Vulnerabilidades en Unknown
5428 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2023-4666CRITICALForm-Maker < 1.15.20 - Unauthenticated Arbitrary File UploadEPSS 3.3%CVE-2018-17922—Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessibEPSS 3.2%CVE-2023-1408HIGHVideo List Manager <= 1.7 - Admin+ SQL InjectionEPSS 3.2%CVE-2023-0900HIGHAP Pricing Tables Lite <= 1.1.6 - Admin+ SQLiEPSS 3.2%CVE-2021-24174—Database Backups <= 1.2.2.6 - CSRF to Backup DownloadEPSS 3.2%CVE-2022-0377—LearnPress < 4.1.5 - Arbitrary Image RenamingEPSS 3.2%CVE-2023-5974—WPB Show Core <= 2.2 - Unauthenticated Server Side Request ForgeryEPSS 3.1%CVE-2021-24884—Formidable Form Builder < 4.09.05 - Unauthenticated Stored Cross-Site ScriptingEPSS 3.1%CVE-2023-4490CRITICALWP Job Portal < 2.0.6 - Unauthenticated SQLiEPSS 3.1%CVE-2022-1153—LayerSlider < 7.1.2 - Admin+ Stored Cross-Site ScriptingEPSS 3.1%CVE-2021-24947—RVM - Responsive Vector Maps < 6.4.2 - Subscriber+ Arbitrary File ReadEPSS 3.1%CVE-2021-24210—PhastPress < 1.111 - Open RedirectEPSS 3.1%CVE-2022-0953—Anti-Malware Security and Brute-Force Firewall < 4.20.96 - Reflected Cross-Site ScriptingEPSS 3.1%CVE-2022-1398—External Media without Import <= 1.1.2 - Subscriber+ Blind SSRFEPSS 3.1%CVE-2021-24820—Cost Calculator <= 1.6 - Authenticated Local File InclusionEPSS 3.0%CVE-2021-24240—Business Hours Pro <= 5.5.0 - Unauthenticated Arbitrary File Upload to RCEEPSS 3.0%CVE-2021-25036—All In One SEO < 4.1.5.3 - Authenticated Privilege EscalationEPSS 3.0%CVE-2022-1597—WPQA < 5.4 - Reflected Cross-Site ScriptingEPSS 3.0%CVE-2022-0424—Popup by Supsystic < 1.10.9 - Unauthenticated Subscriber Email Addresses DisclosureEPSS 3.0%CVE-2024-9796MEDIUMWP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL InjectionEPSS 3.0%