Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2024-32952

Disclosure Date: April 24, 2024 (last updated April 24, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BloomPixel Max Addons Pro for Bricks allows Reflected XSS.This issue affects Max Addons Pro for Bricks: from n/a through 1.6.1.
0
Attacker Value
Unknown

CVE-2024-32951

Disclosure Date: April 24, 2024 (last updated April 24, 2024)
Missing Authorization vulnerability in BloomPixel Max Addons Pro for Bricks.This issue affects Max Addons Pro for Bricks: from n/a through 1.6.1.
0
Attacker Value
Unknown

CVE-2024-31242

Disclosure Date: April 10, 2024 (last updated April 11, 2024)
Missing Authorization vulnerability in Bricksforge.This issue affects Bricksforge: from n/a through 2.0.17.
0
Attacker Value
Unknown

CVE-2022-3401

Disclosure Date: October 28, 2022 (last updated November 08, 2023)
The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocks in website content in versions 1.2 to 1.5.3. This, combined with the missing authorization vulnerability (CVE-2022-3400), makes it possible for authenticated attackers with minimal permissions, such as a subscriber, can edit any page, post, or template on the vulnerable WordPress website and inject a code execution block that can be used to achieve remote code execution.
Attacker Value
Unknown

CVE-2022-3400

Disclosure Date: October 28, 2022 (last updated February 24, 2025)
The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1.5.3. This makes it possible for authenticated attackers with minimal permissions, such as a subscriber, to edit any page, post, or template on the vulnerable WordPress website.
Attacker Value
Unknown

CVE-2018-12920

Disclosure Date: June 28, 2018 (last updated November 26, 2024)
Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettings or basic.html#datadelivery URI.
Attacker Value
Unknown

CVE-2018-3813

Disclosure Date: January 01, 2018 (last updated November 26, 2024)
getConfigExportFile.cgi on FLIR Brickstream 2300 devices 2.0 4.1.53.166 has Incorrect Access Control, as demonstrated by reading the AVI_USER_ID and AVI_USER_PASSWORD fields via a direct request.
0