Vulnerabilidades em unknown
4.771 resultadosAnálise Vexday
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2022-0919—Salon booking system < 7.6.3 - Unauthenticated Sensitive Data DisclosureEPSS 1.1%CVE-2022-2273—Simple Membership < 4.1.3 - Membership Privilege EscalationEPSS 1.1%CVE-2022-3490HIGHCheckout Field Editor for WooCommerce < 1.8.0 - Admin+ PHP Object InjectionEPSS 1.1%CVE-2022-3366HIGHPublishPress Capabilities < 2.5.2 - Admin+ PHP Objection InjectionEPSS 1.1%CVE-2024-7129HIGHAppointment Booking Calendar < 1.6.7.43 - Admin+ Template Injection to RCEEPSS 1.1%CVE-2022-3374HIGHOcean Extra < 2.0.5 - Admin+ PHP Objection InjectionEPSS 1.1%CVE-2022-3334HIGHEasy WP SMTP < 1.5.0 - Admin+ PHP Objection InjectionEPSS 1.1%CVE-2022-3380HIGHCustomizer Export/Import < 0.9.5 - Admin+ PHP Objection InjectionEPSS 1.1%CVE-2021-24840—Squaretype Modern Blog < 3.0.4 - Unauthenticated Private/Schedule Posts DisclosureEPSS 1.1%CVE-2022-1614—WP-Email < 2.69.0 - Anti-Spam Protection Bypass via IP SpoofingEPSS 1.1%CVE-2019-8956—In the Linux Kernel before versions 4.20.8 and 4.19.21 a use-after-free error in the "sctp_sendmsg()" function (net/sctp/socket.c) when handEPSS 1.1%CVE-2022-3076HIGHCM Download Manager < 2.8.6 - Admin+ Arbitrary File UploadEPSS 1.1%CVE-2023-2579—InventoryPress <= 1.7 - Author+ Stored XSSEPSS 1.1%CVE-2022-2367—WSM Downloader <= 1.4.0 - Domain Name Restriction BypassEPSS 1.1%CVE-2023-0080HIGHCustomer Reviews for WooCommerce < 5.16.0 - Contributor+ LFIEPSS 1.1%CVE-2021-25022MEDIUMUpdraftPlus < 1.16.66 - Reflected Cross-Site ScriptingEPSS 1.1%CVE-2023-1478CRITICALHummingbird < 3.4.2 - Unauthenticated Path Traversal EPSS 1.1%CVE-2022-1557—ULeak Security & Monitoring <= 1.2.3 - Subscriber+ Stored Cross-Site ScriptingEPSS 1.1%CVE-2021-24153—Yoast SEO < 3.4.1 - Authenticated Stored Cross-Site Scripting (XSS)EPSS 1.1%CVE-2021-25023—Speed Booster Pack < 4.3.3.1 - Admin+ SQL InjectionEPSS 1.1%