yet
Fix from $2,300 2021-05-06
Online Book Store Project In Php CRITICAL 9.8
CVE-2020-19109

SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_edit.php, which could let a remote malicious user execute a…

No fix yet
Fix from $2,300 2021-05-06
Online Book Store Project In Php CRITICAL 9.8
CVE-2020-19110

SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to book.php parameter, which could let a remote malicious user execu…

Mitigation only
Fix from $2,300 2021-05-06
Online Book Store Project In Php CRITICAL 9.8
CVE-2020-19111

Incorrect Access Control vulnerability in Online Book Store v1.0 via admin_verify.php, which could let a remote mailicious user bypass authentication…

No fix yet
Fix from $2,300 2021-05-06
Online Book Store Project In Php CRITICAL 9.8
CVE-2020-19112

SQL Injection vulnerability in Online Book Store v1.0 via the bookisbn parameter to admin_delete.php, which could let a remote malicious user execute…

No fix yet
Fix from $2,300 2021-05-06
Online Book Store Project In Php CRITICAL 9.8
CVE-2020-19113

Arbitrary File Upload vulnerability in Online Book Store v1.0 in admin_add.php, which may lead to remote code execution.

No fix yet
Fix from $2,300 2021-05-06
Online Book Store Project In Php CRITICAL 9.8
CVE-2020-19114

SQL Injection vulnerability in Online Book Store v1.0 via the publisher parameter to edit_book.php, which could let a remote malicious user execute a…

No fix yet
Fix from $2,300 2021-05-06
Online Book Store Project In Php CRITICAL 9.8
CVE-2020-19107

SQL Injection vulnerability in Online Book Store v1.0 via the isbn parameter to edit_book.php, which could let a remote malicious user execute arbitr…

No fix yet
Fix from $2,300 2021-05-06
Online Matrimonial Project HIGH 8.8
CVE-2020-27397

Marital - Online Matrimonial Project In PHP version 1.0 suffers from an authenticated file upload vulnerability allowing remote attackers to gain rem…

No fix yet
Fix from $1,950 2020-12-23
Visitor Management System HIGH 8.8
CVE-2020-25760

Projectworlds Visitor Management System in PHP 1.0 allows SQL Injection. The file front.php does not perform input validation on the 'rid' parameter.…

No fix yet
Fix from $1,950 2020-09-30
Visitor Management System MEDIUM 6.1
CVE-2020-25761

Projectworlds Visitor Management System in PHP 1.0 allows XSS. The file myform.php does not perform input validation on the request parameters. An at…

No fix yet
Fix from $1,600 2020-09-30
House Rental CRITICAL 9.8
CVE-2020-23833

Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on t…

No fix yet
Fix from $2,300 2020-09-15