Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.9) | 0.36% | — | Alttext.ai Download ALT Text AIAI | 6/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AltText.Ai Download Alt Text AI allows Stored XSS.This issue affects Download Alt Text AI: from n/a through 1.3.4. | |
| Aplazada | Media (5.9) | 0.34% | — | Rimes Gold CF7 File DownloadAI | 26/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rimes Gold CF7 File Download – File Download for CF7 allows Stored XSS.This issue affects CF7 File Download – File Download for CF7: from n/a through 2.0. | |
| Aplazada | Media (6.5) | 0.34% | — | Joomunited WP File Download LightAI | 17/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in JoomUnited WP File Download Light allows Stored XSS.This issue affects WP File Download Light: from n/a through 1.3.3. | |
| Modificada | Alta (8.8) | 0.23% | — | Sandhillsdev Easy Digital Downloads | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.6. | |
| Aplazada | Media (6.5) | 0.31% | — | WP Enhanced Free Downloads Woocommerce Free Downloads WoocommerceAI | 11/4/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Enhanced Free Downloads WooCommerce allows Stored XSS.This issue affects Free Downloads WooCommerce: from n/a through 3.5.8.2. | |
| Modificada | Media (5.3) | 0.60% | — | Awesomemotive Easy Digital Downloads | 9/4/2024 | 17/6/2026 | The Easy Digital Downloads – Sell Digital Files & Subscriptions (eCommerce Store + Payments Made Easy) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to download the debug log via Directory Listing.… | |
| Modificada | Alta (7.2) | 0.61% | — | Wpchill Download Monitor | 29/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.9.4. | |
| Analizada | Alta (8.8) | 0.47% | — | Cminds CM Download Manager | 25/3/2024 | 17/6/2026 | The CM Download Manager WordPress plugin before 2.9.1 does not have CSRF checks in some places, which could allow attackers to make logged in admins edit downloads via a CSRF attack | |
| Analizada | Media (4.8) | 0.24% | — | Cminds CM Download Manager | 25/3/2024 | 17/6/2026 | The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins delete downloads via a CSRF attack | |
| Analizada | Media (6.8) | 0.22% | — | Cminds CM Download Manager | 25/3/2024 | 17/6/2026 | The CM Download Manager WordPress plugin before 2.9.0 does not have CSRF checks in some places, which could allow attackers to make logged in admins unpublish downloads via a CSRF attack | |
| Modificada | Alta (8.8) | 0.44% | — | Jeandaviddaviet Download Media | 21/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Jean-David Daviet Download Media.This issue affects Download Media: from n/a through 1.4.2. | |
| Modificada | Media (5.4) | 0.34% | — | W3eden Download Manager | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in W3 Eden, Inc. Download Manager allows Stored XSS.This issue affects Download Manager: from n/a through 3.2.84. | |
| Modificada | Media (5.4) | 0.54% | — | W3eden Download Manager | 13/3/2024 | 17/6/2026 | The Download Manager Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.2.85 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Media (5.3) | 0.55% | — | W3eden Download Manager | 13/3/2024 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to unauthorized file download of files added via the plugin in all versions up to, and including, 3.2.84. This makes it possible for unauthenticated attackers to download files added with the plugin (even when privately published). | |
| Analizada | Alta (8.8) | 0.28% | — | Mandsconsulting Email Before Download | 29/2/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in M&S Consulting Email Before Download.This issue affects Email Before Download: from n/a through 6.9.7. | |
| Modificada | Media (4.8) | 0.40% | — | Awesomemotive Easy Digital Downloads | 5/2/2024 | 17/6/2026 | The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing option title in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Modificada | Media (5.4) | 0.33% | — | Awesomemotive Easy Digital Downloads | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Digital Downloads Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) allows Stored XSS.This issue affects Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments… | |
| Modificada | Media (5.4) | 0.33% | — | Structured-data-for-wp Download Schema & Structured Data FOR WP & AMP | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magazine3 Schema & Structured Data for WP & AMP allows Stored XSS.This issue affects Schema & Structured Data for WP & AMP: from n/a through 1.23. | |
| Modificada | Alta (7.5) | 0.80% | — | Unknown-o Download-station | 10/1/2024 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in unknown-o download-station up to 1.1.8. This issue affects some unknown processing of the file index.php. The manipulation of the argument f leads to path traversal: '../filedir'. The attack may be initiated remotely. The exploit has been disclosed… | |
| Modificada | Alta (7.5) | 38% | 💥 Exploit | Wpchill Download Monitor | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.7.60. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | W3eden Download Manager | 1/1/2024 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one. | |
| Modificada | Crítica (9.8) | 0.63% | — | Boiteasite Download Rencontre - Dating Site | 29/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Jacques Malgrange Rencontre – Dating Site.This issue affects Rencontre – Dating Site: from n/a through 3.10.1. | |
| Modificada | Alta (8.8) | 0.91% | — | Wpchill Download Monitor | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.3. | |
| Modificada | Media (5.3) | 0.62% | — | Gopiplus Email Download Link | 30/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Gopi Ramasamy Email download link.This issue affects Email download link: from n/a through 3.7. | |
| Modificada | Media (4.9) | 0.65% | — | Wpchill Download Monitor | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in WPChill Download Monitor.This issue affects Download Monitor: from n/a through 4.8.1. |