Vulnerabilidades en Unknown

5492 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-16267HIGHNewsletters < 4.16 - Unauthenticated PHP Object Injection via Date Form FieldEPSS 0.5%CVE-2024-0236MEDIUMEventON (Free < 2.2.8, Premium < 4.5.5) - Unauthenticated Virtual Event Password DisclosureEPSS 0.5%CVE-2026-82925HIGHSite Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form SignatureEPSS 0.5%CVE-2026-84099HIGHIDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro paypal.phpEPSS 0.5%CVE-2024-8700HIGHEvent Calendar <= 1.0.4 - Unauthenticated Arbitrary Calendar DeletionEPSS 0.5%CVE-2024-1564MEDIUMSchema Pro < 2.7.16 - Contributor+ Custom Field AccessEPSS 0.5%CVE-2026-77693HIGHOrder Tip for WooCommerce < 1.6.0 - Shop Manager+ Arbitrary File Deletion via delete_exported_csv_file_ajaxEPSS 0.5%CVE-2026-12987HIGHEvents Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking RegistrationEPSS 0.5%CVE-2023-5942MEDIUMMedialist < 1.4.1 - Contributor+ Stored XSSEPSS 0.5%CVE-2026-76553MEDIUMWP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template Path TraversalEPSS 0.5%CVE-2024-1983HIGHSimple Ajax Chat < 20240223 - Unauthenticated Stored XSSEPSS 0.5%CVE-2023-5209—Bookly < 22.5 - Admin+ Stored XSSEPSS 0.5%CVE-2023-5119—Forminator and Forminator Pro < 1.27.0 - Admin+ Stored Cross-Site ScriptingEPSS 0.5%CVE-2021-25108—IP2Location Country Blocker < 2.26.6 - Arbitrary Country Ban via CSRFEPSS 0.5%CVE-2024-9021MEDIUMRelevanssi < 4.23.1 - Contributor+ Stored XSSEPSS 0.5%CVE-2023-5343MEDIUMPopup Box < 3.7.9 - Admin+ Stored XSSEPSS 0.5%CVE-2023-5757—WP Crowdfunding < 2.1.8 - Admin+ Stored XSSEPSS 0.5%CVE-2023-6257MEDIUMInline Related Posts < 3.6.0 - Subscriber+ Password Protected Post ReadEPSS 0.5%CVE-2026-78361CRITICALzipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Option DeletionEPSS 0.5%CVE-2026-19728HIGHExtra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Disclosure via getpublicfileuploadEPSS 0.4%