Vulnerabilidades en Unknown
5444 resultadosAnálisis Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2021-24377—Autoptimize < 2.7.8 - Race Condition leading to RCEEPSS 1.2%CVE-2021-24869HIGHWP Fastest Cache < 0.9.5 - Subscriber+ SQL InjectionEPSS 1.2%CVE-2022-1614—WP-Email < 2.69.0 - Anti-Spam Protection Bypass via IP SpoofingEPSS 1.2%CVE-2021-24585—Timetable and Event Schedule by MotoPress < 2.4.0 - Arbitrary User's Hashed Password/Email/Username DisclosureEPSS 1.2%CVE-2021-24352—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect ExportEPSS 1.2%CVE-2021-24234—Ivory Search < 4.6.1 - Reflected Cross Site Scripting (XSS)EPSS 1.2%CVE-2022-2273—Simple Membership < 4.1.3 - Membership Privilege EscalationEPSS 1.2%CVE-2021-24840—Squaretype Modern Blog < 3.0.4 - Unauthenticated Private/Schedule Posts DisclosureEPSS 1.2%CVE-2021-24465—Meow Gallery < 4.1.9 - Contributor+ SQL InjectionEPSS 1.2%CVE-2021-24792—Shiny Buttons <= 1.1.0 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.2%CVE-2021-24967—Contact Form & Lead Form Elementor Builder < 1.6.4 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.2%CVE-2021-24797—Tickera < 3.4.8.3 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.2%CVE-2022-2638—Export All URLs < 4.4 - Admin+ Arbitrary System File RemovalEPSS 1.2%CVE-2022-0879—Caldera Forms < 1.9.7 - Reflected Cross-Site ScriptingEPSS 1.2%CVE-2021-24878—SupportCandy < 2.2.7 - Reflected Cross-Site ScriptingEPSS 1.2%CVE-2022-0919—Salon booking system < 7.6.3 - Unauthenticated Sensitive Data DisclosureEPSS 1.2%CVE-2021-24360—Yes/No Chart < 1.0.12 - Authenticated (contributor+) Blind SQL InjectionEPSS 1.2%CVE-2023-2123—WP Inventory Manager < 2.1.0.13 - Reflected Cross-Site ScriptingEPSS 1.2%CVE-2022-2362—Download Manager < 3.2.50 - Bypass IP Address Blocking RestrictionEPSS 1.2%CVE-2022-0429—WP Cerber Security, Anti-spam & Malware Scan < 8.9.6 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.2%