Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

617 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.6%—Synology Download Station14/8/201717/6/2026
Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.
ModificadaAlta (7.8)1.8%—Solarcontrols Heating Control Downloader14/8/201717/6/2026
An Uncontrolled Search Path Element issue was discovered in Solar Controls Heating Control Downloader (HCDownloader) Version 1.0.1.15 and prior. An uncontrolled search path element has been identified, which could allow an attacker to execute arbitrary code on a target system using a malicious DLL file.
ModificadaAlta (8.8)11%💥 ExploitW3eden Download Manager7/8/201717/6/2026
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
ModificadaMedia (6.1)1.5%—W3eden Download Manager7/7/201717/6/2026
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (6.1)1.4%—W3eden Download Manager7/7/201717/6/2026
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)10%💥 ExploitMDC Youtube Downloader Project MDC Youtube Downloader23/5/201717/6/2026
Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php.
ModificadaAlta (7.5)5.3%—Download ZIP Attachments Project Download ZIP Attachments23/5/201717/6/2026
Directory traversal vulnerability in the Download Zip Attachments plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the File parameter to download.php.
ModificadaAlta (8.8)27%💥 ExploitCisco Activetouch General Plugin ContainerCisco Download ManagerCisco Gpccontainer ClassCisco Webex+21/2/201717/6/2026
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on…
ModificadaMedia (4.7)0.28%—SAP Download Manager14/12/201617/6/2026
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of a hardcoded key in the program code and a computer BIOS serial number, aka SAP…
ModificadaMedia (4.7)0.29%—SAP Download Manager14/12/201617/6/2026
SAP Download Manager 2.1.142 and earlier uses a hardcoded encryption key to protect stored data, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of this key, aka SAP Security Note 2282338.
ModificadaMedia (6.1)1.4%—Filedownload Project Filedownload6/10/201617/6/2026
XSS in filedownload v1.4 wordpress plugin
ModificadaCrítica (9.8)2.6%—Filedownload Project Filedownload6/10/201617/6/2026
Blind SQL Injection in filedownload v1.4 wordpress plugin
ModificadaAlta (8.2)1.8%—Filedownload Project Filedownload6/10/201617/6/2026
Open Proxy in filedownload v1.4 wordpress plugin
ModificadaMedia (4.3)1.9%—Synology Download Station11/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the "Create download task via URL" feature in Synology Download Station before 3.5-2967 allows remote attackers to inject arbitrary web script or HTML via the urls parameter in an add_url_task action to dlm/downloadman.cgi.
ModificadaMedia (4.3)2.1%—Synology Download Station11/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or HTML via the name element in the Info dictionary in a torrent file.
ModificadaBaja (3.5)0.95%—Public Download Count Project Public Download Count21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Download counts report page in the Public Download Count module (pubdlcnt) 7.x-1.x-dev and earlier for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.9%—Synck Graphica Download LOG CGI21/1/201517/6/2026
Directory traversal vulnerability in SYNCK GRAPHICA Download Log CGI 3.0 and earlier allows remote attackers to read arbitrary files via a crafted filename.
ModificadaAlta (10)14%💥 ExploitCreative Minds CM Download Manager5/12/201417/6/2026
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function.
ModificadaMedia (6.8)1.5%—Cminds CM Download Manager5/12/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page…
ModificadaMedia (5)2.9%—W3eden Download Manager4/11/201417/6/2026
Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php.
ModificadaMedia (5.4)0.27%—Easy Video Downloader Project Easy Video Downloader16/10/201417/6/2026
The Easy Video Downloader (aka com.simon.padillar.EasyVideo) application 4.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Musicjustnow 10000 Kindle Books Downloads18/9/201417/6/2026
The 10000 Kindle Books Downloads (aka com.ww10000KindleBooksLatestnBestSellers) application 0.312 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Pinssible Phonegram - Instagram Download9/9/201417/6/2026
The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Avd-app AVD Download Video9/9/201417/6/2026
The AVD Download Video (aka com.myboyfriendisageek.videocatcher.demo) application 3.3.13 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)10%💥 ExploitMikejolley Download Monitor4/9/201416/6/2026
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI.