Vulnerabilidades em unknown

4.767 resultados
Análise Vexday

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2021-24342JNews < 8.0.6 - Reflected Cross-Site Scripting (XSS)EPSS 2.0%CVE-2022-2034Sensei LMS < 4.5.0 - Unauthenticated Private Messages Disclosure via Rest APIEPSS 2.0%CVE-2023-3345LMS by Masteriyo < 1.6.8 - Information ExposureEPSS 2.0%CVE-2023-5604CRITICALAsgaros Forum < 2.7.1 - Unauthenticated Arbitrary File UploadEPSS 2.0%CVE-2023-6750HIGHClone < 2.4.3 - Unauthenticated Backup DownloadEPSS 2.0%CVE-2024-5975CRITICALCZ Loan Management <= 1.1 - Unauthenticated SQLiEPSS 2.0%CVE-2021-24987Super Socializer < 7.13.30 - Reflected Cross-Site ScriptingEPSS 1.9%CVE-2018-3899HIGHAn exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafteEPSS 1.9%CVE-2021-25028Event Tickets < 5.2.2 - Open RedirectEPSS 1.9%CVE-2018-3898HIGHAn exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafteEPSS 1.9%CVE-2024-13726HIGHThemes Coder <= 1.3.4 - Unauthenticated SQLiEPSS 1.9%CVE-2022-3357HIGHSmart Slider 3 < 3.5.1.11 - PHP Object InjectionEPSS 1.9%CVE-2023-7165HIGHJetBackup < 2.0.9.9 - Directory Listing Exposing BackupsEPSS 1.9%CVE-2021-24551Edit Comments <= 0.3 - Unauthenticated SQL InjectionEPSS 1.9%CVE-2022-2535SearchWP Live Ajax Search < 1.6.2 - Unauthenticated Arbitrary Post Title DisclosureEPSS 1.9%CVE-2021-25111English WordPress Admin < 1.5.2 - Unauthenticated Open RedirectEPSS 1.9%CVE-2021-24224Easy Form Builder <= 1.0 - Authenticated Arbitrary File UploadEPSS 1.9%CVE-2021-24253Classyfrieds <= 3.8 - Authenticated Arbitrary File Upload to RCEEPSS 1.9%CVE-2022-1756Newsletter < 7.4.5 - Reflected Cross-Site ScriptingEPSS 1.9%CVE-2021-24171WooCommerce Upload Files < 59.4 - Unauthenticated Arbitrary File UploadEPSS 1.9%