Vulnerabilidades em unknown

4.767 resultados
Análise Vexday

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2022-0206NewStatPress < 1.3.6 - Reflected Cross-Site ScriptingEPSS 1.5%CVE-2021-24125Contact Form Submissions < 1.7.1 - Authenticated SQL InjectionEPSS 1.5%CVE-2023-3186Supsystic Popup < 1.10.19 - Prototype PollutionEPSS 1.5%CVE-2021-25119AGIL <= 1.0 - Admin+ Arbitrary File UploadEPSS 1.4%CVE-2022-1409VikBooking Hotel Booking Engine & PMS < 1.5.8 - Admin+ PHP File UploadEPSS 1.4%CVE-2022-1273Import WP < 2.4.6 - Admin+ Arbitrary File Upload to RCEEPSS 1.4%CVE-2021-24131Anti-Spam by CleanTalk < 5.149 - Multiple Authenticated SQL InjectionsEPSS 1.4%CVE-2022-0440Catch Themes Demo Import < 2.1.1 - Admin+ Remote Code ExecutionEPSS 1.4%CVE-2022-0593Login with phone number < 1.3.7 - Unauthenticated remote plugin deletionEPSS 1.4%CVE-2021-24184Tutor LMS < 1.7.7 - Unprotected AJAX including Privilege EscalationEPSS 1.4%CVE-2021-24163Ninja Forms < 3.4.34 - Authenticated SendWP Plugin Installation and Client Secret Key DisclosureEPSS 1.4%CVE-2021-24940Persian Woocommerce <= 5.8.0 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2022-1939Allow SVG Files < 1.1 - Admin+ Arbitrary File UploadEPSS 1.4%CVE-2021-24894Reviews Plus < 1.2.14 - Subscriber+ Reviews DoSEPSS 1.4%CVE-2022-0920Salon booking system < 7.6.3 - Customer+ Bookings/Customers Data DisclosureEPSS 1.4%CVE-2022-2187Contact Form 7 Captcha < 0.1.2 - Reflected Cross-Site ScriptingEPSS 1.4%CVE-2022-1412Log WP_Mail <= 0.1 - Email Logs Publicly AccessibleEPSS 1.4%CVE-2022-1904Easy Pricing Tables < 3.2.1 - Reflected Cross-Site-ScriptingEPSS 1.4%CVE-2021-24451Export Users With Meta < 0.6.5 - Authenticated SQL InjectionEPSS 1.4%CVE-2021-24130WP Google Map Plugin < 4.1.5 - Authenticated SQL InjectionEPSS 1.4%