Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

615 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Repo-git-downloader Project Repo-git-downloader27/6/202217/6/2026
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloading crafted invalid git repositories.
ModificadaCrítica (9.8)2.0%—Pypi Cryptoasset-data-downloader24/6/202217/6/2026
The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaMedia (6.1)0.65%—Wp-filebase Download Manager Project Wp-filebase Download Manager24/6/202217/6/2026
A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.
ModificadaMedia (4.3)0.46%—W3eden Download Manager24/6/202217/6/2026
A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.
ModificadaMedia (6.1)1.2%—W3eden Download Manager13/6/202217/6/2026
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.
ModificadaMedia (6.5)0.42%—Files Download Delay Project Files Download Delay8/6/202217/6/2026
The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action.
ModificadaMedia (4.3)0.88%—Jdownloads6/5/202217/6/2026
In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files
ModificadaMedia (6.1)3.1%—Download Anti-malware Security AND Brute-force Firewall Project Download Anti-malware Security AND Brute-force Firewall25/4/202217/6/2026
The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters
ModificadaMedia (4.3)0.48%—Awesomemotive Easy Digital Downloads18/4/202217/6/2026
The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes, which could allow attackers to make a logged admin insert arbitrary notes via a CSRF attack
ModificadaMedia (4.8)0.66%—Awesomemotive Easy Digital Downloads18/4/202217/6/2026
The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed
ModificadaAlta (7.5)1.5%—W3eden Download Manager11/4/202217/6/2026
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.
ModificadaCrítica (9.8)2.6%—Cocoapods-downloader1/4/202217/6/2026
The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional…
ModificadaCrítica (9.8)1.7%—Cocoapods-downloader1/4/202217/6/2026
The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to…
ModificadaMedia (5.4)0.57%—Wp-downloadmanager Project Wp-downloadmanager25/3/202217/6/2026
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_url, &download_categories.
ModificadaMedia (5.4)0.56%—Wp-downloadmanager Project Wp-downloadmanager18/3/202217/6/2026
Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url.
ModificadaMedia (5.4)0.54%—Wp-downloadmanager Project Wp-downloadmanager18/3/202217/6/2026
Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 versions.
ModificadaMedia (6.5)1.4%—Tipsandtricks-hq Simple Download Monitor14/3/202217/6/2026
The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector.
ModificadaAlta (7.5)1.5%—W3eden Download Manager7/3/202217/6/2026
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).
ModificadaCrítica (9.1)1.6%—Alltubedownload Alltube28/2/202217/6/2026
Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.
AnalizadaAlta (8.8)1.5%—W3eden Download Manager21/2/202217/6/2026
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue
ModificadaMedia (6.8)1.4%—Wpchill Download Monitor28/1/202217/6/2026
Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to…
ModificadaMedia (4.8)84%—Wpchill Download Monitor28/1/202217/6/2026
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
ModificadaAlta (8.8)0.63%—Tipsandtricks-hq Simple Download Monitor24/1/202217/6/2026
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads
ModificadaMedia (5.4)0.61%—Tipsandtricks-hq Simple Download Monitor24/1/202217/6/2026
The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode.
ModificadaMedia (5.4)0.57%—Wpchill Download Monitor14/1/202217/6/2026
Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6).
Orbitaley — Vulnerabilidades