Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
617 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.6% | — | Synology Download Station | 14/8/2017 | 17/6/2026 | Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI. | |
| Modificada | Alta (7.8) | 1.8% | — | Solarcontrols Heating Control Downloader | 14/8/2017 | 17/6/2026 | An Uncontrolled Search Path Element issue was discovered in Solar Controls Heating Control Downloader (HCDownloader) Version 1.0.1.15 and prior. An uncontrolled search path element has been identified, which could allow an attacker to execute arbitrary code on a target system using a malicious DLL file. | |
| Modificada | Alta (8.8) | 11% | 💥 Exploit | W3eden Download Manager | 7/8/2017 | 17/6/2026 | The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option. | |
| Modificada | Media (6.1) | 1.5% | — | W3eden Download Manager | 7/7/2017 | 17/6/2026 | Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (6.1) | 1.4% | — | W3eden Download Manager | 7/7/2017 | 17/6/2026 | Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 10% | 💥 Exploit | MDC Youtube Downloader Project MDC Youtube Downloader | 23/5/2017 | 17/6/2026 | Absolute path traversal vulnerability in the MDC YouTube Downloader plugin 2.1.0 for WordPress allows remote attackers to read arbitrary files via a full pathname in the file parameter to includes/download.php. | |
| Modificada | Alta (7.5) | 5.3% | — | Download ZIP Attachments Project Download ZIP Attachments | 23/5/2017 | 17/6/2026 | Directory traversal vulnerability in the Download Zip Attachments plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the File parameter to download.php. | |
| Modificada | Alta (8.8) | 27% | 💥 Exploit | Cisco Activetouch General Plugin ContainerCisco Download ManagerCisco Gpccontainer ClassCisco Webex+2 | 1/2/2017 | 17/6/2026 | An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on… | |
| Modificada | Media (4.7) | 0.28% | — | SAP Download Manager | 14/12/2016 | 17/6/2026 | SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of a hardcoded key in the program code and a computer BIOS serial number, aka SAP… | |
| Modificada | Media (4.7) | 0.29% | — | SAP Download Manager | 14/12/2016 | 17/6/2026 | SAP Download Manager 2.1.142 and earlier uses a hardcoded encryption key to protect stored data, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of this key, aka SAP Security Note 2282338. | |
| Modificada | Media (6.1) | 1.4% | — | Filedownload Project Filedownload | 6/10/2016 | 17/6/2026 | XSS in filedownload v1.4 wordpress plugin | |
| Modificada | Crítica (9.8) | 2.6% | — | Filedownload Project Filedownload | 6/10/2016 | 17/6/2026 | Blind SQL Injection in filedownload v1.4 wordpress plugin | |
| Modificada | Alta (8.2) | 1.8% | — | Filedownload Project Filedownload | 6/10/2016 | 17/6/2026 | Open Proxy in filedownload v1.4 wordpress plugin | |
| Modificada | Media (4.3) | 1.9% | — | Synology Download Station | 11/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the "Create download task via URL" feature in Synology Download Station before 3.5-2967 allows remote attackers to inject arbitrary web script or HTML via the urls parameter in an add_url_task action to dlm/downloadman.cgi. | |
| Modificada | Media (4.3) | 2.1% | — | Synology Download Station | 11/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the "Create download task via file upload" feature in Synology Download Station before 3.5-2962 allows remote attackers to inject arbitrary web script or HTML via the name element in the Info dictionary in a torrent file. | |
| Modificada | Baja (3.5) | 0.95% | — | Public Download Count Project Public Download Count | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Download counts report page in the Public Download Count module (pubdlcnt) 7.x-1.x-dev and earlier for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.9% | — | Synck Graphica Download LOG CGI | 21/1/2015 | 17/6/2026 | Directory traversal vulnerability in SYNCK GRAPHICA Download Log CGI 3.0 and earlier allows remote attackers to read arbitrary files via a crafted filename. | |
| Modificada | Alta (10) | 14% | 💥 Exploit | Creative Minds CM Download Manager | 5/12/2014 | 17/6/2026 | The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function. | |
| Modificada | Media (6.8) | 1.5% | — | Cminds CM Download Manager | 5/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page… | |
| Modificada | Media (5) | 2.9% | — | W3eden Download Manager | 4/11/2014 | 17/6/2026 | Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php. | |
| Modificada | Media (5.4) | 0.27% | — | Easy Video Downloader Project Easy Video Downloader | 16/10/2014 | 17/6/2026 | The Easy Video Downloader (aka com.simon.padillar.EasyVideo) application 4.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Musicjustnow 10000 Kindle Books Downloads | 18/9/2014 | 17/6/2026 | The 10000 Kindle Books Downloads (aka com.ww10000KindleBooksLatestnBestSellers) application 0.312 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Pinssible Phonegram - Instagram Download | 9/9/2014 | 17/6/2026 | The Phonegram - Instagram Download (aka com.pinssible.padgram) application 1.9.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Avd-app AVD Download Video | 9/9/2014 | 17/6/2026 | The AVD Download Video (aka com.myboyfriendisageek.videocatcher.demo) application 3.3.13 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 10% | 💥 Exploit | Mikejolley Download Monitor | 4/9/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the dlsearch parameter to the default URI. |