Записи rems
50 опубликованных записей вендора rems.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')30
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')14
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')1
- CWE-918 Server-Side Request Forgery (SSRF)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
50 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2024-24142Proof of concept | Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.rems · school task manager · CWE-89 | Критическая9,8 | — | 1,1 % | 13 февр. 2024 г. |
39Наблюдать | CVE-2024-3797Эксплойта нет | SourceCodester QR Code Bookmark System sql injectionrems · qr code bookmark system · CWE-89 | Критическая9,8 | — | 0,8 % | 15 апр. 2024 г. |
39Наблюдать | CVE-2024-25209Эксплойта нет | Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/derems · barangay population monitoring system · CWE-89 | Критическая9,8 | — | 0,8 % | 14 февр. 2024 г. |
39Наблюдать | CVE-2024-25211Эксплойта нет | Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.rems · simple expense tracker app · CWE-89 | Критическая9,8 | — | 0,8 % | 14 февр. 2024 г. |
39Наблюдать | CVE-2024-25210Эксплойта нет | Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.phrems · simple expense tracker app · CWE-89 | Критическая9,8 | — | 0,8 % | 14 февр. 2024 г. |
39Наблюдать | CVE-2024-40472Эксплойта нет | Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."rems · daily calories monitoring tool · CWE-89 | Критическая9,8 | — | 0,7 % | 12 авг. 2024 г. |
36Наблюдать | CVE-2024-26517Эксплойта нет | SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to trems · school task manager · CWE-79 | Критическая9,1 | — | 0,8 % | 14 мая 2024 г. |
26Наблюдать | CVE-2025-63716Эксплойта нет | The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changingrems · leads manager tool · CWE-352 | Средняя6,5 | — | 0,1 % | 7 нояб. 2025 г. |
25Наблюдать | CVE-2024-3129Эксплойта нет | SourceCodester Image Accordion Gallery App add-image.php unrestricted uploadrems · image accordion gallery app · CWE-434 | Средняя6,3 | — | 0,7 % | 1 апр. 2024 г. |
24Наблюдать | CVE-2024-27719Эксплойта нет | A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via rems · faq management system · CWE-79 | Средняя6,1 | — | 0,5 % | 28 мар. 2024 г. |
24Наблюдать | CVE-2024-1111Эксплойта нет | SourceCodester QR Code Login System add-user.php cross site scriptingrems · qr code login system · CWE-79 | Средняя6,1 | — | 0,4 % | 31 янв. 2024 г. |
24Наблюдать | CVE-2023-43292Эксплойта нет | Cross Site Scripting vulnerability in My Food Recipe Using PHP with Source Code v.1.0 allows a local attacker to execute arbitrary code via rems · my food recipe · CWE-79 | Средняя6,1 | — | 0,4 % | 12 мар. 2024 г. |
24Наблюдать | CVE-2025-60313Эксплойта нет | Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input field.rems · link status checker · CWE-79 | Средняя6,1 | — | 0,4 % | 8 окт. 2025 г. |
24Наблюдать | CVE-2024-28276Эксплойта нет | Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.rems · school task manager · CWE-79 | Средняя6,1 | — | 0,3 % | 14 мая 2024 г. |
24Наблюдать | CVE-2025-60312Эксплойта нет | Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" field, allowing a remotrems · markdown to html converter · CWE-79 | Средняя6,1 | — | 0,3 % | 7 окт. 2025 г. |
24Наблюдать | CVE-2025-63640Эксплойта нет | Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields wrems · medicine reminder app · CWE-79 | Средняя6,1 | — | 0,2 % | 7 нояб. 2025 г. |
21Наблюдать | CVE-2024-7643Эксплойта нет | SourceCodester Leads Manager Tool Delete Leads delete-leads.php sql injectionrems · leads manager tool · CWE-89 | Средняя5,3 | — | 0,9 % | 12 авг. 2024 г. |
21Наблюдать | CVE-2024-8170Эксплойта нет | SourceCodester Zipped Folder Manager App add-folder.php unrestricted uploadrems · zipped folder manager app · CWE-434 | Средняя5,3 | — | 0,8 % | 26 авг. 2024 г. |
21Наблюдать | CVE-2024-7644Эксплойта нет | SourceCodester Leads Manager Tool Add Leads add-leads.php cross site scriptingrems · leads manager tool · CWE-79 | Средняя5,3 | — | 0,7 % | 12 авг. 2024 г. |
21Наблюдать | CVE-2024-4967Эксплойта нет | SourceCodester Interactive Map with Marker delete-mark.php sql injectionrems · interactive map with marker · CWE-89 | Средняя5,3 | — | 0,6 % | 16 мая 2024 г. |
21Наблюдать | CVE-2024-7811Эксплойта нет | SourceCodester Daily Expenses Monitoring App delete-expense.php sql injectionrems · daily expenses monitoring app · CWE-89 | Средняя5,3 | — | 0,6 % | 14 авг. 2024 г. |
21Наблюдать | CVE-2024-9975Эксплойта нет | SourceCodester Drag and Drop Image Upload upload.php unrestricted uploadrems · drag and drop image upload · CWE-434 | Средняя5,3 | — | 0,6 % | 15 окт. 2024 г. |
21Наблюдать | CVE-2024-7792Эксплойта нет | SourceCodester Task Progress Tracker delete-task.php sql injectionrems · task progress tracker · CWE-89 | Средняя5,3 | — | 0,6 % | 14 авг. 2024 г. |
21Наблюдать | CVE-2025-1168Эксплойта нет | SourceCodester Contact Manager with Export to VCF delete-contact.php sql injectionrems · contact manager with export to vcf · CWE-74 | Средняя5,3 | — | 0,5 % | 10 февр. 2025 г. |
21Наблюдать | CVE-2024-9093Эксплойта нет | SourceCodester Profile Registration without Reload Refresh GET Parameter del.php sql injectionrems · profile registration without reload\/refresh · CWE-89 | Средняя5,3 | — | 0,5 % | 22 сент. 2024 г. |
- CVE-2024-2414239Наблюдать
Sourcecodester School Task Manager 1.0 allows SQL Injection via the 'subject' parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 1 %rems · school task manager13 февр. 2024 г.
