Vulnerabilidades en Unknown

5615 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-84023MEDIUMBEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via CSRFEPSS 0.2%CVE-2026-19861MEDIUMJetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in Notification EmailsEPSS 0.2%CVE-2026-86612MEDIUMNinja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Data SourceEPSS 0.2%CVE-2026-19698LOWGutenKit < 2.5.1 - Contributor+ Stored CSS InjectionEPSS 0.2%CVE-2025-0688MEDIUMSpiritual Gifts Survey <= 0.9.10 - Unauthenticated CSRF to XSSEPSS 0.2%CVE-2025-0687MEDIUMSpiritual Gifts Survey <= 0.9.10 - Unauthenticated CSRF to XSSEPSS 0.2%CVE-2025-1288MEDIUMwooexim <= 5.0.0 - CSRF to Reflected XSSEPSS 0.2%CVE-2024-13826MEDIUMEmail Keep <= 1.1 - Email Deletion via CSRFEPSS 0.2%CVE-2025-15697HIGHDictionary <= 1.0 - Reflected XSS via Multiple ParametersEPSS 0.2%CVE-2026-92412HIGHFive Star Restaurant Reviews < 2.3.14 - Reflected XSSEPSS 0.2%CVE-2025-15473MEDIUMTimetics < 1.0.52 - Unauthenticated Payment/Booking Status UpdateEPSS 0.2%CVE-2025-4580MEDIUMFile Provider <= 1.2.3 - Item Deletion via CSRFEPSS 0.2%CVE-2026-14307HIGHGeotargeting WP < 3.5.6.2 - Reflected XSSEPSS 0.2%CVE-2026-14936MEDIUMSimple Membership < 4.7.7 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver VerificationEPSS 0.2%CVE-2026-82184MEDIUMWPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option UpdateEPSS 0.2%CVE-2026-15148MEDIUMWP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via IDOREPSS 0.2%CVE-2026-16650MEDIUMCharitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webhook Signature BypassEPSS 0.2%CVE-2026-12501MEDIUMWP Travel Engine < 6.8.2 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver and Amount VerificationEPSS 0.2%CVE-2026-15208MEDIUMRegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal VerificationEPSS 0.2%CVE-2026-84044MEDIUMRestaurant Menu and Food Ordering < 2.4.12 - Unauthenticated Payment Bypass via Forged PayPal IPNEPSS 0.2%