Vulnerabilidades en Unknown

5428 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2023-0224CRITICALGiveWP < 2.24.1 - Unauthenticated SQLiEPSS 3.7%CVE-2018-17916InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote EPSS 3.7%CVE-2021-24376Autoptimize < 2.7.8 - Arbitrary File Upload via "Import Settings"EPSS 3.7%CVE-2022-0901Ad Inserter < 2.7.12 - Reflected Cross-Site ScriptingEPSS 3.6%CVE-2022-4297CRITICALWP AutoComplete Search <= 1.0.4 - Unauthenticated SQLiEPSS 3.6%CVE-2021-24498Calendar Event Multi View < 1.4.01 - Unauthenticated Reflected Cross-Site Scripting (XSS)EPSS 3.5%CVE-2022-2711HIGHWP All Import < 3.6.9 - Admin+ Directory traversal via file uploadEPSS 3.5%CVE-2021-24217Facebook for WordPress < 3.0.0 - PHP Object Injection with POP ChainEPSS 3.5%CVE-2022-4953Elementor < 3.5.5 - Iframe InjectionEPSS 3.4%CVE-2022-2379Easy Student Results <= 2.2.8 - Sensitive Information Disclosure via REST APIEPSS 3.4%CVE-2021-24148MStore API < 3.2.0 - Authentication Bypass With Sign In With AppleEPSS 3.4%CVE-2022-0246iQ Block Country < 1.2.13 - Admin+ Arbitrary File Deletion via Zip SlipEPSS 3.4%CVE-2024-4620CRITICALArForms < 6.6 - Unauthenticated RCEEPSS 3.3%CVE-2021-24495Marmoset Viewer < 1.9.3 - Reflected Cross Site ScriptingEPSS 3.3%CVE-2023-0232CRITICALShopLentor < 2.5.4 - PHP Object InjectionEPSS 3.3%CVE-2023-5991Hotel Booking Lite < 4.8.5 - Unauthenticated Arbitrary File Download & DeletionEPSS 3.3%CVE-2024-0566HIGHSmart Manager < 8.28.0 - Admin+ SQL InjectionEPSS 3.3%CVE-2024-6926CRITICALViral Signup <= 2.1 - Unauthenticated SQLiEPSS 3.3%CVE-2024-6924CRITICALTrueBooker < 1.0.3 - Multiple Unauthenticated SQLiEPSS 3.3%CVE-2024-6928CRITICALOpti Marketing <= 2.0.9 - Unauthenticated SQLiEPSS 3.3%