Medium - CVE-2024-12100 - The Bitcoin Lightning Publisher for WordPress...
The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all...
Medium - CVE-2024-12210 - The Print Invoice & Delivery Notes for...
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo'...
Medium - CVE-2024-12405 - The Export Customers Data plugin for WordPress...
The Export Customers Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 't' parameter in all versions up to, and including, 1.2.3 due to insufficient input...
Medium - CVE-2024-12622 - The WordPress Simple Shopping Cart plugin for...
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_cart_button' and 'wp_cart_display_product'...
NA - CVE-2024-41882 - Team ENVY, a Security Research TEAM has found a...
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker can cause a stack overflow by entering large data into URL parameters, which...
NA - CVE-2024-41883 - Team ENVY, a Security Research TEAM has found a...
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR . An attacker enters a special value for a specific URL parameter, resulting in a NULL...
NA - CVE-2024-41884 - Team ENVY, a Security Research TEAM has found a...
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. If an attacker does not enter any value for a specific URL parameter, NULL pointer...
NA - CVE-2024-41885 - Team ENVY, a Security Research TEAM has found a...
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. The seed string for the encrypt key was hardcoding. The manufacturer has released patch...
NA - CVE-2024-41886 - Team ENVY, a Security Research TEAM has found a...
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. An attacker could inject malformed data into url input parameters to reboot the NVR. The...