carmelo records
127 published records for vendor carmelo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')91
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')17
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-284 Improper Access Control5
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-425 Direct Request ('Forced Browsing')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
127 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2025-25914No exploit | SQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parametercarmelo · online exam mastering system · CWE-89 | Critical9.8 | — | 0.8% | Mar 17, 2025 |
39Monitor | CVE-2025-69559No exploit | code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.carmelo · computer book store · CWE-434 | Critical9.8 | — | 0.6% | Jan 27, 2026 |
39Monitor | CVE-2024-25250No exploit | SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.carmelo · agro-school management system · CWE-89 | Critical9.8 | — | 0.6% | Mar 13, 2024 |
39Monitor | CVE-2026-26711No exploit | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.carmelo · simple food order system · CWE-89 | Critical9.8 | — | 0.5% | Mar 2, 2026 |
39Monitor | CVE-2026-26694No exploit | code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.carmelo · simple student alumni system · CWE-89 | Critical9.8 | — | 0.5% | Mar 2, 2026 |
39Monitor | CVE-2026-26695No exploit | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.carmelo · simple student alumni system · CWE-89 | Critical9.8 | — | 0.5% | Mar 2, 2026 |
39Monitor | CVE-2026-26713No exploit | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.carmelo · simple food order system · CWE-89 | Critical9.8 | — | 0.5% | Mar 2, 2026 |
39Monitor | CVE-2026-26709No exploit | code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.carmelo · simple gym management system · CWE-89 | Critical9.8 | — | 0.5% | Mar 2, 2026 |
39Monitor | CVE-2026-26696No exploit | code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.carmelo · simple student alumni system · CWE-89 | Critical9.8 | — | 0.5% | Mar 2, 2026 |
39Monitor | CVE-2026-26712No exploit | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.carmelo · simple food order system · CWE-89 | Critical9.8 | — | 0.5% | Mar 2, 2026 |
39Monitor | CVE-2026-26710No exploit | code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.carmelo · simple food order system · CWE-89 | Critical9.8 | — | 0.5% | Mar 2, 2026 |
39Monitor | CVE-2025-60307No exploit | code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field oncarmelo · computer laboratory system · CWE-89 | Critical9.8 | — | 0.4% | Oct 10, 2025 |
35Monitor | CVE-2024-25251No exploit | code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.carmelo · agro-school management system · CWE-284 | High8.8 | — | 0.7% | Feb 21, 2024 |
33Monitor | CVE-2024-24100No exploit | Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.carmelo · computer book store · CWE-89 | High8.3 | — | 0.6% | Feb 26, 2024 |
31Monitor | CVE-2024-24096No exploit | Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.carmelo · computer book store · CWE-89 | High7.8 | — | 0.4% | Feb 26, 2024 |
31Monitor | CVE-2024-24105No exploit | SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvalicarmelo · computer science time table system · CWE-89 | High7.8 | — | 0.3% | Mar 13, 2024 |
29Monitor | CVE-2024-28279No exploit | Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.carmelo · computer book store · CWE-89 | High7.3 | — | 0.3% | May 14, 2024 |
29Monitor | CVE-2025-56295No exploit | code-projects Computer Laboratory System 1.0 has a file upload vulnerability.carmelo · computer laboratory system · CWE-434 | High7.3 | — | 0.3% | Sep 16, 2025 |
27Monitor | CVE-2025-6363No exploit | code-projects Simple Pizza Ordering System adding-exec.php sql injectioncarmelo · simple pizza ordering system · CWE-74 | Medium6.9 | — | 0.5% | Jun 20, 2025 |
27Monitor | CVE-2025-6361No exploit | code-projects Simple Pizza Ordering System adds.php sql injectioncarmelo · simple pizza ordering system · CWE-74 | Medium6.9 | — | 0.5% | Jun 20, 2025 |
27Monitor | CVE-2025-6362No exploit | code-projects Simple Pizza Ordering System editpro.php sql injectioncarmelo · simple pizza ordering system · CWE-74 | Medium6.9 | — | 0.5% | Jun 20, 2025 |
27Monitor | CVE-2025-6364No exploit | code-projects Simple Pizza Ordering System adduser-exec.php sql injectioncarmelo · simple pizza ordering system · CWE-74 | Medium6.9 | — | 0.5% | Jun 20, 2025 |
27Monitor | CVE-2026-2158No exploit | code-projects Student Web Portal check_user.php sql injectioncarmelo · student web portal · CWE-74 | Medium6.9 | — | 0.4% | Feb 8, 2026 |
22Monitor | CVE-2026-4532No exploit | code-projects Simple Food Ordering System Database Backup food.sql file accesscarmelo · simple food order system · CWE-425 | Medium5.5 | — | 0.7% | Mar 21, 2026 |
22Monitor | CVE-2026-3744No exploit | code-projects Student Web Portal signup.php valreg_passwdation sql injectioncarmelo · student web portal · CWE-74 | Medium5.5 | — | 0.6% | Mar 8, 2026 |
- CVE-2025-2591439Monitor
SQL injection vulnerability in Online Exam Mastering System v.1.0 allows a remote attacker to execute arbitrary code via the fid parameter
CriticalCVSS 9.8No exploitEPSS 1%carmelo · online exam mastering systemMar 17, 2025
- CVE-2025-6955939Monitor
code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.
