|
209921
|
8.8 |
HIGH
Network
|
ritecms
|
ritecms
|
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.
|
CWE-78
OS Command
|
CVE-2020-23934
|
2024-11-21 14:14 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209922
|
7.5 |
HIGH
Network
|
luajit
|
luajit
|
LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24372
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209923
|
5.3 |
MEDIUM
Network
|
lua
|
lua
|
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2020-24371
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209924
|
5.3 |
MEDIUM
Network
|
lua fedoraproject debian
|
lua fedora debian_linux
|
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2020-24370
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209925
|
7.5 |
HIGH
Network
|
lua
|
lua
|
ldebug.c in Lua 5.4.0 attempts to access debug information via the line hook of a stripped function, leading to a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2020-24369
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209926
|
8.8 |
HIGH
Network
|
shopxo
|
shopxo
|
ShopXO v1.8.1 has a command execution vulnerability. Attackers can use this vulnerability to execute arbitrary commands and gain control of the server.
|
CWE-78
OS Command
|
CVE-2020-24220
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209927
|
9.8 |
CRITICAL
Network
|
online_shopping_alphaware_project
|
online_shopping_alphaware
|
A SQL injection vulnerability in SourceCodester Online Shopping Alphaware 1.0 allows remote unauthenticated attackers to bypass the authentication process via email and password parameters.
|
CWE-89
SQL Injection
|
CVE-2020-24208
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209928
|
9.8 |
CRITICAL
Network
|
snmptt debian
|
snmptt debian_linux
|
SNMPTT before 1.4.2 allows attackers to execute shell code via EXEC, PREXEC, or unknown_trap_exec.
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2020-24361
|
2024-11-21 14:14 |
2020-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209929
|
5.5 |
MEDIUM
Local
|
f5
|
njs
|
njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote …
|
CWE-416
Use After Free
|
CVE-2020-24349
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209930
|
5.5 |
MEDIUM
Local
|
f5
|
njs
|
njs through 0.4.3, used in NGINX, has an out-of-bounds read in njs_json_stringify_iterator in njs_json.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24348
|
2024-11-21 14:14 |
2020-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|