NA - CVE-2024-6617 - The NinjaTeam Header Footer Custom Code...
The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored...
NA - CVE-2024-6723 - The AI Engine WordPress plugin before 2.4.8...
The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing...
NA - CVE-2024-6850 - The Carousel Slider WordPress plugin before...
The Carousel Slider WordPress plugin before 2.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks...
NA - CVE-2024-7129 - The Appointment Booking Calendar — Simply...
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template...
NA - CVE-2024-7133 - The Floating Notification Bar, Sticky Menu on...
The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.3 does not validate and escape some of its settings before...
NA - CVE-2024-7863 - The Favicon Generator (CLOSED) WordPress plugin...
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary...
NA - CVE-2024-7864 - The Favicon Generator (CLOSED) WordPress plugin...
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation in the output_sub_admin_page_0() function, allowing attackers to make logged in admins delete...
High - CVE-2024-39377 - Media Encoder versions 24.5, 23.6.8 and earlier...
Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation...
Medium - CVE-2024-41870 - Media Encoder versions 24.5, 23.6.8 and earlier...
Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability...
Medium - CVE-2024-41871 - Media Encoder versions 24.5, 23.6.8 and earlier...
Media Encoder versions 24.5, 23.6.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory...