Vulnerabilidades en Unknown

5428 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2022-1409VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ PHP File UploadEPSS 1.4%CVE-2022-2240Request a Quote <= 2.3.7 - CSV InjectionEPSS 1.4%CVE-2021-25104Ocean Extra < 1.9.5 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2021-24131Anti-Spam by CleanTalk < 5.149 - Multiple Authenticated SQL InjectionsEPSS 1.4%CVE-2015-10140HIGHAjax Load More < 2.8.1.2 - Subscriber+ File Upload & DeletionEPSS 1.4%CVE-2022-0440Catch Themes Demo Import < 2.1.1 - Admin+ Remote Code ExecutionEPSS 1.4%CVE-2022-0593Login with phone number < 1.3.7 - Unauthenticated remote plugin deletionEPSS 1.4%CVE-2021-24163Ninja Forms < 3.4.34 - Authenticated SendWP Plugin Installation and Client Secret Key DisclosureEPSS 1.4%CVE-2021-24184Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege EscalationEPSS 1.4%CVE-2021-24940Persian Woocommerce <= 5.8.0 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2021-24956Blog2Social < 6.8.7 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2022-0599Mapping Multiple URLs Redirect Same Page <= 5.8 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2022-2261WPide < 3.0 - Admin+ Local File InclusionEPSS 1.4%CVE-2022-25811Transposh WordPress Translation <= 1.0.8 - Admin+ SQL InjectionEPSS 1.4%CVE-2022-2268WP All Import < 3.6.8 - Admin+ Arbitrary File UploadEPSS 1.4%CVE-2022-3393CRITICALPost to CSV by BestWebSoft <= 1.4.0 - Author+ CSV InjectionEPSS 1.4%CVE-2021-24807Support Board < 3.3.5 - Agent+ Stored Cross-Site ScriptingEPSS 1.4%CVE-2022-1239HubSpot < 8.8.15 - Contributor+ Blind SSRFEPSS 1.4%CVE-2021-24451Export Users With Meta < 0.6.5 - Authenticated SQL InjectionEPSS 1.4%CVE-2021-24130WP Google Map Plugin < 4.1.5 - Authenticated SQL InjectionEPSS 1.4%