Vulnerabilities in unknown
5,492 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2021-24558—Project Status <= 1.6 - Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2021-24698—Simple Download Monitor < 3.9.6 - Arbitrary Thumbnails RemovalEPSS 0.7%CVE-2022-1512—ScrollReveal.js Effects <= 1.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-24346—Stock in & out <= 1.0.4 - Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2021-25061—WP Booking System – Booking Calendar < 2.0.15 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2024-5630HIGHInsert or Embed Articulate Content into WordPress < 4.3000000024 - Author+ Arbitrary File UploadEPSS 0.7%CVE-2022-0775MEDIUMWooCommerce < 6.2.1 - Subscriber+ Arbitrary Comment DeletionEPSS 0.7%CVE-2021-24911—Transposh WordPress Translation < 1.0.8 - Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-1581MEDIUMWP-Polls < 2.76.0 - IP Validation BypassEPSS 0.7%CVE-2021-24961—WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via ShortcodeEPSS 0.7%CVE-2021-24960—WordPress File Upload < 4.16.3 - Contributor+ Stored Cross-Site Scripting via Malicious SVGEPSS 0.7%CVE-2026-84171CRITICALWP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File UploadEPSS 0.7%CVE-2026-14289CRITICALWP FacturaONE < 5.37 - Unauthenticated Remote Code ExecutionEPSS 0.7%CVE-2026-14602CRITICALRemote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query ParameterEPSS 0.7%CVE-2021-24633—Countdown Block < 1.1.2 - Missing Authorisation in AJAX actionEPSS 0.7%CVE-2021-24561—WP SMS < 5.4.13 - Authenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-4417MEDIUMWP Cerber < 9.3.3 - User Enumeration Bypass via Rest APIEPSS 0.7%CVE-2024-8699HIGHZ-Downloads < 1.11.5 - Admin+ Arbitrary File UploadEPSS 0.7%CVE-2021-25053—WP Coder < 2.5.2 - RFI leading to RCE via CSRFEPSS 0.7%CVE-2024-2908MEDIUMCall Now Button < 1.4.7 - Admin+ Stored XSSEPSS 0.7%