Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

615 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)17%💥 ExploitWpchill Download Monitor3/1/202217/6/2026
The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue
ModificadaMedia (5.4)0.60%—W3eden Download Manager27/12/202117/6/2026
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is…
ModificadaAlta (8.8)1.4%—Mandsconsulting Email Before Download29/11/202117/6/2026
The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues
ModificadaMedia (5.7)0.40%—Metagauss Download Plugin23/11/202117/6/2026
The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed.
ModificadaMedia (4.3)0.68%—Tipsandtricks-hq Simple Download Monitor8/11/202117/6/2026
The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download.
ModificadaMedia (6.1)0.83%—Tipsandtricks-hq Simple Download Monitor8/11/202117/6/2026
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
ModificadaAlta (7.5)1.7%—Tipsandtricks-hq Simple Download Monitor8/11/202117/6/2026
The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames
ModificadaCrítica (9)1.3%—Tipsandtricks-hq Simple Download Monitor8/11/202117/6/2026
The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review…
ModificadaMedia (4.8)2.9%—W3eden Download Manager1/11/202117/6/2026
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (5.4)0.62%—Easy Media Download Project Easy Media Download25/10/202117/6/2026
The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
ModificadaMedia (6.7)0.41%—Tonec Internet Download Manager22/10/202117/6/2026
Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Search function. This vulnerability allows attackers to escalate local process privileges via unspecified vectors.
ModificadaAlta (7.1)0.41%—Tonec Internet Download Manager22/10/202117/6/2026
Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Export/Import function. This vulnerability allows attackers to escalate local process privileges via a crafted ef2 file.
ModificadaMedia (4.8)0.93%—Awesomemotive Easy Digital Downloads21/10/202117/6/2026
The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2.
ModificadaAlta (8.8)0.58%—W3eden Download Manager5/8/202117/6/2026
Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.
ModificadaMedia (6.5)1.3%—W3eden Download Manager5/8/202117/6/2026
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded…
ModificadaAlta (8.1)1.7%—Cminds CM Download Manager7/7/202117/6/2026
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.
ModificadaMedia (6.1)1.00%—Cminds CM Download Manager7/7/202117/6/2026
Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action.
ModificadaAlta (7.5)2.0%—Ninjateam Video Downloader FOR Tiktok7/7/202117/6/2026
Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.
ModificadaCrítica (9.8)1.7%—Ninjateam Video Downloader FOR Tiktok7/7/202117/6/2026
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open ports, local network hosts and execute…
ModificadaMedia (5.3)0.93%—Wp-downloadmanager Project Wp-downloadmanager7/7/202117/6/2026
Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute command on services
ModificadaMedia (4.3)0.76%—Synology Download Station18/6/202117/6/2026
Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors.
ModificadaAlta (8.8)1.4%—Synology Download Station18/6/202117/6/2026
Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.
ModificadaAlta (8.8)1.9%—Synology Download Station18/6/202117/6/2026
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.7)1.0%—Synology Download Station1/6/202117/6/2026
Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authenticated users to read arbitrary files via unspecified vectors.
ModificadaAlta (7.2)1.3%—Shipment 100-design Material Download System Project Shipment 100-design Material Download System29/4/202117/6/2026
SQL injection in the getip function in conn/function.php in 发货100-设计素材下载系统 1.1 allows remote attackers to inject arbitrary SQL commands via the X-Forwarded-For header to admin/product_add.php.