Vulnerabilities in unknown
5,492 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2026-11962HIGHFileOrganizer < 1.2.0 - Authenticated Arbitrary File Upload via elFinder File OperationsEPSS 0.7%CVE-2026-77018HIGHWorkeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Upload via Candidate Profile Mass AssignmentEPSS 0.7%CVE-2026-16985HIGHSqueeze < 1.7.12 - Author+ Arbitrary File UploadEPSS 0.7%CVE-2026-8385MEDIUMWP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX FallbackEPSS 0.7%CVE-2022-1938—Awin Data Feed < 1.8 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-2189—WP Video Lightbox < 1.9.5 - Reflected Cross-Site ScriptingEPSS 0.7%CVE-2021-24794—Connections Business Directory < 10.4.3 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-4746HIGHFluentAuth < 1.0.2 - Bypass blocks by IP SpoofingEPSS 0.7%CVE-2021-24474—Awesome Weather Widget <= 3.0.2 - Reflected Cross-site Scripting (XSS)EPSS 0.7%CVE-2021-24809—BP Better Messages < 1.9.9.41 - Multiple CSRFEPSS 0.7%CVE-2021-24560—Software License Manager < 4.4.8 - Reflected Cross-Site ScriptingEPSS 0.7%CVE-2022-2369—YaySMTP < 2.2.1 - Subscriber+ Logs DisclosureEPSS 0.7%CVE-2022-2775—Fast Flow < 1.2.13 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-1563MEDIUMWPGraphQL WooCommerce <= 0.11.0 - Unauthenticated Coupon Codes Disclosure EPSS 0.7%CVE-2021-24842—Bulk Datetime Change < 1.12 - Missing AuthorisationEPSS 0.7%CVE-2023-4776HIGHWPSchoolPress < 2.2.5 - Teacher+ SQLiEPSS 0.7%CVE-2023-5645—WP Mail Log < 1.1.3 – Contributor+ SQL Injection in wml_logs endpointEPSS 0.7%CVE-2021-24355—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Update and Retrieve Wildcard ValueEPSS 0.7%CVE-2023-6064HIGHPayHere Payment Gateway < 2.2.12 - Unauthenticated Log Data DisclosureEPSS 0.7%CVE-2024-4388HIGHCAS <= 1.0.0 - Unauthenticated Arbitrary File AccessEPSS 0.7%