Remyandrade maintains a modest portfolio of web-based business and educational applications—including habit tracking, employee management, student grading, and knowledge-base tools—that collectively occupy a more prominent position in the vulnerability landscape than their product count would suggest. Vulnerabilities affecting this vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur consistently across the application portfolio through input-handling and access-control weakness classes: cross-site scripting, SQL injection, code injection, unrestricted file upload, and improper access control. These patterns reflect common gaps in secure coding practice across web application development, particularly in input validation, output encoding, and authorization enforcement. Defenders should prioritize inventory and patching of exposed instances, especially where these applications handle sensitive employee, student, or user data; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Remyandrade over time
Signals from CVEs in this vendor scope (77 CVEs).
77 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-24496CRITICAL An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components. | Feb 8, 2024 | 9.8 | 47 | NO | YES |
CVE-2024-24495CRITICAL SQL Injection vulnerability in delete-tracker.php in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via crafted GET request. | Feb 8, 2024 | 9.8 | 42 | NO | YES |
CVE-2024-24494MEDIUM Cross Site Scripting vulnerability in Daily Habit Tracker v.1.0 allows a remote attacker to execute arbitrary code via the day, exercise, pray, read_book, vitamins, laundry, alcoho | Feb 8, 2024 | 6.1 | 40 | NO | YES |
CVE-2023-5790CRITICAL A vulnerability classified as critical was found in SourceCodester File Manager App 1.0. Affected by this vulnerability is an unknown functionality of the file endpoint/add-file.ph | Oct 26, 2023 | 9.8 | 31 | NO | NO |
CVE-2024-7748CRITICAL A vulnerability, which was classified as critical, has been found in SourceCodester Accounts Manager App 1.0. This issue affects some unknown processing of the file /endpoint/delet | Aug 13, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-2067CRITICAL A vulnerability was found in SourceCodester Computer Inventory System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /endpoint/delete-co | Mar 1, 2024 | 9.8 | 29 | NO | NO |
CVE-2025-70457CRITICAL A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/upload.php component. The application fails to properly valida | Jan 23, 2026 | 9.8 | 28 | NO | NO |
CVE-2024-8380CRITICAL A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been rated as critical. This issue affects some unknown processing of the file /endpoint/ | Sep 3, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-25302CRITICAL Sourcecodester Event Student Attendance System 1.0, allows SQL Injection via the 'student' parameter. | Feb 9, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-24141CRITICAL Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter. | Jan 29, 2024 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (77 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Remyandrade.
Media articles that mention a CVE ID that affects a product developed by Remyandrade — matched by CVE ID, not by vendor name.