Products: 97
    Vulnerabilities: 484
    Known Exploited: 0
    6
    Critical Level Threats
    214
    High Level Threats
    220
    Medium Level Threats
    44
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Items Per Page

    Vulnerabilities

    CVE-2026-2912

    code-projects Online Reviewer System studentresult-view.php sql injection

    Last Modified: Apr 18, 2026
    Published: Feb 22, 2026

    CVE-2025-70152

    code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management endpoints /admin/save_user.php and /admin/update_user.php. These endpoints lack authentication checks and directly concatenate user-supplied POST parameters (firstname, lastname, username, password, user_id) into SQL queries without validation or parameterization.

    Last Modified: Sep 08, 2026
    Published: Feb 18, 2026

    CVE-2025-70151

    code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestricted file upload. The endpoints update_profile_picture.php and upload_picture.php store uploaded files in a web-accessible uploads/ directory using the original, user-supplied filename without validating the file type or extension. By uploading a PHP file and then requesting it from /uploads/, an attacker can execute arbitrary PHP code as the web server user.

    Last Modified: Sep 08, 2026
    Published: Feb 18, 2026

    CVE-2026-2224

    code-projects Online Reviewer System btn_functions.php cross site scripting

    Last Modified: Apr 18, 2026
    Published: Feb 09, 2026

    CVE-2026-2223

    code-projects Online Reviewer System index.php sql injection

    Last Modified: Apr 17, 2026
    Published: Feb 09, 2026
    Items Per Page