Vulnerabilities in unknown
4,752 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2023-1408HIGHVideo List Manager <= 1.7 - Admin+ SQL InjectionEPSS 3.2%CVE-2021-24174—Database Backups <= 1.2.2.6 - CSRF to Backup DownloadEPSS 3.2%CVE-2022-2711HIGHWP All Import < 3.6.9 - Admin+ Directory traversal via file uploadEPSS 3.2%CVE-2022-0377—LearnPress < 4.1.5 - Arbitrary Image RenamingEPSS 3.2%CVE-2023-5974—WPB Show Core <= 2.2 - Unauthenticated Server Side Request ForgeryEPSS 3.1%CVE-2023-4490CRITICALWP Job Portal < 2.0.6 - Unauthenticated SQLiEPSS 3.1%CVE-2021-24884—Formidable Form Builder < 4.09.05 - Unauthenticated Stored Cross-Site ScriptingEPSS 3.1%CVE-2021-24210—PhastPress < 1.111 - Open RedirectEPSS 3.1%CVE-2022-1398—External Media without Import <= 1.1.2 - Subscriber+ Blind SSRFEPSS 3.1%CVE-2021-24820—Cost Calculator <= 1.6 - Authenticated Local File InclusionEPSS 3.0%CVE-2021-24240—Business Hours Pro <= 5.5.0 - Unauthenticated Arbitrary File Upload to RCEEPSS 3.0%CVE-2022-0953—Anti-Malware Security and Brute-Force Firewall < 4.20.96 - Reflected Cross-Site ScriptingEPSS 3.0%CVE-2022-0424—Popup by Supsystic < 1.10.9 - Unauthenticated Subscriber Email Addresses DisclosureEPSS 3.0%CVE-2021-24947—RVM - Responsive Vector Maps < 6.4.2 - Subscriber+ Arbitrary File ReadEPSS 3.0%CVE-2021-25036—All In One SEO < 4.1.5.3 - Authenticated Privilege EscalationEPSS 3.0%CVE-2022-1597—WPQA < 5.4 - Reflected Cross-Site ScriptingEPSS 3.0%CVE-2024-9796MEDIUMWP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL InjectionEPSS 3.0%CVE-2021-24719—Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)EPSS 3.0%CVE-2022-1192—Turn off all comments <= 1.0 - Reflected Cross-Site ScriptingEPSS 2.9%CVE-2022-4140HIGHWelcart e-Commerce < 2.8.5 - Unauthenticated Arbitrary File AccessEPSS 2.9%