Vulnerabilities in Unknown
5,533 resultsVexday analysis
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2022-0616—Amelia < 1.0.46 - Arbitrary Customer Deletion via CSRFEPSS 0.4%CVE-2021-24818—WP Limits <= 1.0 - Plugin's Settings Update via CSRFEPSS 0.4%CVE-2021-24780—Single Post Exporter <= 1.1.1 - Plugin's Settings Update via CSRFEPSS 0.4%CVE-2024-6879MEDIUMQuiz and Survey Master (QSM) < 9.1.1 - Contributor+ Stored XSSEPSS 0.4%CVE-2021-24805—DW Question & Answer Pro <= 1.3.4 - Multiple CSRFEPSS 0.4%CVE-2026-81766MEDIUMReally Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation via rsp_upgrade_install_pluginEPSS 0.4%CVE-2024-3748MEDIUMSP Project & Document Manager <= 4.71 - Data Update via IDOREPSS 0.4%CVE-2026-14206HIGHHT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data DisclosureEPSS 0.4%CVE-2026-16602HIGHContent Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure via Captcha REST EndpointEPSS 0.4%CVE-2026-10735HIGHShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update ServerEPSS 0.4%CVE-2026-16603HIGHContent Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST APIEPSS 0.4%CVE-2026-19717HIGHCatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST APIEPSS 0.4%CVE-2026-13154HIGHEssential Blocks < 6.4.0 - Unauthenticated Non-Public Custom Post Type Content Disclosure via queries EndpointEPSS 0.4%CVE-2026-77007HIGHHEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated BigBlueButton API Secret DisclosureEPSS 0.4%CVE-2026-77016CRITICALWorkeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion via Candidate Profile Mass AssignmentEPSS 0.4%CVE-2026-18470HIGHLogin & Register Forms < 4.0.2 - Unauthenticated Registered User Email Address Disclosure via Lost Password ResponseEPSS 0.4%CVE-2026-14925HIGHImport WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File DownloadEPSS 0.4%CVE-2026-18357HIGHWPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data DisclosureEPSS 0.4%CVE-2026-15236HIGHGallery for Google Photos < 1.2.1 - Unauthenticated Google OAuth Token DisclosureEPSS 0.4%CVE-2026-92404HIGHMgoSync 2.1.5 - 2.1.6 - Unauthenticated WooCommerce API Credential DisclosureEPSS 0.4%