Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.1) | 0.38% | — | Awesomemotive Easy Digital Downloads | 12/8/2024 | 17/6/2026 | The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Agreement Text value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it… | |
| Analizada | Media (4) | 0.35% | — | Awesomemotive Easy Digital Downloads | 12/8/2024 | 17/6/2026 | The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the currency value in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Analizada | Media (5.4) | 0.39% | — | W3eden Download Manager | 31/7/2024 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_all_packages' shortcode in all versions up to, and including, 3.2.97 due to insufficient input sanitization and output escaping on the 'cols' parameter. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.25% | — | Clicklabs Download Button FOR ElementorAI | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in clicklabs® Medienagentur Download Button for Elementor allows Stored XSS.This issue affects Download Button for Elementor: from n/a through 1.2.1. | |
| Modificada | Media (5.3) | 0.47% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter. | |
| Modificada | Media (5.3) | 0.34% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive. | |
| Modificada | Crítica (9.8) | 0.61% | — | Virtosoftware Sharepoint Bulk File Download | 24/6/2024 | 17/6/2026 | An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter. | |
| Aplazada | Alta (7.2) | 0.62% | — | Asus Download MasterAI | 14/6/2024 | 17/6/2026 | ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device. | |
| Aplazada | Alta (7.2) | 0.65% | — | Asus Download MasterAI | 14/6/2024 | 17/6/2026 | The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device. | |
| Modificada | Alta (7.2) | 0.53% | — | Asus Download Master | 14/6/2024 | 17/6/2026 | The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be… | |
| Modificada | Media (4.8) | 0.29% | — | Asus Download Master | 14/6/2024 | 17/6/2026 | The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Stored Cross-site scripting attacks. | |
| Modificada | Media (4.8) | 0.29% | — | Asus Download Master | 14/6/2024 | 17/6/2026 | The parameter used in the certain page of ASUS Download Master is not properly filtered for user input. A remote attacker with administrative privilege can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks. | |
| Modificada | Alta (7.5) | 0.45% | — | W3eden Download Manager | 13/6/2024 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to unauthorized access of data due to an improper authorization check on the 'protectMediaLibrary' function in all versions up to, and including, 3.2.89. This makes it possible for unauthenticated attackers to download password-protected files. | |
| Modificada | Media (5.4) | 0.33% | — | W3eden Download Manager | 12/6/2024 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a user's Display Name in all versions up to, and including, 3.2.86 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject… | |
| Modificada | Media (5.4) | 0.42% | — | W3eden Download Manager | 12/6/2024 | 17/6/2026 | The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpdm_user_dashboard, wpdm_package, wpdm_packages, wpdm_search_result, and wpdm_tag shortcodes in all versions up to, and including, 3.2.92 due to insufficient input sanitization and output escaping on user supplied… | |
| Modificada | Media (5.4) | 0.26% | — | Wpdownloadmanager Download Manager | 5/6/2024 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Crítica (9.8) | 0.54% | — | Wow-company Easy Digital Downloads | 4/6/2024 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Wow-Company Easy Digital Downloads – Recent Purchases allows PHP Remote File Inclusion.This issue affects Easy Digital Downloads – Recent Purchases: from n/a through 1.0.2. | |
| Aplazada | Media (6.4) | 0.33% | — | Dfactory Download AttachmentsAI | 4/6/2024 | 17/6/2026 | The Download Attachments plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'download-attachments' shortcode in all versions up to, and including, 1.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.4) | 0.34% | — | W3eden Download Manager | 31/5/2024 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm-all-packages' shortcode in all versions up to, and including, 3.2.90 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (5.4) | 0.30% | — | Download MonitorAI | 30/5/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized access to functionality due to a missing capability check on the dlm_uninstall_plugin function in all versions up to, and including, 4.9.13. This makes it possible for authenticated attackers to uninstall the plugin and delete its data. | |
| Aplazada | Media (6.5) | 0.67% | — | Wpfactory Download Plugins AND Themes From DashboardAI | 22/5/2024 | 17/6/2026 | Path traversal vulnerability exists in Download Plugins and Themes from Dashboard versions prior to 1.8.6. If this vulnerability is exploited, a remote authenticated attacker with "switch_themes" privilege may obtain arbitrary files on the server. | |
| Analizada | Alta (7.5) | 0.40% | — | W3eden Download Manager | 17/5/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in W3 Eden Inc. Download Manager allows Functionality Bypass.This issue affects Download Manager: from n/a through 3.2.82. | |
| Aplazada | Crítica (10) | 1.2% | — | Urbanbase Z-downloadsAI | 14/5/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in URBAN BASE Z-Downloads.This issue affects Z-Downloads: from n/a through 1.11.3. | |
| Modificada | Alta (7.5) | 0.64% | — | Sandhillsdev Easy Digital Downloads | 14/5/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11. | |
| Modificada | Alta (8.8) | 0.22% | — | Sandhillsdev Easy Digital Downloads | 14/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.11. |