Vulnerabilidades em unknown
4.771 resultadosAnálise Vexday
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2021-24692—Simple Download Monitor < 3.9.5 - Contributor+ Arbitrary File Download via Path TraversalEPSS 1.4%CVE-2022-0493—String Locator < 2.5.0 - Admin+ Arbitrary File ReadEPSS 1.4%CVE-2022-4061HIGHJobBoardWP < 1.2.2 - Unauthenticated Arbitrary File UploadEPSS 1.4%CVE-2022-2317—Simple Membership < 4.1.3 - Unauthenticated Membership Privilege EscalationEPSS 1.3%CVE-2023-0236MEDIUMTutor LMS < 2.0.10 - Reflected Cross-Site ScriptingEPSS 1.3%CVE-2026-10823HIGHYMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post DisclosureEPSS 1.3%CVE-2021-24556—Email Subscriber <= 1.1 - Unauthenticated Stored Cross-Site Scripting (XSS)EPSS 1.3%CVE-2021-24497—Giveaway <= 1.2.2 - Authenticated SQL InjectionEPSS 1.3%CVE-2023-2712CRITICALMalicious File Upload vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform.EPSS 1.3%CVE-2021-24508—Smash Balloon Social Post Feed < 2.19.2 - Unauthenticated Stored XSSEPSS 1.3%CVE-2023-2252LOWDirectorist < 7.5.4 - Admin+ LFIEPSS 1.3%CVE-2021-24910—Transposh WordPress Translation < 1.0.8 - Reflected Cross-Site ScriptingEPSS 1.3%CVE-2022-1580—Site Offline < 1.5.3 - Access BypassEPSS 1.3%CVE-2022-3904MEDIUMMonsterInsights < 8.9.1 - Stored Cross-Site Scripting via Google AnalyticsEPSS 1.3%CVE-2021-24345—Sendit WP Newsletter <= 2.5.1 - Authenticated (admin+) SQL InjectionEPSS 1.3%CVE-2021-24769—Permalink Manager Lite < 2.2.13.1 - Admin+ SQL InjectionEPSS 1.3%CVE-2021-24606—Availability Calendar < 1.2.1 - Authenticated SQL InjectionEPSS 1.3%CVE-2021-24975—NextScripts: Social Networks Auto-Poster < 4.3.24 - Unauthenticated Stored XSSEPSS 1.3%CVE-2023-5939—rtMedia for WordPress, BuddyPress and bbPress < 4.6.16 - Admin+ RCEEPSS 1.3%CVE-2023-4861HIGHFile Manager Pro < 1.8.1 - Admin+ Remote Code ExecutionEPSS 1.3%