Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

616 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)12%💥 ExploitZedna Ebook Download Project Zedna Ebook Download22/8/201917/6/2026
The ebook-download plugin before 1.2 for WordPress has directory traversal.
ModificadaMedia (6.1)0.97%—Awesomemotive Easy Digital Downloads16/8/201917/6/2026
The easy-digital-downloads plugin before 2.9.16 for WordPress has XSS related to IP address logging.
ModificadaCrítica (9.8)2.0%—Awesomemotive Easy Digital Downloads16/8/201917/6/2026
The easy-digital-downloads plugin before 2.3.3 for WordPress has SQL injection.
ModificadaMedia (6.1)0.92%—Never5 Download Monitor13/8/201917/6/2026
The download-monitor plugin before 1.7.1 for WordPress has XSS related to add_query_arg.
ModificadaCrítica (9.8)0.77%—Canonical Ubuntu Download Manager22/4/201917/6/2026
UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications. Before UDM version 1.2+16.04.20160408-0ubuntu1 any confined application could make use of the UDM C++ API to run…
ModificadaCrítica (9.8)2.9%—Shdesigns Resident Download Manager13/7/201817/6/2026
SHDesigns' Resident Download Manager provides firmware update capabilities for Rabbit 2000/3000 CPU boards, which according to the reporter may be used in some industrial control and embedded applications. The Resident Download Manager does not verify that the firmware is authentic before executing code and deploying…
ModificadaAlta (8.1)1.7%—Groupon Selenium-download29/5/201817/6/2026
selenium-download downloads the latest versions of the selenium standalone server and the chromedriver. selenium-download before 2.0.7 downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an…
ModificadaCrítica (9.8)1.6%—Liulishuo Filedownloader18/5/201817/6/2026
util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in the file name, the file can be stored in an unintended directory because of Directory Traversal.
ModificadaMedia (6.1)3.9%💥 ExploitJdownloads12/4/201817/6/2026
The jDownloads extension before 3.2.59 for Joomla! has XSS.
ModificadaMedia (6.1)0.60%—Videodownloaderultimate Video Downloader11/4/201817/6/2026
The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to a link64_msgAddLinks event.
ModificadaCrítica (9.8)2.7%💥 ExploitTechsolsystem File Download Tracker17/2/201817/6/2026
SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter.
ModificadaMedia (6.1)0.92%—W3eden Download Manager16/1/201817/6/2026
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.
ModificadaAlta (7.5)1.2%—Cmcm Armorfly Browser & Downloader12/1/201817/6/2026
Cheetah Mobile Armorfly Browser & Downloader 1.1.05.0010, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass.
ModificadaMedia (6.1)1.7%—Dragonbyte-tech Vbdownloads Module11/1/201816/6/2026
Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownloads module 1.3.2 and earlier for vBulletin allows remote attackers to inject arbitrary web script or HTML via the mirrors[] parameter.
ModificadaMedia (5.4)1.0%—Simple Download Monitor Project Simple Download Monitor4/1/201817/6/2026
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
ModificadaMedia (5.4)1.0%—Simple Download Monitor Project Simple Download Monitor4/1/201817/6/2026
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.
ModificadaCrítica (9.8)40%💥 ExploitXi-soft Nettransport Download Manager29/12/201717/6/2026
A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP response.
ModificadaCrítica (9.8)19%💥 ExploitGetgosoft Getgo Download Manager27/12/201717/6/2026
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.
ModificadaCrítica (9.8)2.7%💥 ExploitProtectedlinks Expiring Download Links31/10/201717/6/2026
Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.
ModificadaCrítica (9.8)3.4%💥 ExploitNswd NS Download Shop29/10/201717/6/2026
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.
ModificadaAlta (7.5)4.7%💥 ExploitConverto Video Downloader & Converter Project Converto Video Downloader & Converter29/10/201717/6/2026
ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php.
ModificadaCrítica (9.8)2.6%—Rayanehdownload Rk-responsive-contact-form14/9/201717/6/2026
Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php.
ModificadaCrítica (9.8)4.2%—Labwebdesigns Double Opt-in FOR Download29/8/201717/6/2026
Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-doifd-download.php or (2) class-doifd-landing-page.php in public/includes/.
ModificadaAlta (7.8)2.3%—Synology Download Station14/8/201717/6/2026
Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 uses weak permissions (0777) for ui/dlm/btsearch directory, which allows remote authenticated users to execute arbitrary code by uploading an executable via unspecified vectors.
ModificadaMedia (6.5)1.6%—Synology Download Station14/8/201717/6/2026
Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.