Vulnerabilities in Unknown
5,591 resultsVexday analysis
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2022-3451MEDIUMProduct Stock Manager < 1.0.5 - Subscriber+ Unauthorised AJAX CallsEPSS 0.3%CVE-2022-4124MEDIUMPopup Manager <= 1.6.6 - Unauthenticated Arbitrary Popup DeletionEPSS 0.3%CVE-2026-14559CRITICALTeddy Bear Customize Addon <= 1.0.5 - Unauthenticated Account TakeoverEPSS 0.3%CVE-2026-16061HIGHRest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name}EPSS 0.3%CVE-2026-86609HIGHDownload Manager Pro < 7.5.6 - Unauthenticated Stored XSS via Email Lock SubscriptionEPSS 0.3%CVE-2022-4745MEDIUMWP Customer Area < 8.1.4 - Unauthorised Actions via CSRFEPSS 0.3%CVE-2026-88783HIGHKubio AI Page Builder < 2.9.3 - Unauthenticated Stored XSS via Comment ContentEPSS 0.3%CVE-2022-3149MEDIUMWP Custom Cursors < 3.0.1 - Stored Cross-Site Scripting via CSRFEPSS 0.3%CVE-2025-11237MEDIUMMake Email Customizer for WooCommerce <= 1.0.6 - Subscriber+ Arbitrary Options UpdateEPSS 0.3%CVE-2026-85573HIGHAll in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SVG UploadEPSS 0.3%CVE-2024-4532MEDIUMBusiness Card <= 1.0.0 - Arbitrary Card Deletion via CSRFEPSS 0.3%CVE-2026-92994HIGHVerge3D < 4.13.1 - Unauthenticated Stored XSS via File Storage APIEPSS 0.3%CVE-2026-15383MEDIUMBlog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent HeaderEPSS 0.3%CVE-2026-15931MEDIUMSimple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber NameEPSS 0.3%CVE-2026-75793MEDIUMSureCart < 4.7.0 - Unauthenticated Account Creation with Automatic LoginEPSS 0.3%CVE-2026-16535MEDIUMLink Library < 7.9.4 - Reflected XSS via Thumbs-Rating likelabelEPSS 0.3%CVE-2026-15032MEDIUMwpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL ConversionEPSS 0.3%CVE-2026-14561MEDIUMAuthora - Easy Login with Mobile Number < 1.7.7 - Unauthenticated Account Takeover via OTP DisclosureEPSS 0.3%CVE-2026-14592MEDIUMWP Real IP-based Access Control <= 1.3.1 - Unauthenticated Stored XSS via acl_ctrl_addrEPSS 0.3%CVE-2026-10824MEDIUMMasteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and DeletionEPSS 0.3%