Vulnerabilities > Code Projects

DATE CVE VULNERABILITY TITLE RISK
2024-02-14 CVE-2024-25225 Cross-site Scripting vulnerability in Code-Projects Simple Admin Panel 1.0
A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function.
network
low complexity
code-projects CWE-79
5.4
2024-02-14 CVE-2024-25226 Cross-site Scripting vulnerability in Code-Projects Simple Admin Panel 1.0
A cross-site scripting (XSS) vulnerability in Simple Admin Panel App v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter under the Add Category function.
network
low complexity
code-projects CWE-79
6.1
2024-02-09 CVE-2024-25307 SQL Injection vulnerability in Code-Projects Cinema Seat Reservation System 1.0
Code-projects Cinema Seat Reservation System 1.0 allows SQL Injection via the 'id' parameter at "/Cinema-Reservation/booking.php?id=1."
network
low complexity
code-projects CWE-89
critical
9.8
2024-02-09 CVE-2024-25310 SQL Injection vulnerability in Code-Projects Simple School Management System 1.0
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/delete.php?id=5."
network
low complexity
code-projects CWE-89
8.8
2024-02-09 CVE-2024-25304 SQL Injection vulnerability in Code-Projects Simple School Management System 1.0
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'apass' parameter at "School/index.php."
network
low complexity
code-projects CWE-89
8.8
2024-02-09 CVE-2024-25305 SQL Injection vulnerability in Code-Projects Simple School Management System 1.0
Code-projects Simple School Managment System 1.0 allows Authentication Bypass via the username and password parameters at School/index.php.
network
low complexity
code-projects CWE-89
8.8
2024-02-09 CVE-2024-25306 SQL Injection vulnerability in Code-Projects Simple School Management System 1.0
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'aname' parameter at "School/index.php".
network
low complexity
code-projects CWE-89
8.8
2024-02-09 CVE-2024-25308 SQL Injection vulnerability in Code-Projects Simple School Management System 1.0
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'name' parameter at School/teacher_login.php.
network
low complexity
code-projects CWE-89
8.8
2024-02-09 CVE-2024-25309 SQL Injection vulnerability in Code-Projects Simple School Management System 1.0
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.
network
low complexity
code-projects CWE-89
8.8
2024-02-09 CVE-2024-25312 SQL Injection vulnerability in Code-Projects Simple School Management System 1.0
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'id' parameter at "School/sub_delete.php?id=5."
network
low complexity
code-projects CWE-89
8.8