Sherlock's vulnerability portfolio, though concentrated in a small number of business-management applications spanning employee systems, accounting, gym operations, and online filing platforms, skews strongly toward critical-severity outcomes. The recurring exposure centers on input-handling and injection vulnerabilities—SQL injection, general injection flaws, and cross-site scripting—that are characteristic of web applications with inadequate input sanitization and output encoding. Defenders should treat this vendor's advisories as high-priority given the severity tendency; live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sherlock over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-5035CRITICAL A vulnerability has been found in code-projects Accounting System 1.0. This affects an unknown part of the file /view_work.php of the component Parameter Handler. Such manipulation | Mar 29, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-5033CRITICAL A vulnerability was detected in code-projects Accounting System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_costumer.php of the component Para | Mar 29, 2026 | 9.8 | 32 | NO | NO |
CVE-2024-25216CRITICAL Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the mailud parameter at /aprocess.php. | Feb 14, 2024 | 9.8 | 32 | NO | NO |
CVE-2026-5034CRITICAL A flaw has been found in code-projects Accounting System 1.0. Affected by this issue is some unknown functionality of the file /edit_costumer.php of the component Parameter Handler | Mar 29, 2026 | 9.8 | 31 | NO | NO |
CVE-2024-25215CRITICAL Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php. | Feb 14, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-25214CRITICAL An issue in Employee Managment System v1.0 allows attackers to bypass authentication via injecting a crafted payload into the E-mail and Password parameters at /alogin.html. | Feb 14, 2024 | 9.8 | 29 | NO | NO |
CVE-2023-37068CRITICAL Code-Projects Gym Management System V1.0 allows remote attackers to execute arbitrary SQL commands via the login form, leading to unauthorized access and potential data manipulatio | Aug 9, 2023 | 9.8 | 26 | NO | NO |
CVE-2024-25213HIGH Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /edit.php. | Feb 14, 2024 | 7.2 | 25 | NO | NO |
CVE-2024-25212HIGH Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /delete.php. | Feb 14, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-0503MEDIUM A vulnerability was found in code-projects Online FIR System 1.0. It has been classified as problematic. This affects an unknown part of the file registercomplaint.php. The manipul | Jan 13, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sherlock.
Media articles that mention a CVE ID that affects a product developed by Sherlock — matched by CVE ID, not by vendor name.