Vulnerabilidades en Unknown
5428 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2021-24444—TaxoPress < 3.0.7.2 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 2.3%CVE-2022-0188—Coming Soon & Maintenance Plugin by NiteoThemes < 4.0.19 - Unauthenticated Arbitrary CSS UpdateEPSS 2.3%CVE-2021-25033—Noptin < 1.6.5 - Open RedirectEPSS 2.3%CVE-2021-24358—The Plus Addons for Elementor Page Builder < 4.1.10 - Open RedirectEPSS 2.3%CVE-2024-9186HIGHAutomation By Autonami < 3.3.0 - Unauthenticated SQLiEPSS 2.3%CVE-2022-0212—SpiderCalendar <= 1.5.65 - Reflected Cross-Site ScriptingEPSS 2.3%CVE-2021-25078—Affiliates Manager < 2.9.0 - Unauthenticated Stored Cross-Site ScriptingEPSS 2.3%CVE-2022-1560—Amministrazione Aperta < 3.8 - Admin+ LFIEPSS 2.3%CVE-2023-7164HIGHBackWPup < 4.0.4 - Unauthenticated Backup DownloadEPSS 2.3%CVE-2021-25008—Code Snippets < 2.14.3 - Reflected Cross-Site ScriptingEPSS 2.3%CVE-2018-3935HIGHAn exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted setEPSS 2.3%CVE-2021-24959—WP Email Users <= 1.7.6 - Subscriber+ SQL InjectionEPSS 2.2%CVE-2021-24746—Sassy Social Share < 3.3.40 - Reflected Cross-Site ScriptingEPSS 2.2%CVE-2024-6486HIGHImageMagick Engine < 1.7.11 - Administrator+ OS Command InjectionEPSS 2.2%CVE-2022-0189—WP RSS Aggregator < 4.20 - Reflected Cross-Site Scripting (XSS)EPSS 2.2%CVE-2023-5089MEDIUMDefender Security < 4.1.0 - Protection Bypass (Hidden Login Page)EPSS 2.2%CVE-2021-24838—AnyComment < 0.3.5 - Open RedirectEPSS 2.2%CVE-2021-24223—N5 Upload Form <= 1.0 - Unauthenticated Arbitrary File Upload to RCEEPSS 2.2%CVE-2023-5203HIGHWP Sessions Time Monitoring Full Automatic < 1.0.9 - Unauthenticated SQL injectionEPSS 2.2%CVE-2023-2606—WP Brutal AI < 2.06 - Admin+ Stored XSSEPSS 2.2%