1921
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access protected files within an App Sandbox containe…
|
NVD-CWE-noinfo
|
CVE-2024-44135
|
2024-09-25 22:28 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1922
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7, macOS Sequoia 15. An app may be able to leak sensitive user information.
|
NVD-CWE-noinfo
|
CVE-2024-44129
|
2024-09-25 22:28 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1923
|
5.5 |
MEDIUM
Local
|
apple
|
macos ipados iphone_os visionos watchos tvos
|
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.7, iOS 17.7 and iPadOS 17.7, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iP…
|
NVD-CWE-noinfo
|
CVE-2024-44176
|
2024-09-25 22:27 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1924
|
6.5 |
MEDIUM
Network
|
apple
|
macos iphone_os ipados visionos watchos tvos safari
|
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. This issue is fixed in Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 …
|
CWE-346
Origin Validation Error
|
CVE-2024-44187
|
2024-09-25 22:25 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1925
|
5.5 |
MEDIUM
Local
|
apple
|
macos ipados iphone_os visionos watchos tvos xcode
|
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, Xcode 16, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. An app …
|
NVD-CWE-noinfo
|
CVE-2024-44191
|
2024-09-25 22:24 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1926
|
9.8 |
CRITICAL
Network
cyberhobo
|
geo_mashup
|
The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input.
|
CWE-20
Improper Input Validation
|
CVE-2018-14071
|
2024-09-25 22:10 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1927
|
- |
|
cyberhobo
|
geo_mashup
|
Cross-site scripting (XSS) vulnerability in the geo search widget in the Geo Mashup plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the search key.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1383
|
2024-09-25 22:10 |
2015-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1928
|
6.1 |
MEDIUM
Network
|
liquidfiles
|
liquidfiles
|
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.
|
CWE-79 CWE-74
Cross-site Scripting Injection
|
CVE-2023-4393
|
2024-09-25 21:15 |
2023-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1929
|
7.5 |
HIGH
Network
idattend
|
idweb
|
Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthentica…
|
CWE-287
Improper Authentication
|
CVE-2023-27377
|
2024-09-25 21:15 |
2023-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1930
|
7.5 |
HIGH
Network
idattend
|
idweb
|
Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attack…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2023-27376
|
2024-09-25 21:15 |
2023-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|