Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Repo-git-downloader Project Repo-git-downloader | 27/6/2022 | 17/6/2026 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloading crafted invalid git repositories. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Cryptoasset-data-downloader | 24/6/2022 | 17/6/2026 | The cryptoasset-data-downloader package in PyPI v1.0.0 to v1.0.1 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Media (6.1) | 0.65% | — | Wp-filebase Download Manager Project Wp-filebase Download Manager | 24/6/2022 | 17/6/2026 | A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. | |
| Modificada | Media (4.3) | 0.46% | — | W3eden Download Manager | 24/6/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. | |
| Modificada | Media (6.1) | 1.2% | — | W3eden Download Manager | 13/6/2022 | 17/6/2026 | The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file. | |
| Modificada | Media (6.5) | 0.42% | — | Files Download Delay Project Files Download Delay | 8/6/2022 | 17/6/2026 | The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action. | |
| Modificada | Media (4.3) | 0.88% | — | Jdownloads | 6/5/2022 | 17/6/2026 | In Joomla component 'jDownloads 3.9.8.2 Stable' the remote user can change some parameters in the address bar and see the names of other users' files | |
| Modificada | Media (6.1) | 3.1% | — | Download Anti-malware Security AND Brute-force Firewall Project Download Anti-malware Security AND Brute-force Firewall | 25/4/2022 | 17/6/2026 | The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.20.96 does not sanitise and escape the QUERY_STRING before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting in browsers which do not encode characters | |
| Modificada | Media (4.3) | 0.48% | — | Awesomemotive Easy Digital Downloads | 18/4/2022 | 17/6/2026 | The Easy Digital Downloads WordPress plugin before 2.11.6 does not have CSRF check in place when inserting payment notes, which could allow attackers to make a logged admin insert arbitrary notes via a CSRF attack | |
| Modificada | Media (4.8) | 0.66% | — | Awesomemotive Easy Digital Downloads | 18/4/2022 | 17/6/2026 | The Easy Digital Downloads WordPress plugin before 2.11.6 does not sanitise and escape the Downloadable File Name in the Logs, which could allow high privilege users to perform Cross-Site Scripting attacks when the unfiltered_html capability is disallowed | |
| Modificada | Alta (7.5) | 1.5% | — | W3eden Download Manager | 11/4/2022 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download. | |
| Modificada | Crítica (9.8) | 2.6% | — | Cocoapods-downloader | 1/4/2022 | 17/6/2026 | The package cocoapods-downloader before 1.6.0, from 1.6.2 and before 1.6.3 are vulnerable to Command Injection via git argument injection. When calling the Pod::Downloader.preprocess_options function and using git, both the git and branch parameters are passed to the git ls-remote subcommand in a way that additional… | |
| Modificada | Crítica (9.8) | 1.7% | — | Cocoapods-downloader | 1/4/2022 | 17/6/2026 | The package cocoapods-downloader before 1.6.2 are vulnerable to Command Injection via hg argument injection. When calling the download function (when using hg), the url (and/or revision, tag, branch) is passed to the hg clone command in a way that additional flags can be set. The additional flags can be used to… | |
| Modificada | Media (5.4) | 0.57% | — | Wp-downloadmanager Project Wp-downloadmanager | 25/3/2022 | 17/6/2026 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vulnerable parameters &download_path, &download_path_url, &download_page_url, &download_categories. | |
| Modificada | Media (5.4) | 0.56% | — | Wp-downloadmanager Project Wp-downloadmanager | 18/3/2022 | 17/6/2026 | Multiple Authenticated Stored Cross-Site Scripting (XSS) vulnerabilities discovered in WP-DownloadManager WordPress plugin (versions <= 1.68.6). Vvulnerable parameters &download_path, &download_path_url, &download_page_url. | |
| Modificada | Media (5.4) | 0.54% | — | Wp-downloadmanager Project Wp-downloadmanager | 18/3/2022 | 17/6/2026 | Auth. (admin+) Reflected Cross-Site Scripting (XSS) vulnerability discovered in WP-DownloadManager plugin <= 1.68.6 versions. | |
| Modificada | Media (6.5) | 1.4% | — | Tipsandtricks-hq Simple Download Monitor | 14/3/2022 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.5 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector. | |
| Modificada | Alta (7.5) | 1.5% | — | W3eden Download Manager | 7/3/2022 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25). | |
| Modificada | Crítica (9.1) | 1.6% | — | Alltubedownload Alltube | 28/2/2022 | 17/6/2026 | Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2. | |
| Analizada | Alta (8.8) | 1.5% | — | W3eden Download Manager | 21/2/2022 | 17/6/2026 | The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue | |
| Modificada | Media (6.8) | 1.4% | — | Wpchill Download Monitor | 28/1/2022 | 17/6/2026 | Authenticated (admin+) Arbitrary File Download vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6). The plugin allows arbitrary files, including sensitive configuration files such as wp-config.php, to be downloaded via the &downloadable_file_urls[0] parameter data. It's also possible to… | |
| Modificada | Media (4.8) | 84% | — | Wpchill Download Monitor | 28/1/2022 | 17/6/2026 | Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0]. | |
| Modificada | Alta (8.8) | 0.63% | — | Tipsandtricks-hq Simple Download Monitor | 24/1/2022 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which could allow attackers to perform CSRF attacks to 1) make admins export logs to exploit a separate log disclosure vulnerability (fixed in 3.9.6), 2) delete logs (fixed in 3.9.9), 3) remove thumbnail image from downloads | |
| Modificada | Media (5.4) | 0.61% | — | Tipsandtricks-hq Simple Download Monitor | 24/1/2022 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.11 could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attack via 1) "color" or "css_class" argument of sdm_download shortcode, 2) "class" or "placeholder" argument of sdm_search_form shortcode. | |
| Modificada | Media (5.4) | 0.57% | — | Wpchill Download Monitor | 14/1/2022 | 17/6/2026 | Authenticated Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress plugin Download Monitor (versions <= 4.4.6). |