CriticalCVSS 9.8No exploitEPSS 1%carmelo · computer book storeJan 27, 2026
- CVE-2024-2525039Monitor
SQL Injection vulnerability in code-projects Agro-School Management System 1.0 allows attackers to run arbitrary code via the Login page.
CriticalCVSS 9.8No exploitEPSS 1%carmelo · agro-school management systemMar 13, 2024
- CVE-2026-2671139Monitor
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.
CriticalCVSS 9.8No exploitEPSS 1%carmelo · simple food order systemMar 2, 2026
- CVE-2026-2669439Monitor
code-projects Simple Student Alumni System v1.0 is vulnerale to SQL Injection in /TracerStudy/modal_view.php.
CriticalCVSS 9.8No exploitEPSS 1%carmelo · simple student alumni systemMar 2, 2026
- CVE-2026-2669539Monitor
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordstudent_edit.php.
CriticalCVSS 9.8No exploitEPSS 1%carmelo · simple student alumni systemMar 2, 2026
- CVE-2026-2671339Monitor
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/cancel-order.php.
CriticalCVSS 9.8No exploitEPSS 1%carmelo · simple food order systemMar 2, 2026
- CVE-2026-2670939Monitor
code-projects Simple Gym Management System v1.0 is vulnerable to SQL Injection in /gym/trainer_search.php.
CriticalCVSS 9.8No exploitEPSS 1%carmelo · simple gym management systemMar 2, 2026
- CVE-2026-2669639Monitor
code-projects Simple Student Alumni System v1.0 is vulnerable to SQL Injection in /TracerStudy/recordteacher_edit.php.
CriticalCVSS 9.8No exploitEPSS 1%carmelo · simple student alumni systemMar 2, 2026
- CVE-2026-2671239Monitor
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket-admin.php.
CriticalCVSS 9.8No exploitEPSS 1%carmelo · simple food order systemMar 2, 2026
- CVE-2026-2671039Monitor
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/routers/edit-orders.php.
CriticalCVSS 9.8No exploitEPSS 1%carmelo · simple food order systemMar 2, 2026
- CVE-2025-6030739Monitor
code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in the Password field on
CriticalCVSS 9.8No exploitEPSS 0%carmelo · computer laboratory systemOct 10, 2025
- CVE-2024-2525135Monitor
code-projects Agro-School Management System 1.0 is suffers from Incorrect Access Control.
HighCVSS 8.8No exploitEPSS 1%carmelo · agro-school management systemFeb 21, 2024
- CVE-2024-2410033Monitor
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.
HighCVSS 8.3No exploitEPSS 1%carmelo · computer book storeFeb 26, 2024
- CVE-2024-2409631Monitor
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.
HighCVSS 7.8No exploitEPSS 0%carmelo · computer book storeFeb 26, 2024
- CVE-2024-2410531Monitor
SQL Injection vulnerability in Code-projects Computer Science Time Table System 1.0 allows attackers to run arbitrary code via adminFormvali
HighCVSS 7.8No exploitEPSS 0%carmelo · computer science time table systemMar 13, 2024
- CVE-2024-2827929Monitor
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via book.php?bookisbn=.
HighCVSS 7.3No exploitEPSS 0%carmelo · computer book storeMay 14, 2024
- CVE-2025-5629529Monitor
code-projects Computer Laboratory System 1.0 has a file upload vulnerability.
HighCVSS 7.3No exploitEPSS 0%carmelo · computer laboratory systemSep 16, 2025
- CVE-2025-636327Monitor
code-projects Simple Pizza Ordering System adding-exec.php sql injection
MediumCVSS 6.9No exploitEPSS 0%carmelo · simple pizza ordering systemJun 20, 2025
- CVE-2025-636127Monitor
code-projects Simple Pizza Ordering System adds.php sql injection
MediumCVSS 6.9No exploitEPSS 0%carmelo · simple pizza ordering systemJun 20, 2025
- CVE-2025-636227Monitor
code-projects Simple Pizza Ordering System editpro.php sql injection
MediumCVSS 6.9No exploitEPSS 0%carmelo · simple pizza ordering systemJun 20, 2025
- CVE-2025-636427Monitor
code-projects Simple Pizza Ordering System adduser-exec.php sql injection
MediumCVSS 6.9No exploitEPSS 0%carmelo · simple pizza ordering systemJun 20, 2025
- CVE-2026-215827Monitor
code-projects Student Web Portal check_user.php sql injection
MediumCVSS 6.9No exploitEPSS 0%carmelo · student web portalFeb 8, 2026
- CVE-2026-453222Monitor
code-projects Simple Food Ordering System Database Backup food.sql file access
MediumCVSS 5.5No exploitEPSS 1%carmelo · simple food order systemMar 21, 2026
- CVE-2026-374422Monitor
code-projects Student Web Portal signup.php valreg_passwdation sql injection
MediumCVSS 5.5No exploitEPSS 1%carmelo · student web portalMar 8, 2026