Vulnerabilidades en Unknown

5533 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-12493HIGHClover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass via check_orderEPSS 0.4%CVE-2026-16041HIGHMStore API < 4.21.0 - Unauthenticated Product Review CreationEPSS 0.4%CVE-2026-11575HIGHPhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged CallbackEPSS 0.4%CVE-2024-12302MEDIUMIcegram Engage < 3.1.32 - Author+ Stored XSSEPSS 0.4%CVE-2026-9702HIGHInPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker HijackingEPSS 0.4%CVE-2026-87839HIGHTripzzy < 1.5.1 - Unauthenticated Arbitrary Comment DeletionEPSS 0.4%CVE-2026-91051MEDIUMEWWW Image Optimizer 8.6.0 - 8.7.7 - Author+ PHP Object Injection via 'eio_page_settings' Post MetaEPSS 0.4%CVE-2026-76586HIGHBookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment ConfirmationEPSS 0.4%CVE-2024-0427MEDIUMArforms < 6.4.1 - Reflected XSSEPSS 0.4%CVE-2023-6783MEDIUMWolfNet IDX for WordPress <= 1.19.1 - Admin+ Stored XSSEPSS 0.4%CVE-2026-14830HIGHFlxWoo < 3.1.1 - Unauthenticated Payment BypassEPSS 0.4%CVE-2024-12587MEDIUMContact Form Master <= 1.0.7 - Reflected XSSEPSS 0.4%CVE-2024-13218MEDIUMFast Tube <= 2.3.1 - Reflected XSSEPSS 0.4%CVE-2022-2375—WP Sticky Button < 1.4.1 - Unauthenticated Arbitrary Settings Update to Stored XSSEPSS 0.4%CVE-2024-13119MEDIUMProfilePress < 4.15.20 - Admin+ Stored XSSEPSS 0.4%CVE-2026-87068MEDIUMForminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form ImportEPSS 0.4%CVE-2024-3978MEDIUMWordPress Jitsi Shortcode <= 0.1 - Contributor+ Stored XSS via ShortcodeEPSS 0.4%CVE-2026-19222MEDIUMForminator Forms < 1.57.0.7 - Authenticated Privilege Escalation via Registration Form Role BypassEPSS 0.4%CVE-2026-2688MEDIUMCM HIPAA Forms < 3.2.0 - Unauthenticated Authorization BypassEPSS 0.4%CVE-2022-2382—Product Slider for WooCommerce < 2.5.7 - Subscriber+ Arbitrary Options DeletionEPSS 0.4%