oretnom23 records
761 published records for vendor oretnom23.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 0.3%
- Pre-auth RCE
- 46
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')376
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')166
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')76
- CWE-434 Unrestricted Upload of File with Dangerous Type25
- CWE-707 Improper Neutralization18
- CWE-352 Cross-Site Request Forgery (CSRF)17
The weakness classes this vendor ships most often: where to look.
CWEAll records
761 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2022-40471Weaponized | Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture uploaoretnom23 · clinic\'s patient management system · CWE-434 | Critical9.8 | — | 21.8% | Oct 31, 2022 |
44Plan | CVE-2024-0264No exploit | SourceCodester Clinic Queuing System LoginRegistration.php authorizationoretnom23 · clinic queuing system · CWE-639 | Critical9.8 | — | 18.2% | Jan 7, 2024 |
42Plan | CVE-2021-42580Proof of concept | Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and auoretnom23 · online learning system · CWE-89 | Critical9.8 | — | 10.0% | Nov 15, 2021 |
41Plan | CVE-2024-0265No exploit | SourceCodester Clinic Queuing System GET Parameter index.php file inclusionoretnom23 · clinic queuing system · CWE-73 | High8.8 | — | 20.9% | Jan 7, 2024 |
41Plan | CVE-2021-44653Proof of concept | Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability.oretnom23 · online magazine management system · CWE-89 | Critical9.8 | — | 6.0% | Dec 15, 2021 |
40Plan | CVE-2021-43140Proof of concept | SQL Injection vulnerability exists in Sourcecodester.oretnom23 · simple subscription website · CWE-89 | Critical9.8 | — | 4.7% | Nov 3, 2021 |
40Plan | CVE-2023-1826Proof of concept | SourceCodester Online Computer and Laptop Store index.php unrestricted uploadoretnom23 · online computer and laptop store · CWE-434 | Critical9.8 | — | 4.4% | Apr 4, 2023 |
40Plan | CVE-2023-33592Proof of concept | Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=systeoretnom23 · lost and found information system · CWE-89 | Critical9.8 | — | 3.8% | Jun 28, 2023 |
40Plan | CVE-2023-34581Proof of concept | Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&oretnom23 · service provider management system · CWE-89 | Critical9.8 | — | 3.3% | Jun 12, 2023 |
40Plan | CVE-2021-40247No exploit | SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL coretnom23 · budget and expense tracker system · CWE-89 | Critical9.8 | — | 2.6% | Jan 21, 2022 |
40Plan | CVE-2022-26645No exploit | A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted Poretnom23 · banking system · CWE-434 | Critical9.8 | — | 2.5% | Mar 30, 2022 |
40Plan | CVE-2021-41644Proof of concept | Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that byoretnom23 · online food ordering system · CWE-434 | Critical9.8 | — | 2.5% | Oct 29, 2021 |
40Plan | CVE-2024-34833Proof of concept | Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload.oretnom23 · payroll management system · CWE-434 | Critical9.8 | — | 2.0% | Jun 17, 2024 |
39Monitor | CVE-2022-26283No exploit | Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint.oretnom23 · simple subscription website · CWE-89 | Critical9.8 | — | 1.6% | Mar 21, 2022 |
39Monitor | CVE-2021-46200No exploit | An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.oretnom23 · simple music cloud community system · CWE-89 | Critical9.8 | — | 1.6% | Jan 21, 2022 |
39Monitor | CVE-2021-46309No exploit | An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.oretnom23 · employee and visitor gate pass logging system · CWE-89 | Critical9.8 | — | 1.6% | Jan 21, 2022 |
39Monitor | CVE-2023-31857No exploit | Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution.oretnom23 · online computer and laptop store · CWE-434 | Critical9.8 | — | 1.5% | May 16, 2023 |
39Monitor | CVE-2022-36270No exploit | Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.oretnom23 · clinic\'s patient management system | Critical9.8 | — | 1.4% | Aug 10, 2022 |
39Monitor | CVE-2023-43457No exploit | An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/adminoretnom23 · service provider management system · CWE-269 | Critical9.8 | — | 1.4% | Sep 25, 2023 |
39Monitor | CVE-2024-3376No exploit | SourceCodester Computer Laboratory Management System config.php redirectoretnom23 · computer laboratory management system · CWE-698 | Critical9.8 | — | 1.3% | Apr 6, 2024 |
39Monitor | CVE-2023-31704Proof of concept | Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate privoretnom23 · online computer and laptop store · CWE-863 | Critical9.8 | — | 1.3% | Jul 13, 2023 |
39Monitor | CVE-2022-27304No exploit | Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.oretnom23 · student grading system · CWE-89 | Critical9.8 | — | 1.3% | Apr 5, 2022 |
39Monitor | CVE-2023-38965No exploit | Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.oretnom23 · lost and found information system · CWE-639 | Critical9.8 | — | 1.3% | Nov 3, 2023 |
39Monitor | CVE-2022-29650No exploit | Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/foodoretnom23 · online food ordering system · CWE-89 | Critical9.8 | — | 1.3% | May 25, 2022 |
39Monitor | CVE-2021-41659No exploit | SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the useoretnom23 · banking system · CWE-89 | Critical9.8 | — | 1.3% | Jan 24, 2022 |
- CVE-2022-4047146Plan
Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture uploa
CriticalCVSS 9.8WeaponizedEPSS 22%oretnom23 · clinic\'s patient management systemOct 31, 2022
- CVE-2024-026444Plan
SourceCodester Clinic Queuing System LoginRegistration.php authorization
CriticalCVSS 9.8No exploitEPSS 18%oretnom23 · clinic queuing systemJan 7, 2024
- CVE-2021-4258042Plan
Sourcecodester Online Learning System 2.0 is vunlerable to sql injection authentication bypass in admin login file (/admin/login.php) and au
CriticalCVSS 9.8Proof of conceptEPSS 10%oretnom23 · online learning systemNov 15, 2021
- CVE-2024-026541Plan
SourceCodester Clinic Queuing System GET Parameter index.php file inclusion
HighCVSS 8.8No exploitEPSS 21%oretnom23 · clinic queuing systemJan 7, 2024
- CVE-2021-4465341Plan
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability.
