Vulnerabilities
49 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-25176 | LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c. LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2023-36118 | Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the Cross Site Scripting vulnerability in Faculty Evaulation System using PHP/MySQLi v.1.0 allows an attacker to execute arbitrary code via a crafted payload to the page parameter. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-33569 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user. Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via ip/eval/ajax.php?action=update_user. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2023-2962 | A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affected by this issue is some unknown functionality of the file index.php?page=edit_user. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-230150 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-33440 +1 in the same advisory: …33439 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user. Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user. NVD description · AI analysis pending | 7.2 | 15% | PoC |
| — | |
| CVE-2023-32700 | LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted source. This occurs because luatex-core.lua lets the original io.popen be accessed. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2023-31845 | Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=. Sourcecodester Faculty Evaluation System v1.0 is vulnerable to SQL Injection via /eval/admin/manage_class.php?id=. NVD description · AI analysis pending | 7.2 | <1% | PoC |
| — | |
| CVE-2023-32668 | LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. LuaTeX before 1.17.0 allows a document (compiled with the default settings) to make arbitrary network requests. This occurs because full access to the socket library is permitted by default, as stated in the documentation. This also affects TeX Live before 2023 r66984 and MiKTeX before 23.5. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2023-2366 | A vulnerability was found in SourceCodester Faculty Evaluation System 1.0 and classified as critical. A vulnerability was found in SourceCodester Faculty Evaluation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file ajax.php?action=delete_class. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-227642 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2023-29625 | Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code vi Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2021-45985 | In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read. In Lua 5.4.3, an erroneous finalizer called during a tail call leads to a heap-based buffer over-read. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2022-40435 | Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Dep Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2022-3753 | The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform St The Evaluate WordPress plugin through 1.0 does not sanitize and escapes some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup). NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2022-34992 | Luadec v0.9.9 was discovered to contain a heap-buffer overflow via the function UnsetPending. Luadec v0.9.9 was discovered to contain a heap-buffer overflow via the function UnsetPending. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2022-33099 | An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs. An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs. NVD description · AI analysis pending | 7.5 | 3% | PoC ×3 |
| — | |
| CVE-2022-28805 | singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read th singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code. NVD description · AI analysis pending | 9.1 | 3% | PoC ×3 |
| — | |
| CVE-2022-27123 | Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter. Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-44964 | Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file. Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file. NVD description · AI analysis pending | 6.3 | <1% | PoC ×3 |
| — | |
| CVE-2021-44647 | Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service. Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2021-43519 | Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file. Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file. NVD description · AI analysis pending | 5.5 | 1% | PoC |
| — | |
| CVE-2020-35272 +1 in the same advisory: …35271 | Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in the Task and Descript Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in the Task and Description fields. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2020-24372 | LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c. LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2020-24369 | ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference. ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference. NVD description · AI analysis pending | 7.5 group max | 2% | PoC |
| — | |
| CVE-2020-24342 | Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row. Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row. NVD description · AI analysis pending | 7.8 | 1% | PoC |
| — | |
| CVE-2020-15945 | Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly expects that an oldp Lua 5.4.0 (fixed in 5.4.1) has a segmentation fault in changedline in ldebug.c (e.g., when called by luaG_traceexec) because it incorrectly expects that an oldpc value is always updated upon a return of the flow of control to a function. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2020-15890 | LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled. LuaJit through 2.1.0-beta3 has an out-of-bounds read because __gc handler frame traversal is mishandled. NVD description · AI analysis pending | 7.5 | 3% | PoC |
| — | |
| CVE-2020-15889 +1 in the same advisory: …15888 | Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members. Lua 5.4.0 has a getobjname heap-based buffer over-read because youngcollection in lgc.c uses markold for an insufficient number of list members. NVD description · AI analysis pending | 9.8 group max | 2% | PoC |
| — | |
| CVE-2020-9434 | openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values. openssl_x509_check_ip_asc in lua-openssl 0.7.7-1 mishandles X.509 certificate validation because it uses lua_pushboolean for certain non-boolean return values. NVD description · AI analysis pending | 9.1 | <1% |
| — | ||
| CVE-2019-19391 | In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue that leads to arbitrary memory write or re In LuaJIT through 2.0.5, as used in Moonjit before 2.1.2 and other products, debug.getinfo has a type confusion issue that leads to arbitrary memory write or read operations, because certain cases involving valid stack levels and > options are mishandled. NOTE: The LuaJIT project owner states that the debug libary is unsafe by definition and that this is not a vulnerability. When LuaJIT was originally developed, the expectation was that the entire debug library had no security guarantees and thus it made no sense to assign CVEs. However, not all users of later LuaJIT derivatives share this perspective NVD description · AI analysis pending | 9.1 | 1% |
| — | ||
| CVE-2018-18758 +1 in the same advisory: …18757 | Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757. Open Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2019-6706 | Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. Lua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example, a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships. NVD description · AI analysis pending | 7.5 | 17% | PoC ×2 |
| — | |
| CVE-2018-18803 | Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb. Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb. NVD description · AI analysis pending | 9.8 | 3% | PoC ×2 |
| — |