Vulnerabilities in unknown
5,484 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2021-24444—TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 2.3%CVE-2021-25033—Noptin < 1.6.5 - Open RedirectEPSS 2.3%CVE-2021-24358—The Plus Addons for Elementor Page Builder < 4.1.10 - Open RedirectEPSS 2.3%CVE-2022-0212—SpiderCalendar <= 1.5.65 - Reflected Cross-Site ScriptingEPSS 2.3%CVE-2024-9186HIGHAutomation By Autonami < 3.3.0 - Unauthenticated SQLiEPSS 2.3%CVE-2021-25078—Affiliates Manager < 2.9.0 - Unauthenticated Stored Cross-Site ScriptingEPSS 2.3%CVE-2022-1560—Amministrazione Aperta < 3.8 - Admin+ LFIEPSS 2.3%CVE-2023-7164HIGHBackWPup < 4.0.4 - Unauthenticated Backup DownloadEPSS 2.3%CVE-2021-25008—Code Snippets < 2.14.3 - Reflected Cross-Site ScriptingEPSS 2.3%CVE-2018-3935HIGHAn exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted setEPSS 2.3%CVE-2021-24959—WP Email Users <= 1.7.6 - Subscriber+ SQL InjectionEPSS 2.2%CVE-2021-24746—Sassy Social Share < 3.3.40 - Reflected Cross-Site ScriptingEPSS 2.2%CVE-2024-6486HIGHImageMagick Engine < 1.7.11 - Administrator+ OS Command InjectionEPSS 2.2%CVE-2022-0189—WP RSS Aggregator < 4.20 - Reflected Cross-Site Scripting (XSS)EPSS 2.2%CVE-2023-5089MEDIUMDefender Security < 4.1.0 - Protection Bypass (Hidden Login Page)EPSS 2.2%CVE-2021-24838—AnyComment < 0.3.5 - Open RedirectEPSS 2.2%CVE-2021-24223—N5 Upload Form <= 1.0 - Unauthenticated Arbitrary File Upload to RCEEPSS 2.2%CVE-2023-5203HIGHWP Sessions Time Monitoring Full Automatic < 1.0.9 - Unauthenticated SQL injectionEPSS 2.2%CVE-2023-2606—WP Brutal AI < 2.06 - Admin+ Stored XSSEPSS 2.2%CVE-2021-25112—WHMCS Bridge < 6.4b - Reflected Cross-Site Scripting (XSS)EPSS 2.2%