mayurik records
283 published records for vendor mayurik.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 15
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')102
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')84
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')45
- CWE-284 Improper Access Control11
- CWE-266 Incorrect Privilege Assignment7
- CWE-434 Unrestricted Upload of File with Dangerous Type7
The weakness classes this vendor ships most often: where to look.
CWEAll records
283 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2024-27747Proof of concept | File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the mayurik · petrol pump management · CWE-434 | Critical9.8 | — | 23.6% | Mar 1, 2024 |
43Plan | CVE-2024-27746Proof of concept | SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to thmayurik · petrol pump management · CWE-89 | Critical9.8 | — | 12.9% | Mar 1, 2024 |
39Monitor | CVE-2023-46980Proof of concept | An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted scmayurik · best courier management system · CWE-94 | Critical9.8 | — | 1.5% | Nov 3, 2023 |
39Monitor | CVE-2024-28556No exploit | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate pmayurik · php task management system · CWE-89 | Critical9.8 | — | 1.2% | Apr 15, 2024 |
39Monitor | CVE-2024-28557No exploit | SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate pmayurik · php task management system · CWE-89 | Critical9.8 | — | 1.2% | Apr 15, 2024 |
39Monitor | CVE-2024-46377Proof of concept | Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/amayurik · best house rental management system · CWE-434 | Critical9.8 | — | 1.2% | Sep 18, 2024 |
39Monitor | CVE-2023-4181No exploit | SourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflowmayurik · free hospital management system for small practices · CWE-841 | Critical9.8 | — | 1.1% | Aug 6, 2023 |
39Monitor | CVE-2023-48823No exploit | A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload vmayurik · courier management system · CWE-89 | Critical9.8 | — | 1.1% | Dec 7, 2023 |
39Monitor | CVE-2024-48581No exploit | File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_clmayurik · best courier management system · CWE-94 | Critical9.8 | — | 1.1% | Oct 25, 2024 |
39Monitor | CVE-2024-46375No exploit | Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_clmayurik · best house rental management system · CWE-22 | Critical9.8 | — | 1.1% | Sep 18, 2024 |
39Monitor | CVE-2024-46376No exploit | Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/mayurik · best house rental management system · CWE-22 | Critical9.8 | — | 1.1% | Sep 18, 2024 |
39Monitor | CVE-2023-4749No exploit | SourceCodester Inventory Management System index.php file inclusionmayurik · inventory management system · CWE-73 | Critical9.8 | — | 1.0% | Sep 3, 2023 |
39Monitor | CVE-2023-4180No exploit | SourceCodester Free Hospital Management System for Small Practices login.php sql injectionmayurik · free hospital management system for small practices · CWE-89 | Critical9.8 | — | 0.9% | Aug 6, 2023 |
39Monitor | CVE-2024-29303No exploit | The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injectionmayurik · php task management system · CWE-89 | Critical9.8 | — | 0.9% | Mar 25, 2024 |
39Monitor | CVE-2024-48579No exploit | SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code vmayurik · best house rental management system · CWE-94 | Critical9.8 | — | 0.9% | Oct 25, 2024 |
39Monitor | CVE-2024-48580No exploit | SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email mayurik · best courier management system · CWE-89 | Critical9.8 | — | 0.9% | Oct 25, 2024 |
39Monitor | CVE-2023-4179No exploit | SourceCodester Free Hospital Management System for Small Practices sql injectionmayurik · free hospital management system for small practices · CWE-89 | Critical9.8 | — | 0.8% | Aug 6, 2023 |
39Monitor | CVE-2023-3617No exploit | SourceCodester Best POS Management System Login Page admin_class.php sql injectionmayurik · best pos management system · CWE-89 | Critical9.8 | — | 0.8% | Jul 11, 2023 |
39Monitor | CVE-2023-1962No exploit | SourceCodester Best Online News Portal POST Parameter forgot-password.php sql injectionmayurik · best online news portal · CWE-89 | Critical9.8 | — | 0.8% | Apr 9, 2023 |
39Monitor | CVE-2023-0784No exploit | SourceCodester Best Online News Portal Login Page sql injectionmayurik · best online news portal · CWE-89 | Critical9.8 | — | 0.8% | Feb 12, 2023 |
39Monitor | CVE-2023-6305No exploit | SourceCodester Free and Open Source Inventory Management System suppliar_data.php sql injectionmayurik · free and open source inventory management system · CWE-89 | Critical9.8 | — | 0.8% | Nov 26, 2023 |
39Monitor | CVE-2023-6306No exploit | SourceCodester Free and Open Source Inventory Management System member_data.php sql injectionmayurik · free and open source inventory management system · CWE-89 | Critical9.8 | — | 0.8% | Nov 26, 2023 |
39Monitor | CVE-2023-27202No exploit | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.mayurik · best pos management system · CWE-89 | Critical9.8 | — | 0.8% | Mar 9, 2023 |
