Vulnerabilidades em unknown

4.771 resultados
Análise Vexday

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2021-24465Meow Gallery < 4.1.9 - Contributor+ SQL InjectionEPSS 1.2%CVE-2022-2261WPide < 3.0 - Admin+ Local File InclusionEPSS 1.2%CVE-2021-24796My Tickets < 1.8.31 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.2%CVE-2021-24967Contact Form & Lead Form Elementor Builder < 1.6.4 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.2%CVE-2021-24797Tickera < 3.4.8.3 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.2%CVE-2021-24792Shiny Buttons <= 1.1.0 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.2%CVE-2021-24876Registrations for The Events Calendar < 2.7.5 - Reflected Cross-Site ScriptingEPSS 1.2%CVE-2021-24878SupportCandy < 2.2.7 - Reflected Cross-Site ScriptingEPSS 1.2%CVE-2024-10820CRITICALWooCommerce Upload Files <= 84.3 - Unauthenticated Arbitrary File UploadEPSS 1.2%CVE-2021-24360Yes/No Chart < 1.0.12 - Authenticated (contributor+) Blind SQL InjectionEPSS 1.2%CVE-2022-3335HIGHKadence WooCommerce Email Designer < 1.5.7 - Admin+ PHP Objection InjectionEPSS 1.2%CVE-2023-2123WP Inventory Manager < 2.1.0.13 - Reflected Cross-Site ScriptingEPSS 1.2%CVE-2022-2903HIGHNinjaForms < 3.6.13 - Admin+ PHP Objection InjectionEPSS 1.2%CVE-2022-0429WP Cerber Security, Anti-spam & Malware Scan < 8.9.6 - Unauthenticated Stored Cross-Site ScriptingEPSS 1.2%CVE-2021-25004SEUR Oficial < 1.7.2 - Admin+ Arbitrary File DownloadEPSS 1.2%CVE-2023-2624KiviCare Management System < 3.2.1 - Reflected Cross-Site ScriptingEPSS 1.2%CVE-2022-2133OAuth Single Sign On < 6.22.6 - Authentication BypassEPSS 1.2%CVE-2023-4724HIGHWP All Export (Free < 1.4.0, Pro < 1.8.6) - Admin+ RCEEPSS 1.2%CVE-2021-24124WP Shieldon 1.6.3 - Unauthenticated Cross-Site Scripting (XSS)EPSS 1.1%CVE-2024-9926MEDIUMJetpack < 13.9.1 - Subscriber+ Arbitrary Feedback AccessEPSS 1.1%