Vulnerabilidades en cyberlord92
42 resultadosAnálisis Vexday
O fornecedor cyberlord92 apresenta 40 CVEs catalogadas, com 11 classificadas como críticas, mas nenhuma sob ataque ativo identificado no momento. Embora 4 vulnerabilidades tenham sido publicadas nos últimos 90 dias, indicando risco recente, a ausência de exploração conhecida (KEV) reduz a urgência imediata. A fraqueza dominante é CWE-862 (controle de acesso inadequado), padrão relevante que requer atenção em avaliações de segurança de fornecedores.
CVE-2023-3447HIGHActive Directory Integration / LDAP Integration <= 4.1.5 - Authenticated (Subscriber+) LDAP InjectionEPSS 0.5%CVE-2024-9887HIGHLogin using WordPress Users ( WP as SAML IDP ) <= 1.15.6 - Authenticated (Administrator+) SQL InjectionEPSS 0.5%CVE-2024-11901MEDIUMPowerBI Embed Reports <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site ScriptingEPSS 0.5%CVE-2026-12761CRITICALminiOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP FlowEPSS 0.5%CVE-2024-11087HIGHminiOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon <= 200.3.9 - Authentication BypassEPSS 0.4%CVE-2026-15013CRITICALSAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm ConfusionEPSS 0.4%CVE-2025-10750MEDIUMPowerBI Embed Reports <= 1.2.0 - Unauthenticated Sensitive Information DisclosureEPSS 0.4%CVE-2023-2599LOWActive Directory Integration / LDAP Integration <= 4.1.4 - Cross-Site Request Forgery to SQL InjectionEPSS 0.4%CVE-2023-46082MEDIUMWordPress Broken Link Checker | Finder plugin <= 2.4.2 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-7665HIGHMiniorange OTP Verification with Firebase 3.1.0 - 3.6.2 - Unauthenticated Privilege EscalationEPSS 0.3%CVE-2025-10753MEDIUMOAuth Single Sign On – SSO (OAuth Client) <= 6.26.14 - Missing AuthorizationEPSS 0.3%CVE-2024-12121MEDIUMBroken Link Checker | Finder <= 2.5.0 - Authenticated (Author+) Blind Server-Side Request ForgeryEPSS 0.3%CVE-2025-10648MEDIUMLogin with YourMembership - YM SSO Login <= 1.1.7 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'moym_display_test_attributes'EPSS 0.3%CVE-2025-10746MEDIUMIntegrate Dynamics 365 CRM <= 1.0.9 - Missing AuthorizationEPSS 0.3%CVE-2025-6003MEDIUMWordPress Single Sign-On (SSO) - Multiple Versions - Incorrect Authorization to Sensitive Information ExposureEPSS 0.3%CVE-2025-14948MEDIUMminiOrange OTP Verification and SMS Notification for WooCommerce <= 4.3.8 - Missing Authorization to Unauthenticated Notification Settings ModificationEPSS 0.2%CVE-2026-1279MEDIUMEmployee Directory <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'form_title' Shortcode AttributeEPSS 0.2%CVE-2026-0725MEDIUMIntegrate Dynamics 365 CRM <= 1.1.1 - Authenticated (Administrator+) Stored Cross-Site Scripting via Field Mapping ConfigurationEPSS 0.2%CVE-2025-12822MEDIUMWP Login and Register using JWT <= 3.0.0 - Missing Authorization to Authenticated (Subscriber+) API Key ExposureEPSS 0.2%CVE-2025-11255MEDIUMPassword Policy Manager | Password Manager <= 2.0.5 - Missing Authorization to Authenticated (Subscriber+) Configuration Log OutEPSS 0.2%