5.5

CVSS3.1

CVE-2021-26281 - Information disclosure vulnerability in Alarm clock module

Some parameters of the alarm clock module are improperly stored, leaking some sensitive information.

๐Ÿ“… Published: Dec. 17, 2024, 6:37 a.m. ๐Ÿ”„ Last Modified: Dec. 17, 2024, 2:41 p.m.

7.9

CVSS3.1

CVE-2021-26280 - Permission bypass vulnerability in permission manager module

Locally installed application can bypass the permission check and perform system operations that require permission.

๐Ÿ“… Published: Dec. 17, 2024, 6:27 a.m. ๐Ÿ”„ Last Modified: Dec. 17, 2024, 2:38 p.m.

8.7

CVSS4.0

CVE-2024-11999 -

CWE-1104: Use of Unmaintained Third-Party Components vulnerability exists that could cause complete control of the device when an authenticated user installs malicious code into HMI product.

๐Ÿ“… Published: Dec. 17, 2024, 6:13 a.m. ๐Ÿ”„ Last Modified: Dec. 17, 2024, 2:40 p.m.

7.3

CVSS4.0

CVE-2024-38499 - Improper Privilege Management Vulnerability in CA Client Automation 14.5

CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to โ€ฆ

๐Ÿ“… Published: Dec. 17, 2024, 5:43 a.m. ๐Ÿ”„ Last Modified: Dec. 19, 2024, 6:15 a.m.

3.3

CVSS3.0

CVE-2024-54125 -

Improper authorization in handler for custom URL scheme issue in "Shonen Jump+" App for Android versions prior to 4.0.0 allows an attacker to lead a user to access an arbitrary website via the vulnerable App. As a result, the user may become a victim of a phishing attack.

๐Ÿ“… Published: Dec. 17, 2024, 5:36 a.m. ๐Ÿ”„ Last Modified: Dec. 17, 2024, 2:59 p.m.

7.6

CVSS3.1

CVE-2024-9624 - WP All Import Pro <= 4.9.3 - Authenticated (Administrator+) Server-Side Request Forgery via File Imโ€ฆ

The WP All Import Pro plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.9.3 due to missing SSRF protection on the pmxi_curl_download function. This makes it possible for authenticated attackers, with Administrator-level access and above, to maโ€ฆ

๐Ÿ“… Published: Dec. 17, 2024, 5:23 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:31 p.m.

4.8

CVSS3.0

CVE-2024-55864 -

Cross-site scripting vulnerability exists in My WP Customize Admin/Frontend versions prior to ver 1.24.1. If a malicious administrative user customizes the administrative page with some malicious contents, an arbitrary script may be executed on the web browser of the other users who are accessing tโ€ฆ

๐Ÿ“… Published: Dec. 17, 2024, 4:43 a.m. ๐Ÿ”„ Last Modified: July 14, 2025, 10:45 p.m.

9.8

CVSS3.1

CVE-2024-12356 - Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)

A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.

๐Ÿ“… Published: Dec. 17, 2024, 4:29 a.m. ๐Ÿ”„ Last Modified: Oct. 24, 2025, 1:44 p.m.

5.9

CVSS3.1

CVE-2021-26279 - Information disclosure vulnerability in Weather module

Some parameters of the weather module are improperly stored, leaking some sensitive information.

๐Ÿ“… Published: Dec. 17, 2024, 3:34 a.m. ๐Ÿ”„ Last Modified: Dec. 17, 2024, 5:30 p.m.

6.3

CVSS3.1

CVE-2021-26278 - Sensitive information leakage vulnerability in wifi module

The wifi module exposes the interface and has improper permission control, leaking sensitive information about the device.

๐Ÿ“… Published: Dec. 17, 2024, 3:05 a.m. ๐Ÿ”„ Last Modified: Dec. 17, 2024, 5:30 p.m.
Total resulsts: 343968
Page 6915 of 34,397
ยซ previous page ยป next page
Filters