Vulnerabilidades en Unknown

5533 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2021-24836—Temporary Login Without Password < 1.7.1 - Subscriber+ Plugin's Settings UpdateEPSS 0.3%CVE-2024-8492MEDIUMHustle < 7.8.5 - Admin+ Stored XSSEPSS 0.3%CVE-2026-16734HIGHStripe Payment Forms by WP Full Pay < 8.5.2 - Unauthenticated Payment Intent Amount ManipulationEPSS 0.3%CVE-2026-77012CRITICALIcollect <= 1.0.0 - Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Write via Default Publishing PasswordEPSS 0.3%CVE-2023-6946HIGHAutotitle for WordPress <= 1.0.3 - Settings Update to Stored XSS via CSRFEPSS 0.3%CVE-2026-15958CRITICALEasy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access and Upload via nopriv AJAXEPSS 0.3%CVE-2024-10545LOWNextGEN Gallery < 3.59.9 - Admin+ Stored XSSEPSS 0.3%CVE-2026-81022MEDIUMSupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Auth Code LeakEPSS 0.3%CVE-2026-80339MEDIUMPayment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticated Customer PII Disclosure via order-payEPSS 0.3%CVE-2024-5767HIGHSitetweet <= 0.2 - Stored XSS via CSRFEPSS 0.3%CVE-2026-18778MEDIUMTrueBooker Appointment Booking < 1.2.7 - Unauthenticated Customer PII Disclosure via Multiple AJAX ActionsEPSS 0.3%CVE-2026-77758MEDIUMStripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription and Billing Data Disclosure via Unconfirmed SessionEPSS 0.3%CVE-2026-7385MEDIUMDecent Comments < 3.0.2 - Unauthenticated Email Address DisclosureEPSS 0.3%CVE-2026-77773MEDIUMSocial Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure via formychat_get_gf_entryEPSS 0.3%CVE-2026-81021MEDIUMSupportCandy 3.2.9 - 3.5.2 - Unauthenticated Ticket Attachment DisclosureEPSS 0.3%CVE-2026-77782MEDIUMRank Math SEO < 1.0.277.1 - Unauthenticated Password-Protected Post Content Disclosure via Post Metadata and llms.txtEPSS 0.3%CVE-2026-86796MEDIUMWP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request ParametersEPSS 0.3%CVE-2026-14240MEDIUMTourmaster < 5.4.9 - Unauthenticated Sensitive Data Disclosure via Order ExportEPSS 0.3%CVE-2026-82124MEDIUMSchema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Content Disclosure via JSON-LD Schema OutputEPSS 0.3%CVE-2026-11351MEDIUMShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information DisclosureEPSS 0.3%