Vulnerabilidades en Unknown

5533 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-88802HIGHMDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post DeletionEPSS 0.4%CVE-2022-1251—Ask Me < 6.8.4 - CSRF in Edit ProfileEPSS 0.4%CVE-2026-13399HIGHPayment Plugins for PayPal WooCommerce < 2.0.20 - Unauthenticated Payment Bypass via Reuse of a Completed PayPal OrderEPSS 0.4%CVE-2024-4094MEDIUMSimple Share Buttons Adder < 8.5.1 - Admin+ Stored XSSEPSS 0.4%CVE-2024-4372MEDIUMCarousel Slider < 2.2.11 - Editor+ Stored XSSEPSS 0.4%CVE-2024-3939MEDIUMDitty < 3.1.36 - Author+ Stored XSSEPSS 0.4%CVE-2024-3261MEDIUMStrong Testimonials < 3.1.12 - Contributor+ Stored XSSEPSS 0.4%CVE-2024-5169MEDIUMVideo Widget <= 1.2.3 - Admin+ Stored XSS via WidgetEPSS 0.4%CVE-2024-6724MEDIUMGenerate Images – Magic Post Thumbnail < 5.2.8 - Admin+ Stored XSSEPSS 0.4%CVE-2024-6888MEDIUMSecure Copy Content Protection and Content Locking < 4.1.7 - Admin+ Stored XSSEPSS 0.4%CVE-2026-9576MEDIUMFluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure via Attendee ExportEPSS 0.4%CVE-2026-74853MEDIUMPods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display CallbackEPSS 0.4%CVE-2026-8825MEDIUMElementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST APIEPSS 0.4%CVE-2024-7955MEDIUMStarbox < 3.5.2 - Admin+ Stored XSSEPSS 0.4%CVE-2024-1487MEDIUMPhotos and Files Contest Gallery < 21.3.1 - Author+ Stored Cross Site ScriptingEPSS 0.4%CVE-2026-84221MEDIUMKirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field IDEPSS 0.4%CVE-2024-5172MEDIUMExpert Invoice <= 1.0.2 -Admin+ Stored XSSEPSS 0.4%CVE-2024-4752MEDIUMEventON < 2.2.15 - Admin+ Stored Cross-Site Scripting via event subtitleEPSS 0.4%CVE-2023-5354MEDIUMAwesome Support < 6.1.5 - Reflected Cross-Site ScriptingEPSS 0.4%CVE-2021-24703—Download Plugin < 1.6.1 - Subscriber+ Arbitrary Plugin ActivationEPSS 0.4%