Vulnerabilidades en Unknown

5444 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2022-2535SearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title DisclosureEPSS 1.9%CVE-2021-25111English WordPress Admin < 1.5.2 - Unauthenticated Open RedirectEPSS 1.9%CVE-2021-24253Classyfrieds <= 3.8 - Authenticated Arbitrary File Upload to RCEEPSS 1.9%CVE-2021-24224Easy Form Builder <= 1.0 - Authenticated Arbitrary File UploadEPSS 1.9%CVE-2021-24171WooCommerce Upload Files < 59.4 - Unauthenticated Arbitrary File UploadEPSS 1.9%CVE-2025-1232HIGHSite Reviews < 7.2.5 - Unauthenticated Stored XSSEPSS 1.9%CVE-2021-24221Quiz And Survey Master < 7.1.12 - Authenticated SQL injection via shortcodeEPSS 1.9%CVE-2021-24363Photo Gallery < 1.5.75 - File Upload Path TraversalEPSS 1.9%CVE-2021-24228Patreon WordPress < 1.7.2 - Reflected XSS on Login FormEPSS 1.9%CVE-2021-24979Paid Memberships Pro < 2.6.6 - Reflected Cross-Site ScriptingEPSS 1.9%CVE-2022-1007Advanced Booking Calendar < 1.7.1 - Reflected Cross-Site ScriptingEPSS 1.9%CVE-2026-3326HIGHXStore < 9.7.3 - Unauthenticated SQLiEPSS 1.9%CVE-2022-2373Simply Schedule Appointments < 1.5.7.7 - Unauthenticated Email Address DisclosureEPSS 1.9%CVE-2022-1724Simple Membership < 4.1.1 - Reflected Cross-Site ScriptingEPSS 1.8%CVE-2022-0694Advanced Booking Calendar < 1.7.0 - Unauthenticated SQL InjectionEPSS 1.8%CVE-2022-1168JobSearch < 1.5.1 - Unauthenticated Reflected Cross-Site Scripting (XSS)EPSS 1.8%CVE-2025-11307HIGHWP Google Maps < 9.0.48 - Unauthenticated Stored XSSEPSS 1.8%CVE-2021-24254College Publisher Import <= 0.1 - Arbitrary File Upload to RCEEPSS 1.8%CVE-2021-24857ToTop Link <= 1.7.1 - Unauthenticated PHP Object InjectionEPSS 1.8%CVE-2022-2376Directorist < 7.3.1 - Unauthenticated Email Address DisclosureEPSS 1.8%