NA - CVE-2024-41884 - Team ENVY, a Security Research TEAM has found a...
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. If an attacker does not enter any value for a specific URL parameter, NULL pointer...
NA - CVE-2024-41885 - Team ENVY, a Security Research TEAM has found a...
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. The seed string for the encrypt key was hardcoding. The manufacturer has released patch...
NA - CVE-2024-41886 - Team ENVY, a Security Research TEAM has found a...
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker could inject malformed data into url input parameters to reboot the NVR. The...
NA - CVE-2024-41887 - Team ENVY, a Security Research TEAM has found a...
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can create an NVR log file in a directory one level higher on the system, which...
Medium - CVE-2024-12814 - The Loan Comparison plugin for WordPress is...
The Loan Comparison plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'loancomparison' shortcode in all versions up to, and including, 2.0 due to...
Medium - CVE-2024-11896 - The Text Prompter – Unlimited chatgpt text...
The Text Prompter – Unlimited chatgpt text prompts for openai tasks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'text_prompter' shortcode in...
Medium - CVE-2024-12468 - The WP Datepicker plugin for WordPress is...
The WP Datepicker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpdp_get_selected_datepicker' parameter in all versions up to, and including, 2.1.4 due to...
Medium - CVE-2024-12031 - The Advanced Floating Content plugin for...
The Advanced Floating Content plugin for WordPress is vulnerable to SQL Injection via the 'floating_content_duplicate_post' function in all versions up to, and including, 3.8.2 due to...
Medium - CVE-2024-12103 - The Content No Cache: prevent specific content...
The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.1.2 via the eos_dyn_get_content...
Medium - CVE-2024-12850 - The Database Backup and check Tables Automated...
The Database Backup and check Tables Automated With Scheduler 2024 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.32 via the...