Vulnerabilities in unknown

5,484 results
Vexday analysis

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2021-24628—Wow Forms <= 3.1.3 - Admin+ SQL InjectionEPSS 1.5%CVE-2021-24629—Post Content XMLRPC <= 1.0 - Admin+ SQL InjectionsEPSS 1.5%CVE-2026-2025HIGHMail Mint < 1.19.5 - Unauthenticated Emails DisclosureEPSS 1.5%CVE-2022-0478—Event Manager for WooCommerce < 3.5.8 - Contributor+ SQL InjectionEPSS 1.5%CVE-2022-0828—Download Manager < 3.2.39 - Unauthenticated brute force of files master keyEPSS 1.5%CVE-2021-24511—Create WooCommerce Product Feeds For 40+ Merchants < 3.3.1.0 - Authenticated SQL InjectionEPSS 1.5%CVE-2021-24844—Affiliate Manager < 2.8.7 - Admin+ SQL injectionEPSS 1.5%CVE-2020-35012—Events Manager < 5.9.8 - Admin+ SQL InjectionEPSS 1.5%CVE-2021-24834—YOP Poll < 6.3.1 - Author+ Stored Cross-Site Scripting via Options ModuleEPSS 1.5%CVE-2022-0230—Better WordPress Google XML Sitemaps <= 1.4.1 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.5%CVE-2026-10823HIGHYMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post DisclosureEPSS 1.5%CVE-2022-1683—amtyThumb <= 4.2.0 - Subscriber+ SQLiEPSS 1.5%CVE-2026-13153HIGHEssential Blocks < 6.4.0 - Unauthenticated WooCommerce Sales Data Disclosure via REST products EndpointEPSS 1.5%CVE-2021-25107—Form Store to DB < 1.1.1 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.5%CVE-2021-25002—Tipsacarrier < 1.5.0.5 - Unauthenticated Orders DisclosureEPSS 1.5%CVE-2022-3076HIGHCM Download Manager < 2.8.6 - Admin+ Arbitrary File UploadEPSS 1.5%CVE-2023-1406HIGHJetEngine < 3.1.3.1 - Author+ Remote Code ExecutionEPSS 1.5%CVE-2022-1539—Exports and Reports < 0.9.2 - Contributor+ CSV InjectionEPSS 1.5%CVE-2022-0411—Asgaros Forum < 2.0.0 - Subscriber+ Blind SQL InjectionEPSS 1.5%CVE-2021-24398—Responsive 3D Slider <= 1.2 - Authenticated SQL InjectionEPSS 1.5%