Vulnerabilities in Unknown
5,591 resultsVexday analysis
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2025-14545MEDIUMYML for Yandex Market < 5.0.26 - Shop Manager+ RCE via Feed GenerationEPSS 0.3%CVE-2022-1617MEDIUMWP-Invoice <= 4.3.1 - Stored Cross-Site Scripting via CSRFEPSS 0.3%CVE-2024-12708HIGHBulk Me Now <= 2.0 - Stored XSS via ShortcodeEPSS 0.3%CVE-2026-19416MEDIUMKiviCare < 4.5.4 - Patient+ Cross-Patient Appointment Modification via IDOREPSS 0.3%CVE-2025-15386HIGHResponsive Lightbox & Gallery < 2.6.1 - Unauthenticated Stored XSSEPSS 0.3%CVE-2023-2495—Greeklish-permalink < 3.5 - Unauthenticated Post Slug UpdateEPSS 0.3%CVE-2026-77790MEDIUMRegistrationMagic < 6.0.9.4 - Admin+ SQLi via 'rm_sortby' ParameterEPSS 0.3%CVE-2026-14189LOWWPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fieldsEPSS 0.3%CVE-2026-91020MEDIUMWebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulation via wt_credit_amountEPSS 0.3%CVE-2025-10124MEDIUMBooking Manager < 2.1.15 - Contributor+ Booking DeletionEPSS 0.3%CVE-2024-4758HIGHMuslim Prayer Time BD <= 2.4 - Settings Reset via CSRFEPSS 0.3%CVE-2025-7022MEDIUMMy Reservation System <= 2.3 - Reflected XSSEPSS 0.3%CVE-2025-15693LOWJCH Optimize 4.2.1 - 5.0.0 - Admin+ Path TraversalEPSS 0.3%CVE-2024-6230MEDIUMPardakht Delkhah <= 2.9.8 - Form Fields Reset via CSRFEPSS 0.3%CVE-2025-13820MEDIUMComments – wpDiscuz < 7.6.40 - Unauthenticated Account TakeoverEPSS 0.3%CVE-2024-0677MEDIUMPz-LinkCard <= 2.5.1 - Contributor+ SSRFEPSS 0.3%CVE-2026-75799CRITICALYAHMAN Add-ons < 0.9.31 - Unauthenticated Arbitrary File Upload via Blog Card CacheEPSS 0.3%CVE-2025-5526MEDIUMBuddyPress Docs < 2.2.5 - Subscriber+ Arbitrary Document Read/UpdateEPSS 0.3%CVE-2024-9230MEDIUMPowerPress Podcasting < 11.9.18 - Author+ XSS via Podcast URLEPSS 0.3%CVE-2026-14862LOWSupport Genix Lite < 1.4.48 - Unauthenticated Ticket Attachment Download via Missing AuthorizationEPSS 0.3%