4
CVE-2024-23912 -
Out-of-bounds Read vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_File() function is used to read a malformed DICOM data, it might result in over-reading memory buffer and could cause memory access violation.
6.6
CVE-2023-35701 - Apache Hive: Arbitrary command execution via JDBC driver
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Hive. The vulnerability affects the Hive JDBC driver component and it can potentially lead to arbitrary code execution on the machine/endpoint that the JDBC driver (client) is running. The malicious user must have suβ¦
5.7
CVE-2024-28072 - Arbitrary File Overwrite Vulnerability
A highly privileged account can overwrite arbitrary files on the system with log output. The log file path tags were not sanitized properly.
4.3
CVE-2024-24710 - WordPress Feed Them Social plugin <= 4.2.0 - Broken Access Control vulnerability
Missing Authorization vulnerability in SlickRemix Feed Them Social.This issue affects Feed Them Social: from n/a through 4.2.0.
7.6
CVE-2024-32810 - WordPress ShortPixel Critical CSS plugin <= 1.0.2 - Broken Access Control vulnerability
Missing Authorization vulnerability in ShortPixel ShortPixel Critical CSS.This issue affects ShortPixel Critical CSS: from n/a through 1.0.2.
5.3
CVE-2023-25457 - WordPress Slider Carousel β Responsive Image Slider plugin <=1.5.1 - Broken Access Control vulnerabβ¦
Missing Authorization vulnerability in Richteam Slider Carousel β Responsive Image Slider.This issue affects Slider Carousel β Responsive Image Slider: from n/a through 1.5.1.
4.3
CVE-2023-44472 - WordPress Unyson plugin <= 2.7.28 - Broken Access Control vulnerability
Missing Authorization vulnerability in ThemeFuse Unyson.This issue affects Unyson: from n/a through 2.7.28.
5.3
CVE-2024-33941 - WordPress iPanorama 360 plugin <= 1.8.1 - Broken Access Control vulnerability
Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.1.
6.5
CVE-2024-32831 - WordPress Accessibility Widget plugin <= 2.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lorna Timbah (webgrrrl) Accessibility Widget allows Stored XSS.This issue affects Accessibility Widget: from n/a through 2.2.
6.5
CVE-2024-33916 - WordPress CPO Companion plugin <= 1.1.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MachoThemes CPO Companion allows Stored XSS.This issue affects CPO Companion: from n/a through 1.1.0.