A vulnerability classified as problematic has been found in templatescoderthemes Spexo Addons for Elementor Plugin up to 1.0.14 on WordPress. Affected is the function tmpcoder_theme_install_func. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2024-13335. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability classified as critical was found in wpwax Post Grid Slider & Carousel Ultimate Plugin up to 1.6.10 on WordPress. Affected by this vulnerability is the function post_type_ajax_handler of the component Shortcode Handler. The manipulation of the argument theme leads to path traversal.
This vulnerability is known as CVE-2024-13409. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in wpwax Post Grid, Slider & Carousel Ultimate Plugin up to 1.6.10 on WordPress. Affected by this issue is the function pgcu of the component Shortcode Handler. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is handled as CVE-2024-13408. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Broadcom Symantec Privileged Access Management up to 3.4.6/4.1.8/4.2.0. This vulnerability affects unknown code of the component Request Notifications Handler. The manipulation leads to improper authentication.
This vulnerability was named CVE-2025-24502. The attack can only be done within the local network. There is no exploit available.
A vulnerability was found in Broadcom Symantec Privileged Access Management up to 3.4.6/4.1.8. It has been classified as critical. This affects an unknown part of the component PAM. The manipulation leads to unrestricted upload.
This vulnerability is uniquely identified as CVE-2025-24505. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Broadcom Symantec Privileged Access Management up to 3.4.6/4.1.8/4.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component PAM Database. The manipulation leads to information disclosure.
This vulnerability was named CVE-2025-24500. The attack needs to be approached within the local network. There is no exploit available.
A vulnerability was found in Broadcom Symantec Privileged Access Management up to 3.4.6/4.1.8/4.2.0. It has been rated as critical. This issue affects some unknown processing of the component PAM Server. The manipulation leads to session fixiation.
The identification of this vulnerability is CVE-2025-24503. The attack can only be done within the local network. There is no exploit available.
A vulnerability classified as problematic has been found in Broadcom Symantec Privileged Access Management up to 3.4.6/4.1.8/4.2.0. Affected is an unknown function of the component Application Log Handler. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2025-24504. The attack can only be initiated within the local network. There is no exploit available.
A vulnerability classified as problematic was found in Broadcom Symantec Privileged Access Management up to 3.4.6/4.1.8/4.2.0. Affected by this vulnerability is an unknown functionality of the component PAM. The manipulation leads to information disclosure.
This vulnerability is known as CVE-2025-24506. The attack needs to be done within the local network. There is no exploit available.