Vulnerabilidades em unknown
4.767 resultadosAnálise Vexday
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2022-4140HIGHWelcart e-Commerce < 2.8.5 - Unauthenticated Arbitrary File AccessEPSS 2.9%CVE-2021-24235—Goto - Tour & Travel < 2.0 - Unauthenticated Reflected XSSEPSS 2.9%CVE-2021-25120—Easy Social Feed < 6.2.7 - Reflected Cross-Site ScriptingEPSS 2.9%CVE-2024-0399HIGHWooCommerce Customers Manager < 29.7 - Subscriber+ SQL InjectionEPSS 2.9%CVE-2022-4953—Elementor < 3.5.5 - Iframe InjectionEPSS 2.9%CVE-2021-24962—WordPress File Upload < 4.16.3 - Contributor+ Path Traversal to RCEEPSS 2.8%CVE-2024-6244HIGHpz-frontend-manager < 1.0.6 - CSRF change user profile pictureEPSS 2.8%CVE-2023-5559—10Web Booster < 2.24.18 - Unauthenticated Arbitrary Option DeletionEPSS 2.8%CVE-2021-24773—WordPress Download Manager < 3.2.16 - Admin+ Stored Cross-Site ScriptingEPSS 2.8%CVE-2022-1595—HC Custom WP-Admin URL <= 1.4 - Unauthenticated Secret URL DisclosureEPSS 2.8%CVE-2021-24596—youForms for WordPress <= 1.0.5 - Authenticated Stored Cross-Site ScriptingEPSS 2.8%CVE-2021-24997—WP Guppy < 1.3 - Sensitive Information DisclosureEPSS 2.8%CVE-2022-0994—Hummingbird < 3.3.2 - Admin+ Stored Cross-Site ScriptingEPSS 2.8%CVE-2021-24510—MF Gig Calendar < 1.2 - Reflected Cross-Site Scripting (XSS)EPSS 2.7%CVE-2022-0142—Visual Form Builder < 3.0.6 - CSV InjectionEPSS 2.7%CVE-2021-25033—Noptin < 1.6.5 - Open RedirectEPSS 2.7%CVE-2018-3892CRITICALAn exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafteEPSS 2.7%CVE-2024-6159CRITICALPush Notification for Post and BuddyPress <=1.93 - Multiple Unauthenticated SQLiEPSS 2.6%CVE-2022-1153—LayerSlider < 7.1.2 - Admin+ Stored Cross-Site ScriptingEPSS 2.6%CVE-2018-3934CRITICALAn exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially craftedEPSS 2.6%