Vulnerabilities in Unknown

5,428 results
Vexday analysis

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2021-25052—Button Generator < 2.3.3 - RFI leading to RCE via CSRFEPSS 3.0%CVE-2021-24719—Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)EPSS 3.0%CVE-2022-1192—Turn off all comments <= 1.0 - Reflected Cross-Site ScriptingEPSS 2.9%CVE-2022-4140HIGHWelcart e-Commerce < 2.8.5 - Unauthenticated Arbitrary File AccessEPSS 2.9%CVE-2021-24235—Goto - Tour & Travel < 2.0 - Unauthenticated Reflected XSSEPSS 2.9%CVE-2021-25120—Easy Social Feed < 6.2.7 - Reflected Cross-Site ScriptingEPSS 2.9%CVE-2022-1595—HC Custom WP-Admin URL <= 1.4 - Unauthenticated Secret URL DisclosureEPSS 2.9%CVE-2024-0399HIGHWooCommerce Customers Manager < 29.7 - Subscriber+ SQL InjectionEPSS 2.9%CVE-2022-0142—Visual Form Builder < 3.0.6 - CSV InjectionEPSS 2.9%CVE-2021-24773—WordPress Download Manager < 3.2.16 - Admin+ Stored Cross-Site ScriptingEPSS 2.9%CVE-2024-6244HIGHpz-frontend-manager < 1.0.6 - CSRF change user profile pictureEPSS 2.8%CVE-2021-24962—WordPress File Upload < 4.16.3 - Contributor+ Path Traversal to RCEEPSS 2.8%CVE-2022-0994—Hummingbird < 3.3.2 - Admin+ Stored Cross-Site ScriptingEPSS 2.8%CVE-2023-5559—10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option DeletionEPSS 2.8%CVE-2024-6159CRITICALPush Notification for Post and BuddyPress <=1.93 - Multiple Unauthenticated SQLiEPSS 2.8%CVE-2021-24596—youForms for WordPress <= 1.0.5 - Authenticated Stored Cross-Site ScriptingEPSS 2.8%CVE-2021-24997—WP Guppy < 1.3 - Sensitive Information DisclosureEPSS 2.8%CVE-2021-24510—MF Gig Calendar < 1.2 - Reflected Cross-Site Scripting (XSS)EPSS 2.7%CVE-2018-3892CRITICALAn exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafteEPSS 2.7%CVE-2022-2846MEDIUMCalendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSSEPSS 2.6%