Vulnerabilities in SourceCodester

2,005 results
Vexday analysis

Com 1.829 CVEs catalogadas e 132 surgidas apenas nos últimos 90 dias, o volume de vulnerabilidades associadas ao SourceCodester reflete um ritmo elevado de descobertas recentes que exige atenção contínua. A taxa de exploração ativa está abaixo da média geral do catálogo, sem registros no CISA KEV, o que pode indicar menor visibilidade dos ativos em ambientes críticos, mas não reduz o risco potencial dado que 143 falhas já possuem PoC pública disponível. O tipo de falha mais comum é CWE-89 (SQL Injection), uma classe de vulnerabilidade com longa tradição de abuso e baixo custo de exploração. A CVE mais perigosa identificada atualmente é CVE-2022-4855, com score EPSS de 0,2646, sugerindo probabilidade não negligenciável de exploração e recomendando priorização imediata em processos de remediação.

CVE-2025-5984MEDIUMSourceCodester Online Student Clearance System add-fee.php cross site scriptingEPSS 0.3%CVE-2026-12529MEDIUMSourceCodester CET Automated Grading System with AI Predictive Analytics Student Self-Registration Endpoint index.php access controlEPSS 0.3%CVE-2026-10704MEDIUMSourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injectionEPSS 0.3%CVE-2025-1961MEDIUMSourceCodester Best Church Management Software web_crud.php sql injectionEPSS 0.3%CVE-2025-9306MEDIUMSourceCodester Advanced School Management System addNotice cross site scriptingEPSS 0.3%CVE-2025-10088MEDIUMSourceCodester Time Tracker index.html cross site scriptingEPSS 0.3%CVE-2026-2160MEDIUMSourceCodester Simple Responsive Tourism Website Master.php cross site scriptingEPSS 0.3%CVE-2024-11097MEDIUMSourceCodester Student Record Management System Main Menu infinite loopEPSS 0.3%CVE-2026-11515MEDIUMSourceCodester Barangay Resident Profiling and Information Management System Password Reset passsword_reset.php hard-coded passwordEPSS 0.3%CVE-2026-11484MEDIUMSourceCodester Class and Exam Timetabling System archive3.php sql injectionEPSS 0.3%CVE-2026-11486MEDIUMSourceCodester Class and Exam Timetabling System archive1.php sql injectionEPSS 0.3%CVE-2026-11485MEDIUMSourceCodester Class and Exam Timetabling System archive2.php sql injectionEPSS 0.3%CVE-2026-11483MEDIUMSourceCodester Class and Exam Timetabling System archive4.php sql injectionEPSS 0.3%CVE-2026-1147MEDIUMSourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System api_patient_schedule.php cross site scriptingEPSS 0.3%CVE-2026-95957MEDIUMSourceCodester Smart Attendance System with QR Code Scanner Self-Registration student_signup.php prepend cross site scriptingEPSS 0.3%CVE-2026-10876MEDIUMSourceCodester Ship Ferry Ticket Reservation System admin improper authorizationEPSS 0.3%CVE-2026-2009MEDIUMSourceCodester Gas Agency Management System createUser.php access controlEPSS 0.3%CVE-2026-10263MEDIUMSourceCodester Computer Repair Shop Management System manage_product.php sql injectionEPSS 0.3%CVE-2026-10185MEDIUMSourceCodester Hospitals Patient Records Management System Users.php save sql injectionEPSS 0.3%CVE-2026-10184MEDIUMSourceCodester Hospitals Patient Records Management System Users.php delete sql injectionEPSS 0.3%