Show filters
68 Total Results
Displaying 31-40 of 68
Sort by:
Attacker Value
Unknown

CVE-2022-28805

Disclosure Date: April 08, 2022 (last updated February 23, 2025)
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
Attacker Value
Unknown

CVE-2022-27123

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Employee Performance Evaluation v1.0 was discovered to contain a SQL injection vulnerability via the email parameter.
Attacker Value
Unknown

CVE-2021-44964

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Use after free in garbage collector and finalizer of lgc.c in Lua interpreter 5.4.0~5.4.3 allows attackers to perform Sandbox Escape via a crafted script file.
Attacker Value
Unknown

CVE-2021-44647

Disclosure Date: January 11, 2022 (last updated February 23, 2025)
Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.
Attacker Value
Unknown

CVE-2021-43519

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
Attacker Value
Unknown

CVE-2020-28400

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
Affected devices contain a vulnerability that allows an unauthenticated attacker to trigger a denial of service condition. The vulnerability can be triggered if a large amount of DCP reset packets are sent to the device.
Attacker Value
Unknown

CVE-2020-36309

Disclosure Date: April 06, 2021 (last updated November 28, 2024)
ngx_http_lua_module (aka lua-nginx-module) before 0.10.16 in OpenResty allows unsafe characters in an argument when using the API to mutate a URI, or a request or response header.
Attacker Value
Unknown

CVE-2020-35272

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Admin Portal in the Task and Description fields.
Attacker Value
Unknown

CVE-2020-35271

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees, First Name and Last Name fields.
Attacker Value
Unknown

CVE-2020-24371

Disclosure Date: August 17, 2020 (last updated February 21, 2025)
lgc.c in Lua 5.4.0 mishandles the interaction between barriers and the sweep phase, leading to a memory access violation involving collectgarbage.