Show filters
121 Total Results
Displaying 61-70 of 121
Sort by:
Attacker Value
Unknown
CVE-2022-4950
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
0
Attacker Value
Unknown
CVE-2023-32964
Disclosure Date: May 26, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Made with Fuel Better Notifications for WP plugin <= 1.9.2 versions.
0
Attacker Value
Unknown
CVE-2023-0644
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
0
Attacker Value
Unknown
CVE-2023-1087
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The WC Sales Notification WordPress plugin before 1.2.3 does not have CSRF check when activating plugins, which could allow attackers to make logged in admins activate arbitrary plugins present on the blog via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-34654
Disclosure Date: November 28, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) in Virgial Berveling's Manage Notification E-mails plugin <= 1.8.2 on WordPress.
0
Attacker Value
Unknown
CVE-2022-3610
Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Jeeng Push Notifications WordPress plugin before 2.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-45385
Disclosure Date: November 15, 2022 (last updated February 24, 2025)
A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.
0
Attacker Value
Unknown
CVE-2022-41906
Disclosure Date: November 11, 2022 (last updated February 24, 2025)
OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Custom web-hook etc channels. A potential SSRF issue in OpenSearch Notifications Plugin starting in 2.0.0 and prior to 2.2.1 could allow an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Notification plugin's intended scope. OpenSearch 2.2.1+ contains the fix for this issue. There are currently no recommended workarounds.
0
Attacker Value
Unknown
CVE-2022-39976
Disclosure Date: October 27, 2022 (last updated February 24, 2025)
School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=.
0
Attacker Value
Unknown
CVE-2022-39272
Disclosure Date: October 22, 2022 (last updated February 24, 2025)
Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or `.spec.timeout` (and structured variations of these fields), causing the entire object type to stop being processed. This issue is patched in version 0.35.0. As a workaround, Admission controllers can be employed to restrict the values that can be used for fields `.spec.interval` and `.spec.timeout`, however upgrading to the latest versions is still the recommended mitigation.
0