Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Society Management System Portal MEDIUM 6.1
CVE-2026-26464

Stored Cross-Site Scripting (XSS) was found in the /admin/edit_user.php page of Society Management System Portal V1.0, which allows remote attackers …

No fix yet
Fix from $1,600 2026-02-23
Ecommerce Website MEDIUM 6.5
CVE-2024-44651

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the recover_email parameter in user_password_recover.php.

No fix yet
Fix from $1,600 2025-11-17
Ecommerce Website MEDIUM 6.5
CVE-2024-44653

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email parameter in user_login.php.

No fix yet
Fix from $1,600 2025-11-17
Ecommerce Website MEDIUM 6.5
CVE-2024-44652

Kashipara Ecommerce Website 1.0 is vulnerable to SQL Injection via the user_email, username, user_firstname, user_lastname, and user_address paramete…

No fix yet
Fix from $1,600 2025-11-17
School Management System MEDIUM 6.1
CVE-2024-46334

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via the formuser and formpassword parameters in /adminLogin.php.

No fix yet
Fix from $1,600 2025-11-17
School Management System MEDIUM 6.1
CVE-2024-46336

kashipara School Management System 1.0 is vulnerable to Cross Site Scripting (XSS) via /client_user/feedback.php.

No fix yet
Fix from $1,600 2025-11-17
Online Attendance Management System MEDIUM 5.6
CVE-2025-26158

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the manage-employee.php page of Kashipara Online Attendance Management System V1.…

No fix yet
Fix from $1,600 2025-02-14
Billing Software CRITICAL 9.8
CVE-2024-0496

A vulnerability was found in Kashipara Billing Software 1.0 and classified as critical. This issue affects some unknown processing of the file item_l…

Mitigation only
Fix from $2,300 2024-01-13
Billing Software CRITICAL 9.8
CVE-2024-0495

A vulnerability has been found in Kashipara Billing Software 1.0 and classified as critical. This vulnerability affects unknown code of the file part…

Mitigation only
Fix from $2,300 2024-01-13
Billing Software CRITICAL 9.8
CVE-2024-0493

A vulnerability, which was classified as critical, has been found in Kashipara Billing Software 1.0. Affected by this issue is some unknown functiona…

Mitigation only
Fix from $2,300 2024-01-13
Billing Software CRITICAL 9.8
CVE-2024-0494

A vulnerability, which was classified as critical, was found in Kashipara Billing Software 1.0. This affects an unknown part of the file material_bil…

Mitigation only
Fix from $2,300 2024-01-13
Billing Software CRITICAL 9.8
CVE-2024-0492

A vulnerability classified as critical was found in Kashipara Billing Software 1.0. Affected by this vulnerability is an unknown functionality of the…

Mitigation only
Fix from $2,300 2024-01-13
Food Management System CRITICAL 9.8
CVE-2024-0290

A vulnerability, which was classified as critical, has been found in Kashipara Food Management System 1.0. This issue affects some unknown processing…

No fix yet
Fix from $2,300 2024-01-08
Food Management System CRITICAL 9.8
CVE-2024-0289

A vulnerability classified as critical was found in Kashipara Food Management System 1.0. This vulnerability affects unknown code of the file stock_e…

No fix yet
Fix from $2,300 2024-01-08
Food Management System CRITICAL 9.8
CVE-2024-0288

A vulnerability classified as critical has been found in Kashipara Food Management System 1.0. This affects an unknown part of the file rawstock_used…

No fix yet
Fix from $2,300 2024-01-08
Food Management System CRITICAL 9.8
CVE-2024-0287

A vulnerability was found in Kashipara Food Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionalit…

No fix yet
Fix from $2,300 2024-01-07
Travel Website CRITICAL 9.8
CVE-2023-50864

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelId' parameter of the hotelDetails.php resource…

No fix yet
Fix from $2,300 2024-01-04
Travel Website CRITICAL 9.8
CVE-2023-50865

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'city' parameter of the hotelSearch.php resource doe…

No fix yet
Fix from $2,300 2024-01-04
Travel Website CRITICAL 9.8
CVE-2023-50866

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource…

No fix yet
Fix from $2,300 2024-01-04
Travel Website CRITICAL 9.8
CVE-2023-50867

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the signupAction.php resourc…

No fix yet
Fix from $2,300 2024-01-04
Travel Website CRITICAL 9.8
CVE-2023-50862

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the booking.php resourc…

No fix yet
Fix from $2,300 2024-01-04
Travel Website CRITICAL 9.8
CVE-2023-50863

Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'hotelIDHidden' parameter of the generateReceipt.php…

No fix yet
Fix from $2,300 2024-01-04
Online Notice Board System HIGH 8.8
CVE-2023-50760

Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allo…

No fix yet
Fix from $1,950 2024-01-04
Billing Software CRITICAL 9.8
CVE-2023-49666

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'custmer_details' parameter of the submit_material…

No fix yet
Fix from $2,300 2024-01-04
Online Notice Board System CRITICAL 9.8
CVE-2023-50743

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the registration.php r…

No fix yet
Fix from $2,300 2024-01-04
Online Notice Board System CRITICAL 9.8
CVE-2023-50752

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'e' parameter of the login.php resource …

No fix yet
Fix from $2,300 2024-01-04
Online Notice Board System CRITICAL 9.8
CVE-2023-50753

Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the user/update_profil…

No fix yet
Fix from $2,300 2024-01-04
Billing Software CRITICAL 9.8
CVE-2023-49625

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'id' parameter of the partylist_edit_submit.php re…

No fix yet
Fix from $2,300 2024-01-04
Billing Software CRITICAL 9.8
CVE-2023-49633

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'buyer_address' parameter of the buyer_detail_subm…

No fix yet
Fix from $2,300 2024-01-04
Billing Software CRITICAL 9.8
CVE-2023-49639

Billing Software v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'customer_details' parameter of the buyer_invoice_…

No fix yet
Fix from $2,300 2024-01-04