39Monitor | CVE-2023-27205No exploit | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.mayurik · best pos management system · CWE-89 | Critical9.8 | — | 0.8% | Mar 9, 2023 |
39Monitor | CVE-2023-27204No exploit | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.mayurik · best pos management system · CWE-89 | Critical9.8 | — | 0.8% | Mar 9, 2023 |
- CVE-2024-2774746Plan
File Upload vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the
CriticalCVSS 9.8Proof of conceptEPSS 24%mayurik · petrol pump managementMar 1, 2024
- CVE-2024-2774643Plan
SQL Injection vulnerability in Petrol Pump Mangement Software v.1.0 allows an attacker to execute arbitrary code via a crafted payload to th
CriticalCVSS 9.8Proof of conceptEPSS 13%mayurik · petrol pump managementMar 1, 2024
- CVE-2023-4698039Monitor
An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted sc
CriticalCVSS 9.8Proof of conceptEPSS 2%mayurik · best courier management systemNov 3, 2023
- CVE-2024-2855639Monitor
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate p
CriticalCVSS 9.8No exploitEPSS 1%mayurik · php task management systemApr 15, 2024
- CVE-2024-2855739Monitor
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate p
CriticalCVSS 9.8No exploitEPSS 1%mayurik · php task management systemApr 15, 2024
- CVE-2024-4637739Monitor
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the save_settings() function of the file rental/a
CriticalCVSS 9.8Proof of conceptEPSS 1%mayurik · best house rental management systemSep 18, 2024
- CVE-2023-418139Monitor
SourceCodester Free Hospital Management System for Small Practices Redirect behavioral workflow
CriticalCVSS 9.8No exploitEPSS 1%mayurik · free hospital management system for small practicesAug 6, 2023
- CVE-2023-4882339Monitor
A Blind SQL injection issue in ajax.php in GaatiTrack Courier Management System 1.0 allows an unauthenticated attacker to inject a payload v
CriticalCVSS 9.8No exploitEPSS 1%mayurik · courier management systemDec 7, 2023
- CVE-2024-4858139Monitor
File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_cl
CriticalCVSS 9.8No exploitEPSS 1%mayurik · best courier management systemOct 25, 2024
- CVE-2024-4637539Monitor
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the signup() function of the file rental/admin_cl
CriticalCVSS 9.8No exploitEPSS 1%mayurik · best house rental management systemSep 18, 2024
- CVE-2024-4637639Monitor
Best House Rental Management System 1.0 contains an arbitrary file upload vulnerability in the update_account() function of the file rental/
CriticalCVSS 9.8No exploitEPSS 1%mayurik · best house rental management systemSep 18, 2024
- CVE-2023-474939Monitor
SourceCodester Inventory Management System index.php file inclusion
CriticalCVSS 9.8No exploitEPSS 1%mayurik · inventory management systemSep 3, 2023
- CVE-2023-418039Monitor
SourceCodester Free Hospital Management System for Small Practices login.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%mayurik · free hospital management system for small practicesAug 6, 2023
- CVE-2024-2930339Monitor
The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection
CriticalCVSS 9.8No exploitEPSS 1%mayurik · php task management systemMar 25, 2024
- CVE-2024-4857939Monitor
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code v
CriticalCVSS 9.8No exploitEPSS 1%mayurik · best house rental management systemOct 25, 2024
- CVE-2024-4858039Monitor
SQL Injection vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the email
CriticalCVSS 9.8No exploitEPSS 1%mayurik · best courier management systemOct 25, 2024
- CVE-2023-417939Monitor
SourceCodester Free Hospital Management System for Small Practices sql injection
CriticalCVSS 9.8No exploitEPSS 1%mayurik · free hospital management system for small practicesAug 6, 2023
- CVE-2023-361739Monitor
SourceCodester Best POS Management System Login Page admin_class.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%mayurik · best pos management systemJul 11, 2023
- CVE-2023-196239Monitor
SourceCodester Best Online News Portal POST Parameter forgot-password.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%mayurik · best online news portalApr 9, 2023
- CVE-2023-078439Monitor
SourceCodester Best Online News Portal Login Page sql injection
CriticalCVSS 9.8No exploitEPSS 1%mayurik · best online news portalFeb 12, 2023
- CVE-2023-630539Monitor
SourceCodester Free and Open Source Inventory Management System suppliar_data.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%mayurik · free and open source inventory management systemNov 26, 2023
- CVE-2023-630639Monitor
SourceCodester Free and Open Source Inventory Management System member_data.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%mayurik · free and open source inventory management systemNov 26, 2023
- CVE-2023-2720239Monitor
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.
CriticalCVSS 9.8No exploitEPSS 1%mayurik · best pos management systemMar 9, 2023
- CVE-2023-2720539Monitor
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.
CriticalCVSS 9.8No exploitEPSS 1%mayurik · best pos management systemMar 9, 2023
- CVE-2023-2720439Monitor
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
CriticalCVSS 9.8No exploitEPSS 1%mayurik · best pos management systemMar 9, 2023