Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 17% | 💥 Exploit | Wpchill Download Monitor | 3/1/2022 | 17/6/2026 | The Download Monitor WordPress plugin before 4.4.5 does not properly validate and escape the "orderby" GET parameter before using it in a SQL statement when viewing the logs, leading to an SQL Injection issue | |
| Modificada | Media (5.4) | 0.60% | — | W3eden Download Manager | 27/12/2021 | 17/6/2026 | The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is… | |
| Modificada | Alta (8.8) | 1.4% | — | Mandsconsulting Email Before Download | 29/11/2021 | 17/6/2026 | The Email Before Download WordPress plugin before 6.8 does not properly validate and escape the order and orderby GET parameters before using them in SQL statements, leading to authenticated SQL injection issues | |
| Modificada | Media (5.7) | 0.40% | — | Metagauss Download Plugin | 23/11/2021 | 17/6/2026 | The Download Plugin WordPress plugin before 1.6.1 does not have capability and CSRF checks in the dpwap_plugin_activate AJAX action, allowing any authenticated users, such as subscribers, to activate plugins that are already installed. | |
| Modificada | Media (4.3) | 0.68% | — | Tipsandtricks-hq Simple Download Monitor | 8/11/2021 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.6 allows users with a role as low as Contributor to remove thumbnails from downloads they do not own, even if they cannot normally edit the download. | |
| Modificada | Media (6.1) | 0.83% | — | Tipsandtricks-hq Simple Download Monitor | 8/11/2021 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the 1) sdm_active_tab GET parameter and 2) sdm_stats_start_date/sdm_stats_end_date POST parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues | |
| Modificada | Alta (7.5) | 1.7% | — | Tipsandtricks-hq Simple Download Monitor | 8/11/2021 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.6 saves logs in a predictable location, and does not have any authentication or authorisation in place to prevent unauthenticated users to download and read the logs containing Sensitive Information such as IP Addresses and Usernames | |
| Modificada | Crítica (9) | 1.3% | — | Tipsandtricks-hq Simple Download Monitor | 8/11/2021 | 17/6/2026 | The Simple Download Monitor WordPress plugin before 3.9.5 does not escape the "File Thumbnail" post meta before outputting it in some pages, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. Given the that XSS is triggered even when the Download is in a review… | |
| Modificada | Media (4.8) | 2.9% | — | W3eden Download Manager | 1/11/2021 | 17/6/2026 | The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (5.4) | 0.62% | — | Easy Media Download Project Easy Media Download | 25/10/2021 | 17/6/2026 | The Easy Media Download WordPress plugin before 1.1.7 does not escape the text argument of its shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.7) | 0.41% | — | Tonec Internet Download Manager | 22/10/2021 | 17/6/2026 | Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Search function. This vulnerability allows attackers to escalate local process privileges via unspecified vectors. | |
| Modificada | Alta (7.1) | 0.41% | — | Tonec Internet Download Manager | 22/10/2021 | 17/6/2026 | Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Export/Import function. This vulnerability allows attackers to escalate local process privileges via a crafted ef2 file. | |
| Modificada | Media (4.8) | 0.93% | — | Awesomemotive Easy Digital Downloads | 21/10/2021 | 17/6/2026 | The Easy Digital Downloads WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the $start_date and $end_date parameters found in the ~/includes/admin/payments/class-payments-table.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.11.2. | |
| Modificada | Alta (8.8) | 0.58% | — | W3eden Download Manager | 5/8/2021 | 17/6/2026 | Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions. | |
| Modificada | Media (6.5) | 1.3% | — | W3eden Download Manager | 5/8/2021 | 17/6/2026 | Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded… | |
| Modificada | Alta (8.1) | 1.7% | — | Cminds CM Download Manager | 7/7/2021 | 17/6/2026 | Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action. | |
| Modificada | Media (6.1) | 1.00% | — | Cminds CM Download Manager | 7/7/2021 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action. | |
| Modificada | Alta (7.5) | 2.0% | — | Ninjateam Video Downloader FOR Tiktok | 7/7/2021 | 17/6/2026 | Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter. | |
| Modificada | Crítica (9.8) | 1.7% | — | Ninjateam Video Downloader FOR Tiktok | 7/7/2021 | 17/6/2026 | Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open ports, local network hosts and execute… | |
| Modificada | Media (5.3) | 0.93% | — | Wp-downloadmanager Project Wp-downloadmanager | 7/7/2021 | 17/6/2026 | Server-side request forgery in the WP-DownloadManager plugin 1.68.4 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the file_remote parameter to download-add.php. It can help identify open ports, local network hosts and execute command on services | |
| Modificada | Media (4.3) | 0.76% | — | Synology Download Station | 18/6/2021 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to access intranet resources via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.4% | — | Synology Download Station | 18/6/2021 | 17/6/2026 | Improper privilege management vulnerability in cgi component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.9% | — | Synology Download Station | 18/6/2021 | 17/6/2026 | Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.7) | 1.0% | — | Synology Download Station | 1/6/2021 | 17/6/2026 | Server-Side request forgery (SSRF) vulnerability in task management component in Synology Download Station before 3.8.15-3563 allows remote authenticated users to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.3% | — | Shipment 100-design Material Download System Project Shipment 100-design Material Download System | 29/4/2021 | 17/6/2026 | SQL injection in the getip function in conn/function.php in 发货100-设计素材下载系统 1.1 allows remote attackers to inject arbitrary SQL commands via the X-Forwarded-For header to admin/product_add.php. |