Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.57% | — | W3eden Download Manager | 16/1/2023 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.62 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks against logged-in admins. | |
| Modificada | Media (4.3) | 0.66% | — | Metagauss Download Plugin | 28/11/2022 | 17/6/2026 | The Download Plugin WordPress plugin before 2.0.0 does not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download a full copy of the website. | |
| Modificada | Crítica (9.8) | 1.3% | — | Awesomemotive Easy Digital Downloads | 21/11/2022 | 17/6/2026 | The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection. | |
| Modificada | Media (4.3) | 0.30% | — | Awesomemotive Easy Digital Downloads | 7/11/2022 | 17/6/2026 | The Easy Digital Downloads WordPress plugin before 3.0 does not have CSRF check in place when deleting payment history, and does not ensure that the post to be deleted is actually a payment history. As a result, attackers could make a logged in admin delete arbitrary post via a CSRF attack | |
| Modificada | Media (5.3) | 0.64% | — | Jenkins Compuware Source Code Download FOR Endevor, Pds, AND Ispw | 19/10/2022 | 17/6/2026 | Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of Java system properties from the Jenkins controller process. | |
| Modificada | Media (4.9) | 1.1% | — | Wpchill Download Monitor | 10/10/2022 | 17/6/2026 | The Download Monitor WordPress plugin before 4.5.98 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup. | |
| Modificada | Alta (7.2) | 1.5% | — | Cminds CM Download Manager | 26/9/2022 | 17/6/2026 | The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example. | |
| Modificada | Media (4.9) | 1.7% | — | Adobe Download Manager | 26/9/2022 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory | |
| Modificada | Media (5.3) | 0.70% | — | Mangadex-downloader Project Mangadex-downloader | 7/9/2022 | 17/6/2026 | mangadex-downloader is a command-line tool to download manga from MangaDex. When using `file:<location>` command and `<location>` is a web URL location (http, https), mangadex-downloader between versions 1.3.0 and 1.7.2 will try to open and read a file in local disk for each line of website contents. Version 1.7.2… | |
| Modificada | Alta (8.8) | 2.0% | — | W3eden Download Manager | 6/9/2022 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to deserialization of untrusted input via the 'file[package_dir]' parameter in versions up to, and including 3.2.49. This makes it possible for authenticated attackers with contributor privileges and above to call files using a PHAR wrapper that will deserialize… | |
| Modificada | Alta (8.8) | 3.8% | — | W3eden Download Manager | 6/9/2022 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to arbitrary file deletion in versions up to, and including 3.2.50. This is due to insufficient file type and path validation on the deleteFiles() function found in the ~/Admin/Menu/Packages.php file that triggers upon download post deletion. This makes it… | |
| Modificada | Alta (8.8) | 0.34% | — | W3eden Download Manager | 23/8/2022 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. | |
| Modificada | Media (5.4) | 0.56% | — | W3eden Download Manager | 23/8/2022 | 17/6/2026 | Multiple Authenticated (contributor+) Persistent Cross-Site Scripting (XSS) vulnerabilities in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. | |
| Modificada | Alta (8.8) | 0.37% | — | W3eden Download Manager | 22/8/2022 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in W3 Eden Download Manager plugin <= 3.2.48 at WordPress. | |
| Modificada | Alta (7.2) | 0.90% | — | Awesomemotive Easy Digital Downloads | 22/8/2022 | 17/6/2026 | PHP Object Injection vulnerability in Easy Digital Downloads plugin <= 3.0.1 at WordPress. | |
| Modificada | Media (6.5) | 1.1% | — | Lana Downloads Manager | 22/8/2022 | 17/6/2026 | The Lana Downloads Manager WordPress plugin before 1.8.0 is affected by an arbitrary file download vulnerability that can be exploited by users with "Contributor" permissions or higher. | |
| Modificada | Alta (7.5) | 1.2% | — | W3eden Download Manager | 22/8/2022 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.50 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based download blocking restrictions. | |
| Modificada | Alta (7.8) | 0.30% | — | Power-software-download Viewpower | 16/8/2022 | 17/6/2026 | upsMonitor in ViewPower (aka ViewPowerHTML) 1.04-21012 through 1.04-21353 has insecure permissions for the service binary that enable an Authenticated User to modify files, allowing for privilege escalation. | |
| Modificada | Alta (7.5) | 1.2% | — | WSM Downloader Project WSM Downloader | 8/8/2022 | 17/6/2026 | The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to download images/files from, this can be bypassed due to the lack of good "link" parameter validation | |
| Modificada | Alta (7.5) | 1.4% | — | WSM Downloader Project WSM Downloader | 8/8/2022 | 17/6/2026 | The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file download feature to download any local files, including sensitive ones like wp-config.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Project-source-code-download Project Project-source-code-download | 1/8/2022 | 17/6/2026 | The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup generation and download functionalities, which may allow any visitors on the site to download the entire site, including sensitive files like wp-config.php. | |
| Modificada | Media (6.5) | 0.70% | — | Jenkins Compuware Source Code Download FOR Endevor, Pds, AND Ispw | 27/7/2022 | 17/6/2026 | A missing permission check in Jenkins Compuware Source Code Download for Endevor, PDS, and ISPW Plugin 2.0.12 and earlier allows attackers with Overall/Read permission to enumerate hosts and ports of Compuware configurations and credentials IDs of credentials stored in Jenkins. | |
| Modificada | Media (5.4) | 1.1% | — | W3eden Download Manager | 18/7/2022 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `file[files][]` parameter in versions up to, and including, 3.2.46 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with contributor level permissions and above… | |
| Modificada | Media (4.9) | 1.1% | — | Wpchill Download Monitor | 17/7/2022 | 17/6/2026 | The Download Monitor WordPress plugin before 4.5.91 does not ensure that files to be downloaded are inside the blog folders, and not sensitive, allowing high privilege users such as admin to download the wp-config.php or /etc/passwd even in an hardened environment or multisite setup. | |
| Analizada | Media (6.1) | 1.4% | 💥 Exploit | W3eden Download Manager | 17/7/2022 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.44 does not escape a generated URL before outputting it back in an attribute of the history dashboard, leading to Reflected Cross-Site Scripting |