Vulnerabilidades en unknown

4771 resultados
Análisis Vexday

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2022-0403Library File Manager < 5.2.3 - Subscriber+ Arbitrary File Creation/Upload/DeletionEPSS 1.2%CVE-2023-7082HIGHWP All Import < 3.7.3 - Admin+ Arbitrary File Upload to RCEEPSS 1.2%CVE-2022-3463CRITICALFluentForm < 4.3.13 - CSV InjectionEPSS 1.2%CVE-2021-24138AdRotate < 5.8.4 - Authenticated SQL InjectionEPSS 1.2%CVE-2022-25811Transposh WordPress Translation <= 1.0.8 - Admin+ SQL InjectionEPSS 1.2%CVE-2021-24942HIGHMenu Item Visibility Control <= 0.5 - Admin+ Arbitrary PHP Code ExecutionEPSS 1.2%CVE-2021-24864WP Cloudy < 4.4.9 - Admin+ SQL InjectionEPSS 1.2%CVE-2022-3600CRITICALEasy Digital Downloads < 3.1.0.2 - Unauthenticated CSV InjectionEPSS 1.2%CVE-2022-1762iQ Block Country < 1.2.20 - Protection Bypass due to IP SpoofingEPSS 1.2%CVE-2021-25065Smash Balloon Social Post Feed < 4.1.1 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 1.2%CVE-2021-24964MEDIUMLiteSpeed Cache < 4.4.4 - IP Check Bypass to Unauthenticated Stored XSSEPSS 1.2%CVE-2022-0989NS WooCommerce Watermark <= 2.11.3 - Abuse of FunctionalityEPSS 1.2%CVE-2026-1368HIGHVideo Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature GenerationEPSS 1.2%CVE-2020-36503Connections Business Directory < 9.7 - Admin+ CSV InjectionEPSS 1.2%CVE-2021-24140Ajax Load More < 5.3.2 - Authenticated SQL InjectionEPSS 1.2%CVE-2021-24141Advanced Database Cleaner < 3.0.2 - Authenticated SQL injectionEPSS 1.2%CVE-2021-25121Rating by BestWebSoft < 1.6 - Rating Denial of ServiceEPSS 1.2%CVE-2022-2546MEDIUMAll-in-One WP Migration < 7.63 - Unauthenticated Reflected XSSEPSS 1.2%CVE-2023-2719HIGHSupportCandy < 3.1.7 - Subscriber+ SQLiEPSS 1.2%CVE-2024-11605MEDIUMWP Publications <= 1.2 - Admin+ Stored XSSEPSS 1.2%