Vulnerabilidades en Unknown

5533 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2024-10027MEDIUMWP Booking Calendar < 10.6.3 - Admin+ Stored XSSEPSS 0.4%CVE-2024-11183MEDIUMSimple Side Tab < 2.2.0 - Admin+ Stored XSSEPSS 0.4%CVE-2024-3918MEDIUMPet Manager <= 1.4 - Contributor+ Stored XSSEPSS 0.4%CVE-2026-17559MEDIUMContent Protector (Passster) < 4.3.9 - Unauthenticated Protected Content Disclosure via REST Path Allowlist BypassEPSS 0.4%CVE-2024-3474HIGHWow Skype Buttons < 4.0.4 - Button Deletion via CSRFEPSS 0.4%CVE-2024-4759MEDIUMMime Types Extended <= 0.11 - Author+ Stored XSS via SVG UploadEPSS 0.4%CVE-2024-10517MEDIUMProfilePress < 4.15.15 - Admin+ Stored XSSEPSS 0.4%CVE-2026-16290MEDIUMProfileGrid < 6.0.0.0 - Unauthenticated Group Member List Disclosure via pm_get_all_users_from_groupEPSS 0.4%CVE-2024-10518MEDIUMProfilePress < 4.15.15 - Admin+ Stored XSSEPSS 0.4%CVE-2026-15230HIGHYayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code DisclosureEPSS 0.4%CVE-2026-78153MEDIUMRestrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Route NormalizationEPSS 0.4%CVE-2026-11963HIGHUser Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier Modification via IDOREPSS 0.4%CVE-2026-13169HIGHEventin < 4.1.21 - Contributor+ Arbitrary Event Modification, Deletion and Ownership Takeover via IDOREPSS 0.4%CVE-2023-2842—WP Inventory Manager < 2.1.0.14 - Inventory Items Deletion via CSRFEPSS 0.4%CVE-2024-3476HIGHSide Menu Lite < 4.2.1 - Menu Deletion via CSRFEPSS 0.4%CVE-2026-14840MEDIUMYOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header SpoofingEPSS 0.4%CVE-2024-5004MEDIUMCM Popup Plugin for WordPress < 1.6.6 - Contributor+ Stored XSSEPSS 0.3%CVE-2023-6391HIGHCustom User CSS <= 0.2 - Settings Update via CSRFEPSS 0.3%CVE-2022-0164—Coming soon and Maintenance mode < 3.6.7 - Subscriber+ Arbitrary Email Sending to Subscribed UsersEPSS 0.3%CVE-2023-6532HIGHWP Blogs' Planetarium <= 1.0 - Settings Update via CSRFEPSS 0.3%