Rems operates a modest portfolio of web-based and utility applications including leads management, PHP data-handling, QR code systems, health monitoring, and interactive mapping tools. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and cluster consistently around input-handling and code-generation weaknesses: cross-site scripting, SQL injection, code injection, unsafe file uploads, and cross-site request forgery. These patterns reflect the vendor's focus on web application development and the recurring risks of insufficient input sanitization and validation across dynamically generated content and database interactions. Defenders tracking this vendor should prioritize patch deployment for internet-facing instances and apply restrictive upload controls and input-validation practices at the application boundary. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rems over time
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-10410CRITICAL A security vulnerability has been detected in SourceCodester Link Status Checker 1.0. This vulnerability affects unknown code of the file index.php. The manipulation of the argumen | Sep 14, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-40472CRITICAL Sourcecodester Daily Calories Monitoring Tool v1.0 is vulnerable to SQL Injection via "delete-calorie.php." | Aug 12, 2024 | 9.8 | 28 | NO | NO |
CVE-2025-1168CRITICAL A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/ | Feb 11, 2025 | 9.8 | 27 | NO | NO |
CVE-2024-8561CRITICAL A vulnerability has been found in SourceCodester PHP CRUD 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /endpoint/delete.ph | Sep 7, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-8170CRITICAL A vulnerability classified as problematic has been found in SourceCodester Zipped Folder Manager App 1.0. This affects an unknown part of the file /endpoint/add-folder.php. The man | Aug 26, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-7811CRITICAL A vulnerability classified as critical has been found in SourceCodester Daily Expenses Monitoring App 1.0. This affects an unknown part of the file /endpoint/delete-expense.php. Th | Aug 15, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-3797CRITICAL A vulnerability was found in SourceCodester QR Code Bookmark System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-book | Apr 15, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-25210CRITICAL Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the expense parameter at /endpoint/delete_expense.php. | Feb 14, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-4967CRITICAL A vulnerability was found in SourceCodester Interactive Map with Marker 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the fil | May 16, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-25211CRITICAL Simple Expense Tracker v1.0 was discovered to contain a SQL injection vulnerability via the category parameter at /endpoint/delete_category.php. | Feb 14, 2024 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rems.
Media articles that mention a CVE ID that affects a product developed by Rems — matched by CVE ID, not by vendor name.