Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-12-12 CVE-2024-10910 The The Grid Plus – Unlimited grid layout plugin for WordPress is vulnerable to arbitrary shortcode execution via grid_plus_load_by_category AJAX action in all versions up to, and including, 1.3.5.
network
low complexity
CWE-94
7.3
2024-12-12 CVE-2024-10111 The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.26.3.
network
high complexity
CWE-287
8.1
2024-12-12 CVE-2024-11443 The de:branding plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the debranding_save() function in all versions up to, and including, 1.0.2.
network
low complexity
CWE-862
8.8
2024-12-12 CVE-2024-11689 The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.29.
network
low complexity
CWE-352
8.8
2024-12-12 CVE-2024-12492 SQL Injection vulnerability in Anisha Farmacia 1.0
A vulnerability was found in code-projects Farmacia 1.0.
network
low complexity
anisha CWE-89
8.8
2024-12-12 CVE-2024-44224 Incorrect Default Permissions vulnerability in Apple Macos
A permissions issue was addressed with additional restrictions.
local
low complexity
apple CWE-276
7.8
2024-12-12 CVE-2024-44225 Unspecified vulnerability in Apple products
A logic issue was addressed with improved checks.
local
low complexity
apple
7.8
2024-12-12 CVE-2024-44245 Out-of-bounds Write vulnerability in Apple products
The issue was addressed with improved memory handling.
local
low complexity
apple CWE-787
7.1
2024-12-12 CVE-2024-44291 Unspecified vulnerability in Apple Macos
A logic issue was addressed with improved file handling.
local
low complexity
apple
7.8
2024-12-12 CVE-2024-54479 Unspecified vulnerability in Apple products
The issue was addressed with improved checks.
network
low complexity
apple
7.5