Vulnerabilidades en Unknown

5615 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2026-80514MEDIUMwpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit BypassEPSS 0.2%CVE-2024-13057HIGHDyn Business Panel <= 1.0.0 - Stored XSS via CSRFEPSS 0.2%CVE-2026-12901MEDIUMGetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient IPN VerificationEPSS 0.2%CVE-2026-17515MEDIUMMLS Import < 7.0.4 - Subscriber+ Sensitive Information Disclosure via mlsimport_logger_per_itemEPSS 0.2%CVE-2023-7197HIGHMarketing Twitter Bot <= 1.11 - Settings Update to Stored XSS via CSRFEPSS 0.2%CVE-2025-15546MEDIUMIptanus File Upload < 5.1.7 - File Overwrite via Race ConditionEPSS 0.2%CVE-2026-14313MEDIUMPeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Order Receipt Tampering via IDOREPSS 0.2%CVE-2024-8243MEDIUMPlugin Upgrade Time Out <= 1.0 - Stored XSS via CSRFEPSS 0.2%CVE-2026-84906MEDIUMEventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transaction ReplayEPSS 0.2%CVE-2026-15213MEDIUMWelcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement CallbackEPSS 0.2%CVE-2026-15239MEDIUMSimple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection Bypass via Reusable Forminator Cache KeyEPSS 0.2%CVE-2026-17008MEDIUMQuick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPNEPSS 0.2%CVE-2025-2248MEDIUMWP-PManager <= 1.2 - Admin+ SQL InjectionEPSS 0.2%CVE-2025-1436HIGHLimit Bio <= 1.0 - Stored XSS via CSRFEPSS 0.2%CVE-2026-16568MEDIUMShopApper <= 0.4.62 - Subscriber+ Customer Data Disclosure via IDOREPSS 0.2%CVE-2026-15211MEDIUMSubscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied PayPal Capture TokenEPSS 0.2%CVE-2026-90951LOWPaid Member Subscriptions < 3.1.0 - Unauthenticated In-Flight Checkout State Deletion via pms_process_paymentEPSS 0.2%CVE-2026-87074LOWForminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attacker-Controlled LinkEPSS 0.2%CVE-2026-19862MEDIUMJetFormBuilder < 3.6.5.2 - Unauthenticated Email Header Injection via Send Email ActionEPSS 0.2%CVE-2026-86604MEDIUMGTranslate < 5.0.1 - Unauthenticated Arbitrary Shortcode Execution via Email TranslationEPSS 0.2%