Vulnerabilidades en Unknown

5450 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2021-24788—Batch Cat <= 0.3 - Subscriber+ Arbitrary Categories Add/Set/Delete to PostsEPSS 0.9%CVE-2022-2370—YaySMTP < 2.2.1 - Subscriber+ SMTP Credentials LeakEPSS 0.9%CVE-2023-1274—Pricing Tables For WPBakery Page Builder < 3.0 - Subscriber+ LFIEPSS 0.9%CVE-2022-0873—Gmedia Photo Gallery < 1.20.0 - Admin+ Stored Cross-Site ScriptingEPSS 0.9%CVE-2021-24158—Orbit Fox by ThemeIsle < 2.10.3 - Authenticated Privilege EscalationEPSS 0.9%CVE-2023-0955HIGHWP Statistics < 14.0 - Authenticated SQLiEPSS 0.9%CVE-2021-24177—WP File Manager < 7.1 - Reflected Cross-Site Scripting (XSS)EPSS 0.9%CVE-2022-4118CRITICALBitcoin / AltCoin Payment Gateway <= 1.7.1 - Unauthenticated SQLiEPSS 0.9%CVE-2023-5877CRITICALaffiliate-toolkit < 3.4.3 - Unauthenticated SSRFEPSS 0.9%CVE-2021-25110—Futurio Extra < 1.6.3 - Subscriber+ User Email Address DisclosureEPSS 0.9%CVE-2022-4295MEDIUMShow All Comments < 7.0.1 - Reflected XSSEPSS 0.9%CVE-2022-1005—WP Statistics < 13.2.2 - Reflected Cross-Site ScriptingEPSS 0.9%CVE-2021-24681—Duplicate Page <= 4.4.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.9%CVE-2023-6272—Theme My Login 2FA < 1.2 - Lack of Rate LimitingEPSS 0.9%CVE-2024-0337MEDIUMTravelpayouts <= 1.1.15 - Open RedirectEPSS 0.9%CVE-2022-3907HIGHClerk < 4.0.0 - Authentication Bypass and API Keys DisclosureEPSS 0.9%CVE-2022-4320MEDIUMWordPress Events Calendar Plugin < 1.4.5 - Multiple Reflected XSSEPSS 0.9%CVE-2023-0388HIGHRandom Text <= 0.3.0 - Subscriber+ SQLiEPSS 0.9%CVE-2023-2492HIGHQueryWall: Plug'n Play Firewall <= 1.1.1 - Admin+ SQLiEPSS 0.9%CVE-2021-24928—Rearrange Woocommerce Products < 3.0.8 - Subscriber+ SQL InjectionEPSS 0.9%