Simple Task Scheduling System
Vendor:
First CVE: Jun 6, 2022 · Active for 4 years
10
Total CVEs
More Total CVEs than 88% of tracked products
10.0
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
9.0
Avg CVSS
Higher Avg CVSS than 83% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Simple Task Scheduling System over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 6, 2022
4 years ago
Most Recent CVE
Sep 1, 2022
1,423 days ago
CVE Severity & Scoring
Simple Task Scheduling System10 CVEs
30%
70%
All CVEs352,427 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High3 (30.0%)
None7 (70.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-36683CRITICAL Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_payment. | Aug 26, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-36681CRITICAL Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_account. | Aug 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-36678CRITICAL Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_category. | Aug 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-30927CRITICAL A SQL injection vulnerability exists in Simple Task Scheduling System 1.0 when MySQL is being used as the application database. An attacker can issue SQL commands to the MySQL data | Jun 6, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-36682CRITICAL Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_student. | Aug 26, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-36680CRITICAL Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /classes/Master.php?f=delete_schedule. | Aug 26, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-36679CRITICAL Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=user/manage_user. | Aug 26, 2022 | 9.8 | 29 | NO | NO |
CVE-2022-36676HIGH Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /categories/view_category.php. | Sep 1, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-36675HIGH Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/manage_schedule.php. | Sep 1, 2022 | 7.2 | 24 | NO | NO |
CVE-2022-36674HIGH Simple Task Scheduling System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /schedules/view_schedule.php. | Sep 1, 2022 | 7.2 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Simple Task Scheduling System
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.0 | 10 | 9.0 | 0.9% | 0 | 0 |