Vulnerabilidades en Unknown

5484 resultados
Análisis Vexday

O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.

CVE-2022-4759MEDIUMGigPress < 2.3.28 - Contributor+ Stored XSS via ShortcodeEPSS 0.7%CVE-2022-4488MEDIUMWidgets on Pages < 1.8.0 - Contributor+ Stored XSSEPSS 0.7%CVE-2022-3511MEDIUMAwesome Support < 6.1.2 - Subscriber+ Arbitrary Exported Tickets DownloadEPSS 0.7%CVE-2024-6517MEDIUMContact Form 7 Math Captcha <= 2.0.1 - Reflected XSSEPSS 0.7%CVE-2022-4109LOWWholesale Market for WooCommerce < 2.0.0 - Admin+ Arbitrary Log DownloadEPSS 0.7%CVE-2021-24813—Events Made Easy < 2.2.24 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2025-12841MEDIUMBookit < 2.5.1 – Unauthenticated Settings UpdateEPSS 0.7%CVE-2022-4303HIGHWP Limit Login Attempts <= 2.6.4 - IP SpoofingEPSS 0.7%CVE-2023-1405HIGHFormidable Forms < 6.2 - Unauthenticated PHP Object InjectionEPSS 0.7%CVE-2024-7354MEDIUMNinja Forms 3.8.6-3.8.10 - Reflected XSSEPSS 0.7%CVE-2023-3154HIGHNextGEN Gallery < 3.39 - Admin+ PHAR DeserializationEPSS 0.7%CVE-2021-24218—Facebook for WordPress 3.0.0-3.0.3 - CSRF to Stored XSS and Settings DeletionEPSS 0.7%CVE-2015-20106—ClickBank Affiliate Ads <= 1.20 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-3961MEDIUMDirectorist < 7.4.4 - Subscriber+ Sensitive Information DisclosureEPSS 0.7%CVE-2021-24888—ImageBoss < 3.0.6 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2021-25026—Patreon WordPress < 1.8.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-1599—Admin Management Xtended < 2.4.5 - Post Visibility/Date/Comment Status Update via CSRFEPSS 0.7%CVE-2023-0375MEDIUMEasy Affiliate Links < 3.7.1 - Contributor+ Stored XSSEPSS 0.7%CVE-2023-4549—DoLogin Security < 3.7 - Unauthenticated Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-1579HIGHLogin Block IPs <= 1.0.0 - IP Spoofing BypassEPSS 0.7%