1901
|
5.5 |
MEDIUM
Local
|
apple
|
macos ipados iphone_os visionos watchos tvos xcode
|
This issue was addressed through improved state management. This issue is fixed in iOS 17.7 and iPadOS 17.7, Xcode 16, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18 and iPadOS 18, tvOS 18. An app …
|
NVD-CWE-noinfo
|
CVE-2024-44191
|
2024-09-25 22:24 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1902
|
9.8 |
CRITICAL
Network
cyberhobo
|
geo_mashup
|
The Geo Mashup plugin before 1.10.4 for WordPress has insufficient sanitization of post editor and other user input.
|
CWE-20
Improper Input Validation
|
CVE-2018-14071
|
2024-09-25 22:10 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1903
|
- |
|
cyberhobo
|
geo_mashup
|
Cross-site scripting (XSS) vulnerability in the geo search widget in the Geo Mashup plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the search key.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1383
|
2024-09-25 22:10 |
2015-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1904
|
6.1 |
MEDIUM
Network
|
liquidfiles
|
liquidfiles
|
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.
|
CWE-79 CWE-74
Cross-site Scripting Injection
|
CVE-2023-4393
|
2024-09-25 21:15 |
2023-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1905
|
7.5 |
HIGH
Network
idattend
|
idweb
|
Missing authentication in the StudentPopupDetails_EmergencyContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthentica…
|
CWE-287
Improper Authentication
|
CVE-2023-27377
|
2024-09-25 21:15 |
2023-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1906
|
7.5 |
HIGH
Network
idattend
|
idweb
|
Missing authentication in the StudentPopupDetails_StudentDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attack…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2023-27376
|
2024-09-25 21:15 |
2023-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1907
|
7.5 |
HIGH
Network
idattend
|
idweb
|
Missing authentication in the StudentPopupDetails_ContactDetails method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student data by unauthenticated attack…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2023-27375
|
2024-09-25 21:15 |
2023-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1908
|
6.5 |
MEDIUM
Network
idattend
|
idweb
|
Missing authentication in the DeleteAssignments method in IDAttend’s IDWeb application 3.1.052 and earlier allows deletion of data by unauthenticated attackers.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2023-27261
|
2024-09-25 21:15 |
2023-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1909
|
7.5 |
HIGH
Network
idattend
|
idweb
|
Missing authentication in the GetAssignmentsDue method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction of sensitive student and teacher data by unauthenticated attackers.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2023-27259
|
2024-09-25 21:15 |
2023-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1910
|
7.5 |
HIGH
Network
idattend
|
idweb
|
Missing authentication in the GetStudentGroupStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows retrieval of student and teacher data by unauthenticated attackers.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2023-27258
|
2024-09-25 21:15 |
2023-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|