Vulnerabilidades em Unknown
4.561 resultadosAnálise Vexday
O fornecedor apresenta um portfólio de 4.268 vulnerabilidades, com 144 publicadas nos últimos 90 dias, indicando exposição contínua a riscos. Embora nenhuma esteja sob ataque ativo documentado no KEV, as 124 vulnerabilidades críticas e a predominância de falhas de validação de entrada (CWE-79) representam vetores de exploração significativos que demandam atenção imediata em priorização de patches.
CVE-2021-24145—Modern Events Calendar Lite < 5.16.5 - Authenticated Arbitrary File Upload leading to RCEEPSS 88.2%CVE-2021-24762—Perfect Survey < 1.5.2 - Unauthenticated SQL InjectionEPSS 86.8%CVE-2022-0441—MasterStudy LMS < 2.7.6 - Unauthenticated Admin Account CreationEPSS 85.3%CVE-2021-25080—Contact Form Entries < 1.1.7 - Unauthenticated Stored Cross-Site ScriptingEPSS 84.2%CVE-2021-24155—Backup Guard < 1.6.0 - Authenticated Arbitrary File UploadEPSS 84.1%CVE-2022-2753—Ketchup Restaurant Reservations <= 1.0.0 - Unauthenticated Stored XSSEPSS 83.4%CVE-2021-25094—Tatsu < 3.3.12 - Unauthenticated RCEEPSS 83.4%CVE-2021-25114—Paid Memberships Pro < 2.6.7 - Unauthenticated Blind SQL InjectionEPSS 81.8%CVE-2023-5360—Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File UploadEPSS 81.7%CVE-2021-24931—Secure Copy Content Protection and Content Locking < 2.8.2 - Unauthenticated SQL InjectionEPSS 78.8%CVE-2022-0169—Photo Gallery by 10Web < 1.6.0 - Unauthenticated SQL InjectionEPSS 74.6%CVE-2023-6063—WP Fastest Cache < 1.2.2 - Unauthenticated SQL InjectionEPSS 73.7%CVE-2021-24862—RegistrationMagic < 5.0.1.6 - Admin+ SQL InjectionEPSS 73.3%CVE-2021-24946—Modern Events Calendar < 6.1.5 - Unauthenticated Blind SQL InjectionEPSS 72.8%CVE-2023-3460—Ultimate Member < 2.6.7 - Unauthenticated Privilege EscalationEPSS 72.3%CVE-2022-1386—Fusion Builder < 3.6.2 - Unauthenticated SSRFEPSS 72.1%CVE-2021-24917—WPS Hide Login < 1.9.1 - Protection Bypass with Referer-HeaderEPSS 71.5%CVE-2022-0364—Modern Events Calendar Lite < 6.4.0 - Contributor+ Stored Cross Site ScriptingEPSS 69.6%CVE-2024-3552CRITICALWeb Directory Free < 1.7.0 - Unauthenticated SQL InjectionEPSS 67.3%CVE-2022-4830MEDIUMPaid Memberships Pro < 2.9.9 - Contributor+ Stored XSS via ShortcodeEPSS 65.0%