|
209561
|
9.8 |
CRITICAL
Network
|
student_management_system_project
|
student_management_system
|
Kabir Alhasan Student Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
|
CWE-89
SQL Injection
|
CVE-2020-23935
|
2024-11-21 14:14 |
2020-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209562
|
9.8 |
CRITICAL
Network
|
phpgurukul
|
vehicle_parking_management_system
|
PHPGurukul Vehicle Parking Management System 1.0 is vulnerable to Authentication Bypass via "Username: admin'# && Password: (Write Something)".
|
CWE-89
SQL Injection
|
CVE-2020-23936
|
2024-11-21 14:14 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209563
|
7.5 |
HIGH
Network
|
icinga debian suse
|
icinga_web_2 debian_linux package_hub
|
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web …
|
CWE-22
Path Traversal
|
CVE-2020-24368
|
2024-11-21 14:14 |
2020-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209564
|
7.1 |
HIGH
Local
|
linux canonical opensuse oracle starwindsoftware
|
linux_kernel ubuntu_linux leap sd-wan_edge starwind_virtual_san
|
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs be…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-24394
|
2024-11-21 14:14 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209565
|
7.5 |
HIGH
Network
|
gunet
|
open_eclass_platform
|
GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, …
|
CWE-200
Information Exposure
|
CVE-2020-24381
|
2024-11-21 14:14 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209566
|
9.8 |
CRITICAL
Network
|
xorux
|
stor2rrd lpar2rrd
|
tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.
|
CWE-78
OS Command
|
CVE-2020-24032
|
2024-11-21 14:14 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209567
|
8.8 |
HIGH
Network
|
ritecms
|
ritecms
|
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php web shell in the "Filemanager" section.
|
CWE-78
OS Command
|
CVE-2020-23934
|
2024-11-21 14:14 |
2020-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209568
|
7.5 |
HIGH
Network
|
luajit
|
luajit
|
LuaJIT through 2.1.0-beta3 has an out-of-bounds read in lj_err_run in lj_err.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-24372
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209569
|
5.3 |
MEDIUM
Network
|
lua
|
lua
|
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.
|
CWE-763
Release of Invalid Pointer or Reference
|
CVE-2020-24371
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209570
|
5.3 |
MEDIUM
Network
|
lua fedoraproject debian
|
lua fedora debian_linux
|
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2020-24370
|
2024-11-21 14:14 |
2020-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|