NA - CVE-2024-5744 - The wp-eMember WordPress plugin before 10.6.7...
The wp-eMember WordPress plugin before 10.6.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site...
NA - CVE-2024-6070 - The If-So Dynamic Content Personalization...
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored...
Medium - CVE-2024-6574 - The Laposta plugin for WordPress is vulnerable...
The Laposta plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.12. This is due to the plugin not preventing direct access to several test files. This...
NA - CVE-2023-39327 - A flaw was found in OpenJPEG. Maliciously...
A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.
NA - CVE-2023-39329 - A flaw was found in OpenJPEG. A resource...
A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.
High - CVE-2024-5902 - The User Feedback – Create Interactive Feedback...
The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the name parameter in all versions up...
NA - CVE-2024-30213 - StoneFly Storage Concentrator (SC and SCVM)...
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution.
NA - CVE-2024-31947 - StoneFly Storage Concentrator (SC and SCVM)...
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive...