Vulnerabilities in unknown

5,484 results
Vexday analysis

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2018-3934CRITICALAn exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially craftedEPSS 2.6%CVE-2023-2744—WP ERP < 1.12.4 - Admin+ SQL InjectionEPSS 2.6%CVE-2024-5522MEDIUMHTML5 Video Player < 2.5.27 - Unauthenticated SQLiEPSS 2.6%CVE-2021-24356—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Arbitrary Plugin ActivationEPSS 2.6%CVE-2020-36510—15Zine < 3.3.0 - Reflected Cross-Site ScriptingEPSS 2.6%CVE-2021-24132—Slider by 10Web < 1.2.36 - Multiple Authenticated SQL InjectionEPSS 2.6%CVE-2023-2359—Revolution Slider <= 6.6.12 - Author+ Remote Code ExecutionEPSS 2.5%CVE-2022-2034—Sensei LMS < 4.5.0 - Unauthenticated Private Messages Disclosure via Rest APIEPSS 2.5%CVE-2022-2180—GREYD.SUITE < 1.2.7 - Unauthenticated File Upload to RCEEPSS 2.5%CVE-2021-24351—The Plus Addons for Elementor < 4.1.12 - Reflected Cross-Site Scripting (XSS)EPSS 2.5%CVE-2023-6444MEDIUMSeriously Simple Podcasting < 3.0.0 - Unauthenticated Administrator Email DisclosureEPSS 2.5%CVE-2023-6421HIGHDownload Manager < 3.2.83 - Unauthenticated Protected File Download Password LeakEPSS 2.4%CVE-2021-24222—WP-Curricul Vitea Free <= 6.3 - Unauthenticated Arbitrary File Upload to RCEEPSS 2.4%CVE-2025-2558HIGHThe Wound <= 0.0.1 - Unauthenticated LFIEPSS 2.4%CVE-2021-24664—WPSchoolPress < 2.1.17 - Multiple Admin+ Stored Cross-Site ScriptingEPSS 2.4%CVE-2022-0149—WooCommerce – Store Exporter < 2.7.1 - Reflected Cross-Site Scripting (XSS)EPSS 2.3%CVE-2022-0220—WordPress GDPR & CCPA < 1.9.27 - Unauthenticated Reflected Cross-Site ScriptingEPSS 2.3%CVE-2022-0779—User Meta < 2.4.4 - Subscriber+ Local File Enumeration via Path TraversalEPSS 2.3%CVE-2024-8625HIGHTS Poll – Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL InjectionEPSS 2.3%CVE-2021-24444—TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 2.3%