Vulnerabilities in unknown

4,752 results
Vexday analysis

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2022-0901Ad Inserter < 2.7.12 - Reflected Cross-Site ScriptingEPSS 3.5%CVE-2021-24498Calendar Event Multi View < 1.4.01 - Unauthenticated Reflected Cross-Site Scripting (XSS)EPSS 3.5%CVE-2021-24217Facebook for WordPress < 3.0.0 - PHP Object Injection with POP ChainEPSS 3.5%CVE-2023-4278HIGHMasterStudy LMS < 3.0.18 - Unauthenticated Instructor Account CreationEPSS 3.5%CVE-2021-25052Button Generator < 2.3.3 - RFI leading to RCE via CSRFEPSS 3.4%CVE-2021-24148MStore API < 3.2.0 - Authentication Bypass With Sign In With AppleEPSS 3.4%CVE-2024-4620CRITICALArForms < 6.6 - Unauthenticated RCEEPSS 3.3%CVE-2021-24495Marmoset Viewer < 1.9.3 - Reflected Cross Site ScriptingEPSS 3.3%CVE-2022-2544Ninja Job Board < 1.3.3 - Resume Disclosure via Directory ListingEPSS 3.3%CVE-2023-0232CRITICALShopLentor < 2.5.4 - PHP Object InjectionEPSS 3.3%CVE-2022-0246iQ Block Country < 1.2.13 - Admin+ Arbitrary File Deletion via Zip SlipEPSS 3.3%CVE-2023-5991Hotel Booking Lite < 4.8.5 - Unauthenticated Arbitrary File Download & DeletionEPSS 3.3%CVE-2021-24329WP Super Cache < 1.7.3 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 3.3%CVE-2024-0566HIGHSmart Manager < 8.28.0 - Admin+ SQL InjectionEPSS 3.3%CVE-2024-6926CRITICALViral Signup <= 2.1 - Unauthenticated SQLiEPSS 3.3%CVE-2024-6924CRITICALTrueBooker < 1.0.3 - Multiple Unauthenticated SQLiEPSS 3.3%CVE-2024-6928CRITICALOpti Marketing <= 2.0.9 - Unauthenticated SQLiEPSS 3.3%CVE-2023-4666CRITICALForm-Maker < 1.15.20 - Unauthenticated Arbitrary File UploadEPSS 3.3%CVE-2018-17922Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessibEPSS 3.2%CVE-2023-1408HIGHVideo List Manager <= 1.7 - Admin+ SQL InjectionEPSS 3.2%