Medium - CVE-2024-12239 - The PowerPack Lite for Beaver Builder plugin...
The PowerPack Lite for Beaver Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the navigate parameter in all versions up to, and including, 1.3.0.5 due to...
NA - CVE-2024-12356 - A critical vulnerability has been discovered in...
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site...
NA - CVE-2024-55864 - Cross-site scripting vulnerability exists in My...
Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious...
NA - CVE-2024-38499 - CA Client Automation (ITCM) allows...
CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which...
NA - CVE-2024-54125 - Improper authorization in handler for custom...
Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker to lead a user to access an arbitrary website via the...
High - CVE-2024-9624 - The WP All Import Pro plugin for WordPress is...
The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download...