Vulnerabilidades em unknown

4.777 resultados
Análise Vexday

O fornecedor acumula 13 vulnerabilidades na base, das quais 2 são críticas (CVSS ≥ 9.0), mas nenhuma está sob ataque ativo no momento. A fraqueza dominante é CWE-121 (stack-based buffer overflow), um vetor clássico de exploração com potencial elevado. A ausência de publicações recentes nos últimos 90 dias sugere risco estabilizado, porém a presença de críticas demanda atenção continuada ao aplicar patches.

CVE-2026-4106MEDIUMHT Mega < 3.0.7 – Unauthenticated PII DisclosureEPSS 0.7%CVE-2022-3359HIGHShortcodes and extra features for Phlox theme < 2.10.7 - PHP Objection InjectionEPSS 0.7%CVE-2022-3981HIGHIcegram Express < 5.5.1 - Subscriber+ SQLiEPSS 0.7%CVE-2024-3822MEDIUMBase64 Encoder/Decoder <= 0.9.2 - Reflected XSSEPSS 0.7%CVE-2021-25102All In One WP Security < 4.4.11 - Authenticated Reflected Cross-Site ScriptingEPSS 0.7%CVE-2022-1600YOP Poll < 6.4.3 - IP SpoofingEPSS 0.7%CVE-2024-6847CRITICALSmartSearch WP <= 2.4.4 - Unauthenticated SQLiEPSS 0.7%CVE-2023-1809HIGHDownload Manager Pro < 6.3.0 - Unauthenticated Sensitive Information DisclosureEPSS 0.7%CVE-2022-2341Simple Page Transition <= 1.4.1 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-2340W-DALIL <= 2.0 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-1524MEDIUMDownload Manager < 3.2.71 - Broken Access ControlsEPSS 0.7%CVE-2023-4294MEDIUMURL Shortify < 1.7.6 - Unauthenticated Stored XSS via referer headerEPSS 0.7%CVE-2021-24152Popup Builder < 3.74 - Authenticated Reflected Cross-Site Scripting (XSS)EPSS 0.7%CVE-2023-3139Protect WP Admin < 4.0 - Unauthenticated Protection BypassEPSS 0.7%CVE-2024-9422MEDIUMGEO My WordPress < 4.5 - Admin+ Arbitrary File UploadEPSS 0.7%CVE-2021-24841Helpful < 4.4.59 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2023-0441HIGHGallery Blocks with Lightbox < 3.0.8 - Subscriber+ Arbitrary Options UpdateEPSS 0.7%CVE-2022-0969Image optimization & Lazy Load < 3.3.2 - Admin+ Stored Cross-Site ScriptingEPSS 0.7%CVE-2022-4746HIGHFluentAuth < 1.0.2 - Bypass blocks by IP SpoofingEPSS 0.7%CVE-2021-24560Software License Manager < 4.4.8 - Reflected Cross-Site ScriptingEPSS 0.7%