Vulnerabilidades en Unknown
5492 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2026-16298CRITICALFoodBoxBooker < 1.0.7 - Unauthenticated Arbitrary Password ResetEPSS 0.5%CVE-2026-16256CRITICALPouco Import Users <= 1.0.0 - Unauthenticated Privilege EscalationEPSS 0.5%CVE-2026-81648CRITICALCryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings Update via Unguarded AJAX RouterEPSS 0.5%CVE-2026-75860CRITICALJSON Options <= 0.0.4 - Unauthenticated Arbitrary Options UpdateEPSS 0.5%CVE-2026-85681CRITICALWP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Blog Option UpdateEPSS 0.5%CVE-2026-78362CRITICALSEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key AuthenticationEPSS 0.5%CVE-2026-18366CRITICALEvents Manager < 7.4.1 - Unauthenticated Privilege Escalation to AdministratorEPSS 0.5%CVE-2026-16299CRITICALSingle Sign On For TNG < 2.2.0 - Unauthenticated Arbitrary Password ResetEPSS 0.5%CVE-2026-16300CRITICALChama < 1.0.13 - Unauthenticated Arbitrary User Password ResetEPSS 0.5%CVE-2026-77000CRITICALWP Social Media Login <= 1.0.6 - Unauthenticated Account Takeover via Twitter Login FlowEPSS 0.5%CVE-2026-18776CRITICALTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Account Takeover via Multiple AJAX ActionsEPSS 0.5%CVE-2026-9810CRITICALAI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation via MCP OAuthEPSS 0.5%CVE-2026-77002CRITICALSmilePass Selfie Login <= 1.0.2 - Unauthenticated Authentication BypassEPSS 0.5%CVE-2023-0816MEDIUMFormidable Forms < 6.1 - IP SpoofingEPSS 0.5%CVE-2026-18031CRITICALTabaPay Gateway <= 1.4.0 - Unauthenticated Account Takeover via Payment CallbackEPSS 0.5%CVE-2026-12492CRITICALHappy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_userEPSS 0.5%CVE-2026-86710CRITICALLogin with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' ParameterEPSS 0.5%CVE-2026-14182CRITICALCustomer Email Verification for WooCommerce < 3.2.6 - Unauthenticated Account Takeover via Type-Juggling Authentication BypassEPSS 0.5%CVE-2026-86707CRITICALPrivate Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' ParameterEPSS 0.5%CVE-2026-14545CRITICALTrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password ResetEPSS 0.5%