NA - CVE-2024-12356 - A critical vulnerability has been discovered in...
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site...
NA - CVE-2024-55864 - Cross-site scripting vulnerability exists in My...
Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious...
NA - CVE-2024-38499 - CA Client Automation (ITCM) allows...
CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which...
NA - CVE-2024-54125 - Improper authorization in handler for custom...
Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker to lead a user to access an arbitrary website via the...
High - CVE-2024-9624 - The WP All Import Pro plugin for WordPress is...
The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download...
NA - CVE-2024-11999 - CWE-1104: Use of Unmaintained Third-Party...
CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.
Medium - CVE-2024-12219 - The Stop Registration Spam plugin for WordPress...
The Stop Registration Spam plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.23. This is due to missing or incorrect nonce validation. This...