Vulnerabilities in unknown

5,492 results
Vexday analysis

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2021-24127—ThirstyAffiliates < 3.9.3 - Authenticated Stored XSSEPSS 0.7%CVE-2023-5239—Security & Malware scan by CleanTalk < 2.121 - IP SpoofingEPSS 0.7%CVE-2024-13628MEDIUMWP Pricing Table <= 1.1 - Reflected XSSEPSS 0.7%CVE-2021-24450—ProfilePress < 3.1.8 - Authenticated Stored XSSEPSS 0.7%CVE-2024-6809CRITICALSimple Video Directory < 1.4.3 - Unauthenticated SQLiEPSS 0.7%CVE-2021-24330—Funnel Builder by CartFlows < 1.6.13 - Authenticated Stored XSS via FB Pixel ID and Google Analytics IDEPSS 0.7%CVE-2021-24331—Smooth Scroll Page Up/Down Buttons < 1.4 - Authenticated Stored XSSEPSS 0.7%CVE-2023-5177MEDIUMVrm 360 3D Model Viewer <= 1.2.1 - Full Path DisclosureEPSS 0.7%CVE-2021-24309—Weekly Schedule < 3.4.3 - Authenticated Stored XSSEPSS 0.7%CVE-2021-24412—Html5 Audio Player < 2.1.3 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-24760—Gutenberg PDF Viewer Block < 1.0.1 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-25084—Advanced Cron Manager - Subscriber+ Arbitrary Events/Schedules Creation/DeletionEPSS 0.7%CVE-2021-24413—Easy Twitter Feed < 1.2 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-24732—Dflip Lite < 1.7.10 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-24682—Cool Tag Cloud < 2.26 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-24734—Compact WP Audio Player < 1.9.7 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-24716—Modern Events Calendar Lite < 5.22.3 - Authenticated Stored Cross Site ScriptingEPSS 0.7%CVE-2021-24723—WP Reactions Lite < 1.3.6 - Authenticated Stored Cross Site ScriptingEPSS 0.7%CVE-2021-24672—One User Avatar < 2.3.7 - Contributor+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-4824MEDIUMWP Blog and Widget < 2.3.1 - Contributor+ Stored XSS via ShortcodeEPSS 0.6%