Vulnerabilidades em unknown
4.777 resultadosAnálise Vexday
O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.
CVE-2026-4106MEDIUMHT Mega < 3.0.7 – Unauthenticated PII DisclosureEPSS 0.7%CVE-2022-3359HIGHShortcodes and extra features for Phlox theme < 2.10.7 - PHP Objection InjectionEPSS 0.7%CVE-2022-3981HIGHIcegram Express < 5.5.1 - Subscriber+ SQLiEPSS 0.7%CVE-2024-3822MEDIUMBase64 Encoder/Decoder <= 0.9.2 - Reflected XSSEPSS 0.7%CVE-2021-25102—All In One WP Security < 4.4.11 - Authenticated Reflected Cross-Site ScriptingEPSS 0.7%CVE-2022-1600—YOP Poll < 6.4.3 - IP SpoofingEPSS 0.7%CVE-2024-6847CRITICALSmartSearch WP <= 2.4.4 - Unauthenticated SQLiEPSS 0.7%CVE-2023-1809HIGHDownload Manager Pro < 6.3.0 - Unauthenticated Sensitive Information DisclosureEPSS 0.7%CVE-2022-2341—Simple Page Transition <= 1.4.1 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-2340—W-DALIL <= 2.0 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-1524MEDIUMDownload Manager < 3.2.71 - Broken Access ControlsEPSS 0.7%CVE-2023-4294MEDIUMURL Shortify < 1.7.6 - Unauthenticated Stored XSS via referer headerEPSS 0.7%CVE-2021-24152—Popup Builder < 3.74 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2023-3139—Protect WP Admin < 4.0 - Unauthenticated Protection BypassEPSS 0.7%CVE-2024-9422MEDIUMGEO My WordPress < 4.5 - Admin+ Arbitrary File UploadEPSS 0.7%CVE-2021-24841—Helpful < 4.4.59 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-0441HIGHGallery Blocks with Lightbox < 3.0.8 - Subscriber+ Arbitrary Options UpdateEPSS 0.7%CVE-2022-0969—Image optimization & Lazy Load < 3.3.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-4746HIGHFluentAuth < 1.0.2 - Bypass blocks by IP SpoofingEPSS 0.7%CVE-2021-24560—Software License Manager < 4.4.8 - Reflected Cross-Site ScriptingEPSS 0.7%