Vulnerabilidades en Unknown

5585 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2025-9544MEDIUMDoppler Forms <= 2.5.1 - Subscriber+ Limited Plugin InstallationEPSS 0.2%CVE-2026-85005MEDIUMPopup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing AuthorizationEPSS 0.2%CVE-2023-6501MEDIUMSplashscreen <= 0.20 - Settings Update via CSRFEPSS 0.2%CVE-2026-75824MEDIUMWP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration DisabledEPSS 0.2%CVE-2026-17563MEDIUMWP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated FormEPSS 0.2%CVE-2026-83555MEDIUMEmail Subscribers by Icegram Express < 5.9.35 - Unauthenticated Subscription Status Change via Missing Token VerificationEPSS 0.2%CVE-2026-18042MEDIUMWP Travel < 12.0.2 - Unauthenticated Arbitrary Booking CancellationEPSS 0.2%CVE-2026-12514MEDIUMShared Files < 1.7.70 - Unauthenticated Limited File UploadEPSS 0.2%CVE-2026-1867MEDIUMWP Front User Submit < 5.0.6 - Unauthenticated Sensitive Information ExposureEPSS 0.2%CVE-2026-77765MEDIUMBetter Payment < 2.3.4 - Unauthenticated Payment Amount ManipulationEPSS 0.2%CVE-2026-16986MEDIUMBooking Package < 1.7.25 - Unauthenticated Price Manipulation via Service and Option Cost ParametersEPSS 0.2%CVE-2026-92437MEDIUMMailchimp for WooCommerce < 6.3 - Unauthenticated Abandoned Cart Modification and DeletionEPSS 0.2%CVE-2026-15232MEDIUMAppointment Booking Lite < 2.4.8 - Unauthenticated Arbitrary Reservation DeletionEPSS 0.2%CVE-2024-11842MEDIUMDN Shipping by Weight for WooCommerce < 1.2 - Settings Update via CSRFEPSS 0.2%CVE-2025-13456MEDIUMShopbuilder < 3.2.2 - Reflected XSSEPSS 0.2%CVE-2026-13404MEDIUMRoyal Elementor Addons < 1.7.1066 - Unauthenticated Like Count and IP Meta Modification via wpr_likes_initEPSS 0.2%CVE-2025-11855HIGHAge Restriction <= 3.0.2 - Subscriber+ Privilege EscalationEPSS 0.2%CVE-2024-12436MEDIUMWP Customer Area <= 8.2.4 - Bulk Delete via CSRFEPSS 0.2%CVE-2026-89237MEDIUMBluff Post <= 1.1.1 - Unauthenticated SQLi via 'table_name' and 'column_name' ParametersEPSS 0.2%CVE-2024-5808MEDIUMWP Ajax Contact Form <= 2.2.2 - Arbitrary Email Deletion via CSRFEPSS 0.2%