Vulnerabilidades en Unknown
5444 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2024-10820CRITICALWooCommerce Upload Files <= 84.3 - Unauthenticated Arbitrary File UploadEPSS 1.2%CVE-2021-24140—Ajax Load More < 5.3.2 - Authenticated SQL InjectionEPSS 1.2%CVE-2021-24141—Advanced Database Cleaner < 3.0.2 - Authenticated SQL injectionEPSS 1.2%CVE-2022-2546MEDIUMAll-in-One WP Migration < 7.63 - Unauthenticated Reflected XSSEPSS 1.2%CVE-2023-2719HIGHSupportCandy < 3.1.7 - Subscriber+ SQLiEPSS 1.2%CVE-2022-1091—Safe SVG < 1.9.10 - SVG Sanitisation BypassEPSS 1.2%CVE-2022-1538HIGHTheme-Demo-Importer < 1.1.1 - Admin+ Arbitrary File UploadEPSS 1.2%CVE-2021-25009—CorreosExpress <= 2.6.0 - Sensitive Information DisclosureEPSS 1.2%CVE-2022-2798—Affiliates Manager < 2.9.14 - Affiliate CSV InjectionEPSS 1.2%CVE-2021-25093—Link Library < 7.2.8 - Unauthenticated Arbitrary Links DeletionEPSS 1.2%CVE-2021-24876—Registrations for The Events Calendar < 2.7.5 - Reflected Cross-Site ScriptingEPSS 1.2%CVE-2021-24831—Tab - Accordion, FAQ < 1.3.2 - Unauthenticated AJAX CallsEPSS 1.2%CVE-2023-0865—WooCommerce Multiple Customer Addresses & Shipping < 21.7 - Arbitrary Address Creation/Deletion/Access/Update via IDOREPSS 1.2%CVE-2026-6433HIGHCustom CSS JS PHP <= 2.0.7 - Unauthenticated SQL Injection to RCEEPSS 1.2%CVE-2022-4321MEDIUMPDF Generator for WordPress < 1.1.2 - Reflected XSSEPSS 1.2%CVE-2022-3418HIGHWP All Import < 3.6.9 - Admin+ Arbitrary File Upload to RCEEPSS 1.2%CVE-2022-2133—OAuth Single Sign On < 6.22.6 - Authentication BypassEPSS 1.2%CVE-2021-24991—WooCommerce PDF Invoices & Packing Slips < 2.10.5 - Reflected Cross-Site ScriptingEPSS 1.2%CVE-2021-24998—Simple JWT Login < 3.3.0 - Insecure Password CreationEPSS 1.2%CVE-2021-24796—My Tickets < 1.8.31 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.2%