Vulnerabilidades en Unknown
5428 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2022-1409—VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ PHP File UploadEPSS 1.4%CVE-2022-2240—Request a Quote <= 2.3.7 - CSV InjectionEPSS 1.4%CVE-2021-25104—Ocean Extra < 1.9.5 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2021-24131—Anti-Spam by CleanTalk < 5.149 - Multiple Authenticated SQL InjectionsEPSS 1.4%CVE-2015-10140HIGHAjax Load More < 2.8.1.2 - Subscriber+ File Upload & DeletionEPSS 1.4%CVE-2022-0440—Catch Themes Demo Import < 2.1.1 - Admin+ Remote Code ExecutionEPSS 1.4%CVE-2022-0593—Login with phone number < 1.3.7 - Unauthenticated remote plugin deletionEPSS 1.4%CVE-2021-24163—Ninja Forms < 3.4.34 - Authenticated SendWP Plugin Installation and Client Secret Key DisclosureEPSS 1.4%CVE-2021-24184—Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege EscalationEPSS 1.4%CVE-2021-24940—Persian Woocommerce <= 5.8.0 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2021-24956—Blog2Social < 6.8.7 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2022-0599—Mapping Multiple URLs Redirect Same Page <= 5.8 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2022-2261—WPide < 3.0 - Admin+ Local File InclusionEPSS 1.4%CVE-2022-25811—Transposh WordPress Translation <= 1.0.8 - Admin+ SQL InjectionEPSS 1.4%CVE-2022-2268—WP All Import < 3.6.8 - Admin+ Arbitrary File UploadEPSS 1.4%CVE-2022-3393CRITICALPost to CSV by BestWebSoft <= 1.4.0 - Author+ CSV InjectionEPSS 1.4%CVE-2021-24807—Support Board < 3.3.5 - Agent+ Stored Cross-Site ScriptingEPSS 1.4%CVE-2022-1239—HubSpot < 8.8.15 - Contributor+ Blind SSRFEPSS 1.4%CVE-2021-24451—Export Users With Meta < 0.6.5 - Authenticated SQL InjectionEPSS 1.4%CVE-2021-24130—WP Google Map Plugin < 4.1.5 - Authenticated SQL InjectionEPSS 1.4%