Vulnerabilidades en Unknown

5518 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2024-10638MEDIUMProduct Labels For Woocommerce < 1.5.11 - Admin+ SQLiEPSS 0.4%CVE-2024-4857MEDIUMFS Product Inquiry <= 1.1.1 - Unauthenticated Stored XSSEPSS 0.4%CVE-2026-77826HIGHRegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Facebook Token Audience ValidationEPSS 0.4%CVE-2026-14596HIGHDynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host InjectionEPSS 0.4%CVE-2023-5605—URL Shortify < 1.7.9.1 - Admin+ Stored XSSEPSS 0.4%CVE-2024-4616MEDIUMWidget Bundle <= 2.0.0 - Unauthencated Reflected XSSEPSS 0.4%CVE-2024-7082MEDIUMeasy-table-of-contents < 2.0.68 - Editor+ Stored XSSEPSS 0.4%CVE-2023-6530MEDIUMTJ Shortcodes <= 0.1.3 - Contributor+ Stored XSS via ShortcodesEPSS 0.4%CVE-2026-13152HIGHCustom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege EscalationEPSS 0.4%CVE-2026-15206HIGHSMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-MobileEPSS 0.4%CVE-2026-16540HIGHSimply Schedule Appointments < 1.6.12.6 - Unauthenticated Appointment Data Disclosure and Mass Deletion via purge EndpointEPSS 0.4%CVE-2026-14333HIGHDemi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup DirectoryEPSS 0.4%CVE-2026-12687HIGHProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group IDEPSS 0.4%CVE-2026-16736HIGHUser Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration DisabledEPSS 0.4%CVE-2026-16561HIGHSunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment DisclosureEPSS 0.4%CVE-2026-15241HIGHChatBot for eCommerce – WoowBot < 4.8.4 - Unauthenticated Gemini API Key Abuse via qcld_gemini_responseEPSS 0.4%CVE-2026-14930HIGHJS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment UploadEPSS 0.4%CVE-2026-12082HIGHPraison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)EPSS 0.4%CVE-2026-8379HIGHFrontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File DownloadEPSS 0.4%CVE-2026-16285HIGHWooCommerce Product Attachment < 2.3.3 - Unauthenticated Arbitrary Media DownloadEPSS 0.4%