Vulnerabilidades en Unknown

5492 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2023-5509—myStickymenu < 2.6.5 - Subscriber+ Arbitrary Form Leads DeletionEPSS 0.5%CVE-2024-6690MEDIUMWP Content Copy Protection & No Right Click (premium) < 15.3 - Open RedirectEPSS 0.5%CVE-2023-0937MEDIUMVK All in One Expansion Unit < 9.87.1.0 - Reflected XSSEPSS 0.5%CVE-2023-1804MEDIUMProduct Catalog Feed by PixelYourSite < 2.1.1 - Reflected XSSEPSS 0.5%CVE-2021-24914—Tawk.to Live Chat < 0.6.0 - Subscriber+ Visitor Monitoring & Chat RemovalEPSS 0.5%CVE-2022-4472MEDIUMSimple Sitemap < 3.5.8 - Contributor+ Stored XSSEPSS 0.5%CVE-2022-2987HIGHLdap WP Login / Active Directory Integration < 3.0.2 - Unauthenticated Settings Update to Auth BypassEPSS 0.5%CVE-2022-3350MEDIUMContact Bank <= 3.0.30 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2024-3594HIGHIDonate <= 1.9.0 - Admin+ Stored XSSEPSS 0.5%CVE-2025-3742MEDIUMResponsive Lightbox & Gallery < 2.5.1 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-77009CRITICALWatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug ConsoleEPSS 0.5%CVE-2026-19049HIGHProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion via 'removesite' CookieEPSS 0.5%CVE-2026-14558HIGHWP User Frontend < 4.3.10 - Editor+ PHP Object Injection via AI Form BuilderEPSS 0.5%CVE-2024-1526MEDIUMHubbub Lite < 1.33.1 - Unauthenticated Password Protected Posts AccessEPSS 0.5%CVE-2026-19725CRITICALWPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_connectEPSS 0.5%CVE-2023-0479MEDIUMPrint Invoice & Delivery Notes for WooCommerce < 4.7.2 - Reflected XSS EPSS 0.5%CVE-2022-2823—Slider, Gallery, and Carousel by MetaSlider < 3.27.9 - Admin+ Stored Cross Site ScriptingEPSS 0.5%CVE-2023-7252MEDIUMTickera < 3.5.2.5 - Ticket leakage through IDOREPSS 0.5%CVE-2022-3220—Advanced Comment Form < 1.2.1 - Admin+ Authenticated Stored XSSEPSS 0.5%CVE-2022-3136—Social Rocket < 1.3.3 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%