Vulnerabilities in unknown

5,484 results
Vexday analysis

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2021-24551—Edit Comments <= 0.3 - Unauthenticated SQL InjectionEPSS 1.9%CVE-2022-2535—SearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title DisclosureEPSS 1.9%CVE-2021-25111—English WordPress Admin < 1.5.2 - Unauthenticated Open RedirectEPSS 1.9%CVE-2021-24224—Easy Form Builder <= 1.0 - Authenticated Arbitrary File UploadEPSS 1.9%CVE-2021-24253—Classyfrieds <= 3.8 - Authenticated Arbitrary File Upload to RCEEPSS 1.9%CVE-2021-24171—WooCommerce Upload Files < 59.4 - Unauthenticated Arbitrary File UploadEPSS 1.9%CVE-2025-1232HIGHSite Reviews < 7.2.5 - Unauthenticated Stored XSSEPSS 1.9%CVE-2021-24363—Photo Gallery < 1.5.75 - File Upload Path TraversalEPSS 1.9%CVE-2021-24221—Quiz And Survey Master < 7.1.12 - Authenticated SQL injection via shortcodeEPSS 1.9%CVE-2021-24228—Patreon WordPress < 1.7.2 - Reflected XSS on Login FormEPSS 1.9%CVE-2021-24979—Paid Memberships Pro < 2.6.6 - Reflected Cross-Site ScriptingEPSS 1.9%CVE-2022-1007—Advanced Booking Calendar < 1.7.1 - Reflected Cross-Site ScriptingEPSS 1.9%CVE-2022-2373—Simply Schedule Appointments < 1.5.7.7 - Unauthenticated Email Address DisclosureEPSS 1.9%CVE-2022-0694—Advanced Booking Calendar < 1.7.0 - Unauthenticated SQL InjectionEPSS 1.8%CVE-2022-1724—Simple Membership < 4.1.1 - Reflected Cross-Site ScriptingEPSS 1.8%CVE-2022-1168—JobSearch < 1.5.1 - Unauthenticated Reflected Cross-Site Scripting (XSS)EPSS 1.8%CVE-2025-11307HIGHWP Google Maps < 9.0.48 - Unauthenticated Stored XSSEPSS 1.8%CVE-2021-24254—College Publisher Import <= 0.1 - Arbitrary File Upload to RCEEPSS 1.8%CVE-2021-24857—ToTop Link <= 1.7.1 - Unauthenticated PHP Object InjectionEPSS 1.8%CVE-2022-2376—Directorist < 7.3.1 - Unauthenticated Email Address DisclosureEPSS 1.8%