Vulnerabilities in unknown
4,715 resultsVexday analysis
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2021-24666—Podlove Podcast Publisher < 3.5.6 - Unauthenticated SQL InjectionEPSS 8.9%CVE-2022-0787—Limit Login Attempts (Spam Protection) < 5.1 - Unauthenticated SQLiEPSS 8.9%CVE-2022-0846—SpeakOut! Email Petitions < 2.14.15.1 - Unauthenticated SQLiEPSS 8.8%CVE-2022-0658—CommonsBooking < 2.6.8 - Unauthenticated SQL InjectionEPSS 8.6%CVE-2022-1903—ARMember < 3.4.8 - Unauthenticated Admin Account TakeoverEPSS 8.6%CVE-2022-0769—Users Ultra <= 3.1.0 - Unauthenticated SQL InjectionEPSS 8.5%CVE-2021-24849—WCFM - WooCommerce Multivendor Marketplace < 3.4.12 - Unauthenticated SQL InjectionEPSS 8.5%CVE-2023-1938HIGHWP Fatest Cache < 1.1.5 - Blind SSRF via CSRFEPSS 8.5%CVE-2021-24579—Bold Page Builder < 3.1.6 - PHP Object InjectionEPSS 8.2%CVE-2015-20067—WP Attachment Export < 0.2.4 - Unauthenticated Posts DownloadEPSS 8.2%CVE-2022-0422—White Label MS < 2.2.9 - Reflected Cross-Site ScriptingEPSS 8.1%CVE-2022-0788—WP Fundraising Donation and Crowdfunding Platform < 1.5.0 - Unauthenticated SQLiEPSS 8.0%CVE-2022-1057—Pricing Deals for WooCommerce <= 2.0.2.02 - Unauthenticated SQLiEPSS 7.9%CVE-2021-24212—WooCommerce Help Scout < 2.9.1 - Unauthenticated Arbitrary File Upload leading to RCEEPSS 7.9%CVE-2022-0656—uDraw < 3.3.3 - Unauthenticated Arbitrary File AccessEPSS 7.9%CVE-2022-0949—WP Block and Stop Bad Bots < 6.930 - Unauthenticated SQLiEPSS 7.9%CVE-2022-0783—Multiple Shipping Address Woocommerce < 2.0 - Unauthenticated SQLiEPSS 7.8%CVE-2021-24527—Profile Builder < 3.4.9 - Admin Access via Password ResetEPSS 7.7%CVE-2022-1013—Personal Dictionary < 1.3.4 - Unauthenticated SQLiEPSS 7.7%CVE-2023-3219—EventON < 2.1.2 - Unauthenticated Post Access via IDOREPSS 7.5%