Vulnerabilidades en Unknown

5465 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2023-3365HIGHMultiParcels Shipping For WooCommerce < 1.14.14 - Subscriber+ Arbitrary Shipment DeletionEPSS 0.7%CVE-2023-0376MEDIUMQubely < 1.8.5 - Contributor+ Stored XSSEPSS 0.7%CVE-2023-0069MEDIUMWPaudio MP3 Player <= 4.0.2 - Contributor+ Stored XSSEPSS 0.7%CVE-2022-0969—Image optimization & Lazy Load < 3.3.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-2877—Titan Anti-spam & Security < 7.3.1 - Protection Bypass due to IP SpoofingEPSS 0.7%CVE-2022-1323—Discy < 5.0 - Subscriber+ Broken Access Control to change settingsEPSS 0.7%CVE-2024-6847CRITICALSmartSearch WP <= 2.4.4 - Unauthenticated SQLiEPSS 0.7%CVE-2023-1809HIGHDownload Manager Pro < 6.3.0 - Unauthenticated Sensitive Information DisclosureEPSS 0.7%CVE-2022-2198—WPQA < 5.7 - Subscriber+ Private Message Disclosure via IDOREPSS 0.7%CVE-2023-1524MEDIUMDownload Manager < 3.2.71 - Broken Access ControlsEPSS 0.7%CVE-2021-24626—Chameleon CSS <= 1.2 - Subscriber+ SQL InjectionEPSS 0.7%CVE-2023-3139—Protect WP Admin < 4.0 - Unauthenticated Protection BypassEPSS 0.7%CVE-2021-24152—Popup Builder < 3.74 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2026-16268HIGHNewsletters < 4.16 - Unauthenticated Server-Side Request Forgery via SNS Bounce HandlerEPSS 0.7%CVE-2026-11974HIGHMedia folder Addon < 4.1.7 - Unauthenticated Arbitrary File DownloadEPSS 0.7%CVE-2026-16616HIGHSimple File List <= 6.3.11 - Unauthenticated Arbitrary File Read and Move via Path TraversalEPSS 0.7%CVE-2023-0441HIGHGallery Blocks with Lightbox < 3.0.8 - Subscriber+ Arbitrary Options UpdateEPSS 0.7%CVE-2026-8385MEDIUMWP Go Maps < 10.0.10 - Unauthenticated Sensitive Information Disclosure via Datatables AJAX FallbackEPSS 0.7%CVE-2026-4106MEDIUMHT Mega < 3.0.7 – Unauthenticated PII DisclosureEPSS 0.7%CVE-2026-76552HIGHWP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remote Image ImportEPSS 0.7%