CriticalCVSS 9.8Proof of conceptEPSS 6%oretnom23 · online magazine management systemDec 15, 2021
- CVE-2021-4314040Plan
SQL Injection vulnerability exists in Sourcecodester.
CriticalCVSS 9.8Proof of conceptEPSS 5%oretnom23 · simple subscription websiteNov 3, 2021
- CVE-2023-182640Plan
SourceCodester Online Computer and Laptop Store index.php unrestricted upload
CriticalCVSS 9.8Proof of conceptEPSS 4%oretnom23 · online computer and laptop storeApr 4, 2023
- CVE-2023-3359240Plan
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=syste
CriticalCVSS 9.8Proof of conceptEPSS 4%oretnom23 · lost and found information systemJun 28, 2023
- CVE-2023-3458140Plan
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/?page=services/view&
CriticalCVSS 9.8Proof of conceptEPSS 3%oretnom23 · service provider management systemJun 12, 2023
- CVE-2021-4024740Plan
SQL injection vulnerability in Sourcecodester Budget and Expense Tracker System v1 by oretnom23, allows attackers to execute arbitrary SQL c
CriticalCVSS 9.8No exploitEPSS 3%oretnom23 · budget and expense tracker systemJan 21, 2022
- CVE-2022-2664540Plan
A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted P
CriticalCVSS 9.8No exploitEPSS 3%oretnom23 · banking systemMar 30, 2022
- CVE-2021-4164440Plan
Remote Code Exection (RCE) vulnerability exists in Sourcecodester Online Food Ordering System 2.0 via a maliciously crafted PHP file that by
CriticalCVSS 9.8Proof of conceptEPSS 2%oretnom23 · online food ordering systemOct 29, 2021
- CVE-2024-3483340Plan
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload.
CriticalCVSS 9.8Proof of conceptEPSS 2%oretnom23 · payroll management systemJun 17, 2024
- CVE-2022-2628339Monitor
Simple Subscription Website v1.0 was discovered to contain a SQL injection vulnerability via the id parameter in the view_plan endpoint.
CriticalCVSS 9.8No exploitEPSS 2%oretnom23 · simple subscription websiteMar 21, 2022
- CVE-2021-4620039Monitor
An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php.
CriticalCVSS 9.8No exploitEPSS 2%oretnom23 · simple music cloud community systemJan 21, 2022
- CVE-2021-4630939Monitor
An SQL Injection vulnerability exists in Sourcecodester Employee and Visitor Gate Pass Logging System 1.0 via the username parameter.
CriticalCVSS 9.8No exploitEPSS 2%oretnom23 · employee and visitor gate pass logging systemJan 21, 2022
- CVE-2023-3185739Monitor
Sourcecodester Online Computer and Laptop Store 1.0 allows unrestricted file upload and can lead to remote code execution.
CriticalCVSS 9.8No exploitEPSS 2%oretnom23 · online computer and laptop storeMay 16, 2023
- CVE-2022-3627039Monitor
Clinic's Patient Management System v1.0 has arbitrary code execution via url: ip/pms/users.php.
CriticalCVSS 9.8No exploitEPSS 1%oretnom23 · clinic\'s patient management systemAug 10, 2022
- CVE-2023-4345739Monitor
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin
CriticalCVSS 9.8No exploitEPSS 1%oretnom23 · service provider management systemSep 25, 2023
- CVE-2024-337639Monitor
SourceCodester Computer Laboratory Management System config.php redirect
CriticalCVSS 9.8No exploitEPSS 1%oretnom23 · computer laboratory management systemApr 6, 2024
- CVE-2023-3170439Monitor
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control, which allows remote attackers to elevate priv
CriticalCVSS 9.8Proof of conceptEPSS 1%oretnom23 · online computer and laptop storeJul 13, 2023
- CVE-2022-2730439Monitor
Student Grading System v1.0 was discovered to contain a SQL injection vulnerability via the user parameter.
CriticalCVSS 9.8No exploitEPSS 1%oretnom23 · student grading systemApr 5, 2022
- CVE-2023-3896539Monitor
Lost and Found Information System 1.0 allows account takeover via username and password to a /classes/Users.php?f=save URI.
CriticalCVSS 9.8No exploitEPSS 1%oretnom23 · lost and found information systemNov 3, 2023
- CVE-2022-2965039Monitor
Online Food Ordering System v1.0 was discovered to contain a SQL injection vulnerability via the Search parameter at /online-food-order/food
CriticalCVSS 9.8No exploitEPSS 1%oretnom23 · online food ordering systemMay 25, 2022
- CVE-2021-4165939Monitor
SQL injection vulnerability in Sourcecodester Banking System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the use
CriticalCVSS 9.8No exploitEPSS 1%oretnom23 · banking systemJan 24, 2022