Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

School Erp Pro HIGH 7.2
CVE-2020-37084

School ERP Pro 1.0 contains a remote code execution vulnerability that allows authenticated admin users to upload arbitrary PHP files as profile phot…

No fix yet
Fix from $1,950 2026-02-03
School Erp Pro CRITICAL 9.8
CVE-2020-37090

School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upl…

Mitigation only
Fix from $2,300 2026-02-03
School Erp Pro CRITICAL 9.8
CVE-2020-37089

School ERP Pro 1.0 contains a SQL injection vulnerability in the 'es_messagesid' parameter that allows attackers to manipulate database queries throu…

Mitigation only
Fix from $2,300 2026-02-03
School Erp Pro HIGH 7.5
CVE-2020-37088

School ERP Pro 1.0 contains a file disclosure vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the 'docume…

No fix yet
Fix from $1,950 2026-02-03
School Erp Pro\+responsive CRITICAL 9.8
CVE-2024-4824

Vulnerability in School ERP Pro+Responsive 1.0 that allows SQL injection through the '/SchoolERP/office_admin/' index in the parameters groups_id, ex…

Mitigation only
Fix from $2,300 2024-05-14
School Erp Pro\+responsive MEDIUM 6.1
CVE-2024-4823

Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the index '/schoolerp/office_admin/' in the parameters es_bankacc, es_bank_name, e…

Mitigation only
Fix from $1,600 2024-05-14
School Erp Pro\+responsive MEDIUM 6.1
CVE-2024-4822

Vulnerability in School ERP Pro+Responsive 1.0 that allows XSS via the username and password parameters in '/index.php'. This vulnerability allows an…

Mitigation only
Fix from $1,600 2024-05-14
School Erp Pro HIGH 8.8
CVE-2022-32119

Arox School ERP Pro v1.0 was discovered to contain multiple arbitrary file upload vulnerabilities via the Add Photo function at photogalleries.inc.ph…

Mitigation only
Fix from $1,950 2022-07-15
School Erp Pro MEDIUM 6.1
CVE-2022-32118

Arox School ERP Pro v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the dispatchcategory parameter in backoffice.inc.ph…

No fix yet
Fix from $1,600 2022-07-15
School Management Software Php\/mysql MEDIUM 6.5
CVE-2020-8504

School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=addadmin CSRF to add an administrative user.

Fix: after 2019-03-14
Fix from $1,600 2020-01-31
School Management Software Php\/mysql MEDIUM 6.5
CVE-2020-8505

School Management Software PHP/mySQL through 2019-03-14 allows office_admin/?action=deleteadmin CSRF to delete a user.

Fix: after 2019-03-14
Fix from $1,600 2020-01-31
School Erp CRITICAL 9.8
CVE-2019-13294EPSS 19%

AROX School-ERP Pro has a command execution vulnerability. import_stud.php and upload_fille.php do not have session control. Therefore an unauthentic…

No fix yet
Fix from $2,300 2019-07-04
School Erp Php Script CRITICAL 9.8
CVE-2017-15978

AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.

No fix yet
Fix from $2,300 2017-10-31