Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Unknown
CVE-2025-24607
Disclosure Date: February 14, 2025 (last updated February 15, 2025)
Missing Authorization vulnerability in Northern Beaches Websites IdeaPush allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects IdeaPush: from n/a through 8.71.
0
Attacker Value
Unknown
CVE-2024-11844
Disclosure Date: December 03, 2024 (last updated December 21, 2024)
The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions up to, and including, 8.71. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete terms for the "boards" taxonomy.
0
Attacker Value
Unknown
CVE-2024-46948
Disclosure Date: November 08, 2024 (last updated November 14, 2024)
Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
0
Attacker Value
Unknown
CVE-2024-49275
Disclosure Date: October 20, 2024 (last updated October 23, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson IdeaPush allows Cross Site Request Forgery.This issue affects IdeaPush: from n/a through 8.69.
0
Attacker Value
Unknown
CVE-2024-37265
Disclosure Date: July 22, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.60.
0
Attacker Value
Unknown
CVE-2024-37461
Disclosure Date: July 21, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Martin Gibson IdeaPush allows Stored XSS.This issue affects IdeaPush: from n/a through 8.65.
0
Attacker Value
Unknown
CVE-2023-45684
Disclosure Date: November 14, 2023 (last updated November 21, 2023)
Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.
0
Attacker Value
Unknown
CVE-2023-47181
Disclosure Date: November 08, 2023 (last updated November 16, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson IdeaPush plugin <= 8.52 versions.
0
Attacker Value
Unknown
CVE-2023-45832
Disclosure Date: October 25, 2023 (last updated November 02, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Martin Gibson WP GoToWebinar plugin <= 14.45 versions.
0
Attacker Value
Unknown
CVE-2023-26560
Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.
0