Vulnerabilidades en Extra Innovation Inc.
4 resultadosAnálisis Vexday
Extra Innovation Inc. apresenta footprint reduzido de 2 CVEs, sendo 1 crítica, sem evidência atual de exploração ativa no cenário. A fraqueza dominante em injeção de comando (CWE-78) indica risco de execução remota de código, porém o portfólio não apresenta vulnerabilidades recentes (90+ dias), sugerindo baixa pressão de exposição imediata.
CVE-2021-46686CRITICALImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in acmailer CGI ver.4.0.3 and earlieEPSS 1.4%CVE-2026-70408HIGHAn incorrect authorization vulnerability exists in acmailer, which may allow a user to create a sub-account that has administrative privilegEPSS 0.4%CVE-2023-49780MEDIUMCross-site scripting vulnerability exists in acmailer CGI ver.4.0.5 and earlier. An arbitrary script may be executed on the web browser of tEPSS 0.3%CVE-2026-66358MEDIUMA cross-site scripting vulnerability exists in acmailer, which may allow an attacker to execute an arbitrary script.EPSS 0.3%