VulnSea

oretnom23 has 7 CVEs on record between 2022 and 2026. The median CVSS is 7.5 (high), with 3 rated critical. None have a confirmed exploitation report. Most affected products: banking_system (3), customer_support_system (1), loan_management_system (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
0 prev 1

Products

  • banking_system 3
  • customer_support_system 1
  • loan_management_system 1
  • lost_and_found_information_system 1
  • simple_online_book_store_system 1
7
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

oretnom23 vulnerabilities

CVEs affecting oretnom23, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2026-30520Medium· 5.4
5mo ago

A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0

A Blind SQL Injection vulnerability exists in SourceCodester Loan Management System v1.0. The vulnerability is located in the ajax.php file (specifically the save_loan action). The application fails to properly sanitize user input suppli…

Sunlitoretnom23 · loan_management_systemEPSS 0.22%via NVD
CVE-2025-70141Critical· 9.4PoC
7mo ago

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php bas…

Abyssaloretnom23 · customer_support_systemEPSS 0.69%via NVD
CVE-2025-63891High· 7.5
10mo ago

Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenti…

Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote unauthenticated attacker to disclose full database contents (including schema and credential hashes) via an unauthenti…

Twilightoretnom23 · simple_online_book_store_systemEPSS 0.45%via NVD
CVE-2023-33677High· 7.5
2y ago

Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".

Sourcecodester Lost and Found Information System's Version 1.0 is vulnerable to unauthenticated SQL Injection at "?page=items/view&id=*".

Twilightoretnom23 · lost_and_found_information_systemEPSS 0.41%via NVD
CVE-2022-26646Critical· 9.8
4y ago

Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.

Online Banking System Protect v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the pages parameter.

Midnightoretnom23 · banking_systemEPSS 1.2%via NVD
CVE-2022-26645Critical· 9.8
4y ago

A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

A remote code execution (RCE) vulnerability in Online Banking System Protect v1.0 allows attackers to execute arbitrary code via a crafted PHP file uploaded through the Upload Image function.

Midnightoretnom23 · banking_systemEPSS 2.5%via NVD
CVE-2022-26644Medium· 6.1
4y ago

Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.

Online Banking System Protect v1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via parameters on user profile, system_info and accounts management.

Sunlitoretnom23 · banking_systemEPSS 0.64%via NVD
oretnom23 vulnerabilities (CVEs) · VulnSea