Vulnerabilities in Unknown

5,585 results
Vexday analysis

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-87840MEDIUMTripzzy < 1.5.1 - Unauthenticated Booking Data TamperingEPSS 0.3%CVE-2026-91015MEDIUMMaster Addons for Elementor < 3.1.9 - Unauthenticated Popup Deactivation via jltma_popup_disable_expiredEPSS 0.3%CVE-2026-92435MEDIUMMailchimp for WooCommerce < 6.1.1 - Unauthenticated Broken Access Control in REST APIEPSS 0.3%CVE-2026-11868MEDIUMWP Travel < 11.7.1 - Unauthenticated Arbitrary Booking CancellationEPSS 0.3%CVE-2026-103514HIGHWP 2FA < 4.1.0 - Two-Factor Authentication Bypass via TOTP Code ReplayEPSS 0.3%CVE-2026-77694MEDIUMEventin < 4.1.19 - Unauthenticated Order Completion Without Payment via order_tokenEPSS 0.3%CVE-2026-88910MEDIUMKBoard < 6.7 - Unauthenticated Board Media Deletion via IDOREPSS 0.3%CVE-2026-15229MEDIUMPinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Price ManipulationEPSS 0.3%CVE-2026-14547MEDIUMEstatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request FormEPSS 0.3%CVE-2022-1759—RB Internal Links <= 2.0.16 - Stored Cross-Site Scripting via CSRFEPSS 0.3%CVE-2026-16282MEDIUMAppointment Hour Booking < 1.5.88 - Unauthenticated Booking Price Manipulation via tcost ParameterEPSS 0.3%CVE-2026-85350MEDIUMUpsellWP < 2.2.10 - Unauthenticated Price Manipulation via Frequently Bought TogetherEPSS 0.3%CVE-2026-85123MEDIUMEasy Form Builder 4.0.0 - 4.1.3 - Unauthenticated Registration Policy Bypass via Login Form Type ConfusionEPSS 0.3%CVE-2026-14843MEDIUMEvents Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOREPSS 0.3%CVE-2026-12276MEDIUMLA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open RegistrationEPSS 0.3%CVE-2026-15237MEDIUMHotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments REST EndpointEPSS 0.3%CVE-2022-1626—Sharebar <= 1.4.1 - Arbitrary Settings Update to Stored XSS via CSRFEPSS 0.3%CVE-2026-82305MEDIUMYITH WooCommerce Wishlist < 4.18.1 - Unauthenticated Arbitrary Wishlist Rename via change_wishlist_titleEPSS 0.3%CVE-2026-77701MEDIUMWCFM Marketplace < 3.8.2 - Unauthenticated Refund Request Creation on Guest OrdersEPSS 0.3%CVE-2026-15257MEDIUMRegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile ModificationEPSS 0.3%