- CVE-2024-379739Наблюдать
SourceCodester QR Code Bookmark System sql injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rems · qr code bookmark system15 апр. 2024 г.
- CVE-2024-2520939Наблюдать
Barangay Population Monitoring System 1.0 was discovered to contain a SQL injection vulnerability via the resident parameter at /endpoint/de
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rems · barangay population monitoring system14 февр. 2024 г.
- CVE-2024-2521139Наблюдать
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rems · simple expense tracker app14 февр. 2024 г.
- CVE-2024-2521039Наблюдать
Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.ph
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rems · simple expense tracker app14 февр. 2024 г.
- CVE-2024-4047239Наблюдать
Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php."
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %rems · daily calories monitoring tool12 авг. 2024 г.
- CVE-2024-2651736Наблюдать
SQL Injection vulnerability in School Task Manager v.1.0 allows a remote attacker to obtain sensitive information via a crafted payload to t
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %rems · school task manager14 мая 2024 г.
- CVE-2025-6371626Наблюдать
The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unauthorized state-changing
СредняяCVSS 6,5Эксплойта нетEPSS 0 %rems · leads manager tool7 нояб. 2025 г.
- CVE-2024-312925Наблюдать
SourceCodester Image Accordion Gallery App add-image.php unrestricted upload
СредняяCVSS 6,3Эксплойта нетEPSS 1 %rems · image accordion gallery app1 апр. 2024 г.
- CVE-2024-2771924Наблюдать
A cross site scripting (XSS) vulnerability in rems FAQ Management System v.1.0 allows a remote attacker to obtain sensitive information via
СредняяCVSS 6,1Эксплойта нетEPSS 0 %rems · faq management system28 мар. 2024 г.
- CVE-2024-111124Наблюдать
SourceCodester QR Code Login System add-user.php cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 0 %rems · qr code login system31 янв. 2024 г.
- CVE-2023-4329224Наблюдать
Cross Site Scripting vulnerability in My Food Recipe Using PHP with Source Code v.1.0 allows a local attacker to execute arbitrary code via
СредняяCVSS 6,1Эксплойта нетEPSS 0 %rems · my food recipe12 мар. 2024 г.
- CVE-2025-6031324Наблюдать
Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input field.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %rems · link status checker8 окт. 2025 г.
- CVE-2024-2827624Наблюдать
Sourcecodester School Task Manager 1.0 is vulnerable to Cross Site Scripting (XSS) via add-task.php?task_name=.
СредняяCVSS 6,1Эксплойта нетEPSS 0 %rems · school task manager14 мая 2024 г.
- CVE-2025-6031224Наблюдать
Sourcecodester Markdown to HTML Converter v1.0 is vulnerable to a Cross-Site Scripting (XSS) in the "Markdown Input" field, allowing a remot
СредняяCVSS 6,1Эксплойта нетEPSS 0 %rems · markdown to html converter7 окт. 2025 г.
- CVE-2025-6364024Наблюдать
Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes (Optional)" fields w
СредняяCVSS 6,1Эксплойта нетEPSS 0 %rems · medicine reminder app7 нояб. 2025 г.
- CVE-2024-764321Наблюдать
SourceCodester Leads Manager Tool Delete Leads delete-leads.php sql injection
СредняяCVSS 5,3Эксплойта нетEPSS 1 %rems · leads manager tool12 авг. 2024 г.
- CVE-2024-817021Наблюдать
SourceCodester Zipped Folder Manager App add-folder.php unrestricted upload
СредняяCVSS 5,3Эксплойта нетEPSS 1 %rems · zipped folder manager app26 авг. 2024 г.
- CVE-2024-764421Наблюдать
SourceCodester Leads Manager Tool Add Leads add-leads.php cross site scripting
СредняяCVSS 5,3Эксплойта нетEPSS 1 %rems · leads manager tool12 авг. 2024 г.
- CVE-2024-496721Наблюдать
SourceCodester Interactive Map with Marker delete-mark.php sql injection
СредняяCVSS 5,3Эксплойта нетEPSS 1 %rems · interactive map with marker16 мая 2024 г.
- CVE-2024-781121Наблюдать
SourceCodester Daily Expenses Monitoring App delete-expense.php sql injection
СредняяCVSS 5,3Эксплойта нетEPSS 1 %rems · daily expenses monitoring app14 авг. 2024 г.
- CVE-2024-997521Наблюдать
SourceCodester Drag and Drop Image Upload upload.php unrestricted upload
СредняяCVSS 5,3Эксплойта нетEPSS 1 %rems · drag and drop image upload15 окт. 2024 г.
- CVE-2024-779221Наблюдать
SourceCodester Task Progress Tracker delete-task.php sql injection
СредняяCVSS 5,3Эксплойта нетEPSS 1 %rems · task progress tracker14 авг. 2024 г.
- CVE-2025-116821Наблюдать
SourceCodester Contact Manager with Export to VCF delete-contact.php sql injection
СредняяCVSS 5,3Эксплойта нетEPSS 1 %rems · contact manager with export to vcf10 февр. 2025 г.
- CVE-2024-909321Наблюдать
SourceCodester Profile Registration without Reload Refresh GET Parameter del.php sql injection
СредняяCVSS 5,3Эксплойта нетEPSS 1 %rems · profile registration without reload\/refresh22 сент. 2024 г.