Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
616 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Zedna Ebook Download Project Zedna Ebook Download | 22/8/2019 | 17/6/2026 | The ebook-download plugin before 1.2 for WordPress has directory traversal. | |
| Modificada | Media (6.1) | 0.97% | — | Awesomemotive Easy Digital Downloads | 16/8/2019 | 17/6/2026 | The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging. | |
| Modificada | Crítica (9.8) | 2.0% | — | Awesomemotive Easy Digital Downloads | 16/8/2019 | 17/6/2026 | The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection. | |
| Modificada | Media (6.1) | 0.92% | — | Never5 Download Monitor | 13/8/2019 | 17/6/2026 | The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg. | |
| Modificada | Crítica (9.8) | 0.77% | — | Canonical Ubuntu Download Manager | 22/4/2019 | 17/6/2026 | UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications. Before UDM version 1.2+16.04.20160408-0ubuntu1 any confined application could make use of the UDM C++ API to run… | |
| Modificada | Crítica (9.8) | 2.9% | — | Shdesigns Resident Download Manager | 13/7/2018 | 17/6/2026 | SHDesigns' Resident Download Manager provides firmware update capabilities for Rabbit 2000/3000 CPU boards, which according to the reporter may be used in some industrial control and embedded applications. The Resident Download Manager does not verify that the firmware is authentic before executing code and deploying… | |
| Modificada | Alta (8.1) | 1.7% | — | Groupon Selenium-download | 29/5/2018 | 17/6/2026 | selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an… | |
| Modificada | Crítica (9.8) | 1.6% | — | Liulishuo Filedownloader | 18/5/2018 | 17/6/2026 | util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in the file name, the file can be stored in an unintended directory because of Directory Traversal. | |
| Modificada | Media (6.1) | 3.9% | 💥 Exploit | Jdownloads | 12/4/2018 | 17/6/2026 | The jDownloads extension before 3.2.59 for Joomla! has XSS. | |
| Modificada | Media (6.1) | 0.60% | — | Videodownloaderultimate Video Downloader | 11/4/2018 | 17/6/2026 | The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to a link64_msgAddLinks event. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Techsolsystem File Download Tracker | 17/2/2018 | 17/6/2026 | SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter. | |
| Modificada | Media (6.1) | 0.92% | — | W3eden Download Manager | 16/1/2018 | 17/6/2026 | The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Cmcm Armorfly Browser & Downloader | 12/1/2018 | 17/6/2026 | Cheetah Mobile Armorfly Browser & Downloader 1.1.05.0010, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass. | |
| Modificada | Media (6.1) | 1.7% | — | Dragonbyte-tech Vbdownloads Module | 11/1/2018 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownloads module 1.3.2 and earlier for vBulletin allows remote attackers to inject arbitrary web script or HTML via the mirrors[] parameter. | |
| Modificada | Media (5.4) | 1.0% | — | Simple Download Monitor Project Simple Download Monitor | 4/1/2018 | 17/6/2026 | The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php. | |
| Modificada | Media (5.4) | 1.0% | — | Simple Download Monitor Project Simple Download Monitor | 4/1/2018 | 17/6/2026 | The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php. | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Xi-soft Nettransport Download Manager | 29/12/2017 | 17/6/2026 | A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP response. | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Getgosoft Getgo Download Manager | 27/12/2017 | 17/6/2026 | A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response. | |
| Modificada | Crítica (9.8) | 2.7% | 💥 Exploit | Protectedlinks Expiring Download Links | 31/10/2017 | 17/6/2026 | Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter. | |
| Modificada | Crítica (9.8) | 3.4% | 💥 Exploit | Nswd NS Download Shop | 29/10/2017 | 17/6/2026 | The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action. | |
| Modificada | Alta (7.5) | 4.7% | 💥 Exploit | Converto Video Downloader & Converter Project Converto Video Downloader & Converter | 29/10/2017 | 17/6/2026 | ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php. | |
| Modificada | Crítica (9.8) | 2.6% | — | Rayanehdownload Rk-responsive-contact-form | 14/9/2017 | 17/6/2026 | Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php. | |
| Modificada | Crítica (9.8) | 4.2% | — | Labwebdesigns Double Opt-in FOR Download | 29/8/2017 | 17/6/2026 | Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-doifd-download.php or (2) class-doifd-landing-page.php in public/includes/. | |
| Modificada | Alta (7.8) | 2.3% | — | Synology Download Station | 14/8/2017 | 17/6/2026 | Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors. | |
| Modificada | Media (6.5) | 1.6% | — | Synology Download Station | 14/8/2017 | 17/6/2026 | Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI. |