Vulnerabilities in unknown

5,484 results
Vexday analysis

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2022-3904MEDIUMMonsterInsights < 8.9.1 - Stored Cross-Site Scripting via Google AnalyticsEPSS 1.3%CVE-2021-24345—Sendit WP Newsletter <= 2.5.1 - Authenticated (admin+) SQL InjectionEPSS 1.3%CVE-2021-24717—AutomatorWP < 1.7.6 - Missing Authorization and Privilege EscalationEPSS 1.3%CVE-2021-24606—Availability Calendar < 1.2.1 - Authenticated SQL InjectionEPSS 1.3%CVE-2021-24975—NextScripts: Social Networks Auto-Poster < 4.3.24 - Unauthenticated Stored XSSEPSS 1.3%CVE-2021-24835—WCFM - Frontend Manager for WooCommerce < 6.5.12 - Customer/Subscriber+ SQL InjectionEPSS 1.3%CVE-2021-24758—Email Log < 2.4.7 - Admin+ SQL InjectionEPSS 1.3%CVE-2022-1037—EXMAGE < 1.0.7 - Admin+ Blind SSRFEPSS 1.3%CVE-2021-24669—MAZ Loader < 1.3.3 - Contributor+ SQL InjectionEPSS 1.3%CVE-2022-2593—Better Search and Replace < 1.4.1 - Admin+ SQLiEPSS 1.3%CVE-2023-5939—rtMedia for WordPress, BuddyPress and bbPress < 4.6.16 - Admin+ RCEEPSS 1.3%CVE-2023-4861HIGHFile Manager Pro < 1.8.1 - Admin+ Remote Code ExecutionEPSS 1.3%CVE-2022-2599—Anti-Malware Security and Brute-Force Firewall < 4.21.83 - Reflected Cross-Site ScriptingEPSS 1.3%CVE-2022-3463CRITICALFluentForm < 4.3.13 - CSV InjectionEPSS 1.3%CVE-2022-1123—Leaflet Maps Marker < 3.12.5 - Admin+ SQLiEPSS 1.3%CVE-2021-25064—Wow Countdowns <= 3.1.2 - Admin+ SQLiEPSS 1.3%CVE-2022-1182—Visual Slide Box Builder <= 3.2.9 - Subscriber+ SQLiEPSS 1.3%CVE-2021-24756—WP System Log < 1.0.21 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.3%CVE-2021-25086—Advanced Page Visit Counter < 6.1.2 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.3%CVE-2021-24689—Contact Forms - Drag & Drop Contact Form Builder <= 1.0.5 - Admin+ Arbitrary System File ReadEPSS 1.3%