Vulnerabilities > Oretnom23 > High

DATE CVE VULNERABILITY TITLE RISK
2022-10-14 CVE-2022-3496 Unspecified vulnerability in Oretnom23 Human Resource Management System 1.0
A vulnerability was found in SourceCodester Human Resource Management System 1.0 and classified as critical.
network
low complexity
oretnom23
8.8
2022-10-13 CVE-2022-3492 OS Command Injection vulnerability in Oretnom23 Human Resource Management System 1.0
A vulnerability classified as critical was found in SourceCodester Human Resource Management System 1.0.
network
low complexity
oretnom23 CWE-78
8.8
2022-10-06 CVE-2022-42242 SQL Injection vulnerability in Oretnom23 Simple Cold Storage Management System 1.0
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_booking.
network
low complexity
oretnom23 CWE-89
7.2
2022-10-06 CVE-2022-42243 SQL Injection vulnerability in Oretnom23 Simple Cold Storage Management System 1.0
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/manage_storage.php?id=.
network
low complexity
oretnom23 CWE-89
7.2
2022-10-06 CVE-2022-42249 SQL Injection vulnerability in Oretnom23 Simple Cold Storage Management System 1.0
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/storages/view_storage.php?id=.
network
low complexity
oretnom23 CWE-89
7.2
2022-10-06 CVE-2022-42250 SQL Injection vulnerability in Oretnom23 Simple Cold Storage Management System 1.0
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/admin/inquiries/view_details.php?id=.
network
low complexity
oretnom23 CWE-89
7.2
2022-10-06 CVE-2022-42241 SQL Injection vulnerability in Oretnom23 Simple Cold Storage Management System 1.0
Simple Cold Storage Management System v1.0 is vulnerable to SQL injection via /csms/classes/Master.php?f=delete_message.
network
low complexity
oretnom23 CWE-89
7.2
2022-09-02 CVE-2022-36754 SQL Injection vulnerability in Oretnom23 Expense Management System 1.0
Expense Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /Home/debit_credit_p.
network
low complexity
oretnom23 CWE-89
7.2
2022-07-26 CVE-2022-34067 SQL Injection vulnerability in Oretnom23 Warehouse Management System 1.0
Warehouse Management System v1.0 was discovered to contain a SQL injection vulnerability via the cari parameter.
network
low complexity
oretnom23 CWE-89
7.5
2022-07-12 CVE-2022-2297 Unrestricted Upload of File with Dangerous Type vulnerability in Oretnom23 Clinic'S Patient Management System 2.0
A vulnerability, which was classified as critical, was found in SourceCodester Clinics Patient Management System 2.0.
network
low complexity
oretnom23 CWE-434
8.8