Vulnerabilidades en Unknown

5520 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2021-24780—Single Post Exporter <= 1.1.1 - Plugin's Settings Update via CSRFEPSS 0.4%CVE-2022-0616—Amelia < 1.0.46 - Arbitrary Customer Deletion via CSRFEPSS 0.4%CVE-2026-81766MEDIUMReally Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation via rsp_upgrade_install_pluginEPSS 0.4%CVE-2024-5575MEDIUMDitty < 3.1.43 - Author+ Stored XSSEPSS 0.4%CVE-2021-24818—WP Limits <= 1.0 - Plugin's Settings Update via CSRFEPSS 0.4%CVE-2024-3628LOWEasyEvent <= 1.0.0 - Admin+ Stored XSSEPSS 0.4%CVE-2021-24805—DW Question & Answer Pro <= 1.3.4 - Multiple CSRFEPSS 0.4%CVE-2026-18357HIGHWPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data DisclosureEPSS 0.4%CVE-2026-17022HIGHSalon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Disclosure via Booking WizardEPSS 0.4%CVE-2026-18946HIGHContact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictable FilenameEPSS 0.4%CVE-2026-16611HIGHProduct Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration DisclosureEPSS 0.4%CVE-2026-17541HIGHBit File Manager < 6.9.1 - Unauthenticated File Activity Log DisclosureEPSS 0.4%CVE-2026-14925HIGHImport WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File DownloadEPSS 0.4%CVE-2026-77016CRITICALWorkeera Remote Tech Job Board < 1.0.6 - Subscriber+ Arbitrary File Deletion via Candidate Profile Mass AssignmentEPSS 0.4%CVE-2026-10735HIGHShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update ServerEPSS 0.4%CVE-2026-77005CRITICALCode Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path TraversalEPSS 0.4%CVE-2024-3748MEDIUMSP Project & Document Manager <= 4.71 - Data Update via IDOREPSS 0.4%CVE-2026-16253HIGHTotal Upkeep < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secretEPSS 0.4%CVE-2026-14319HIGHGiveWP < 4.16.3 - Unauthenticated Recurring Donor Information DisclosureEPSS 0.4%CVE-2026-14206HIGHHT Contact Form < 2.9.3 - Unauthenticated Saved Form Draft Data DisclosureEPSS 0.4%