Vulnerabilidades em unknown
4.771 resultadosAnálise Vexday
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2022-1538HIGHTheme-Demo-Importer < 1.1.1 - Admin+ Arbitrary File UploadEPSS 1.2%CVE-2021-25009—CorreosExpress <= 2.6.0 - Sensitive Information DisclosureEPSS 1.2%CVE-2022-3494HIGHComplianz (Free < 6.3.4, Premium < 6.3.6) - Translator SQLiEPSS 1.2%CVE-2023-0865—WooCommerce Multiple Customer Addresses & Shipping < 21.7 - Arbitrary Address Creation/Deletion/Access/Update via IDOREPSS 1.2%CVE-2021-25093—Link Library < 7.2.8 - Unauthenticated Arbitrary Links DeletionEPSS 1.2%CVE-2021-24831—Tab - Accordion, FAQ < 1.3.2 - Unauthenticated AJAX CallsEPSS 1.2%CVE-2026-6433HIGHCustom CSS JS PHP <= 2.0.7 - Unauthenticated SQL Injection to RCEEPSS 1.2%CVE-2022-0879—Caldera Forms < 1.9.7 - Reflected Cross-Site ScriptingEPSS 1.2%CVE-2022-4321MEDIUMPDF Generator for WordPress < 1.1.2 - Reflected XSSEPSS 1.2%CVE-2022-3125—Frontend File Manager < 21.3 - Subscriber+ Arbitrary File UploadEPSS 1.2%CVE-2022-1801—Very Simple Contact Form < 11.6 - Captcha bypassEPSS 1.2%CVE-2021-24991—WooCommerce PDF Invoices & Packing Slips < 2.10.5 - Reflected Cross-Site ScriptingEPSS 1.2%CVE-2021-24998—Simple JWT Login < 3.3.0 - Insecure Password CreationEPSS 1.2%CVE-2022-1091—Safe SVG < 1.9.10 - SVG Sanitisation BypassEPSS 1.2%CVE-2021-24377—Autoptimize < 2.7.8 - Race Condition leading to RCEEPSS 1.2%CVE-2021-24869HIGHWP Fastest Cache < 0.9.5 - Subscriber+ SQL InjectionEPSS 1.2%CVE-2021-24585—Timetable and Event Schedule by MotoPress < 2.4.0 - Arbitrary User's Hashed Password/Email/Username DisclosureEPSS 1.2%CVE-2021-24352—Simple 301 Redirects by BetterLinks - 2.0.0 – 2.0.3 - Unauthenticated Redirect ExportEPSS 1.2%CVE-2021-24234—Ivory Search < 4.6.1 - Reflected Cross Site Scripting (XSS)EPSS 1.2%CVE-2024-14010HIGHTypora 1.7.4 OS Command Injection via Export PDF PreferencesEPSS 1.2%