Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.39% | — | Download ManagerAI | 27/7/2026 | 27/7/2026 | The Download Manager WordPress plugin before 3.3.62 does not bind its temporary download token to the requesting session nor expire it promptly, making the token a long-lived, multi-use, portable bearer token, so that an attacker who obtains one leaked download key can repeatedly download a role- or password-protected… | |
| Aplazada | Media (6.5) | 0.42% | — | Easydigitaldownloads Easy Digital DownloadsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpforms Download MonitorAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Download Monitor - WPForms Lock <= 1.0.4 versions. | |
| Aplazada | Crítica (10) | 0.45% | — | Dj-extensions Dj-jdownloadsAI | 20/7/2026 | 23/7/2026 | Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE. | |
| Modificada | Crítica (9) | 0.54% | — | Phoca Download | 11/7/2026 | 19/8/2026 | Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE. | |
| Aplazada | Media (6.4) | 0.35% | — | Download ManagerAI | 9/7/2026 | 9/7/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes in all versions up to, and including, 3.3.61 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.36% | — | Download ManagerAI | 1/7/2026 | 1/7/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, and including, 3.3.60 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and… | |
| Analizada | Alta (8.8) | 0.49% | — | Joomlashack Osdownloads | 19/6/2026 | 19/8/2026 | Joomla OSDownloads 1.7.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_osdownloads&view=item&id=[SQL] to extract sensitive database… | |
| Aplazada | Media (5.3) | 0.46% | — | 2download Connector FOR 2DL Hosted CheckoutAI | 19/6/2026 | 22/6/2026 | The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to view arbitrary… | |
| Aplazada | Media (6.5) | 0.25% | — | Postman DownloadAI | 17/6/2026 | 22/6/2026 | The postman_download module uses the workspace name field from the Postman API to construct the local directory path without sanitization. If a malicious workspace has a name containing path traversal characters, pathlib resolves the path outside the intended output directory, allowing an attacker to write arbitrary… | |
| Aplazada | Media (6.4) | 0.23% | — | File Sharing Download Manager User Private FilesAI | 16/6/2026 | 17/6/2026 | The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fldr_ttl' parameter in all versions up to, and including, 2.1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.5) | 0.35% | — | Easydigitaldownloads Easy Digital DownloadsAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions. | |
| Aplazada | Media (4.4) | 0.37% | — | Download MonitorAI | 15/6/2026 | 17/6/2026 | Author Arbitrary File Download in Download Monitor <= 5.1.9 versions. | |
| Aplazada | Alta (8.8) | 0.27% | — | ALL IN ONE Video DownloaderAI | 4/6/2026 | 22/7/2026 | All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send requests to the admin interface with UNION-based SQL injection payloads in the id parameter to extract… | |
| Aplazada | Media (4.3) | 0.20% | — | Easydigitaldownloads Easy Digital DownloadsAI | 28/5/2026 | 17/6/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.7. This is due to missing nonce verification in the `handle_oauth_redirect()` function, which is registered on the `admin_init` hook and processes Square OAuth tokens from a… | |
| Aplazada | Baja (2.1) | 0.40% | — | Dazeb Markdown-downloaderAI | 25/5/2026 | 23/7/2026 | A flaw has been found in dazeb markdown-downloader up to 3d4394b34b6c99d81af817623af55e3384df5a6a. Affected is the function download_markdown/list_downloaded_files/create_subdirectory of the file src/index.ts. Executing a manipulation can lead to path traversal. The attack can be launched remotely. The exploit has… | |
| Aplazada | Media (6.9) | 0.15% | — | Internet Download ManagerAI | 16/5/2026 | 29/9/2026 | Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data exceeding 5000 bytes into the 'Open the following file when done' field to trigger a denial of… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Download From FilesAI | 10/5/2026 | 25/7/2026 | WordPress Plugin Download From Files version 1.48 and earlier contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by exploiting the AJAX fileupload action. Attackers can send POST requests to the admin-ajax.php endpoint with the… | |
| Aplazada | Baja (2.1) | 1.8% | — | Pskill9 Website-downloaderAI | 2/5/2026 | 17/6/2026 | A vulnerability was detected in pskill9 website-downloader up to 0.1.0. This affects the function download_website of the file src/index.ts of the component MCP Interface. Performing a manipulation of the argument outputPath results in os command injection. The attack may be initiated remotely. The exploit is now… | |
| Aplazada | Alta (8.6) | 0.15% | — | Freedownloadmanager Free Download ManagerAI | 29/4/2026 | 17/6/2026 | Free Download Manager 2.0 Build 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploitation. Attackers can craft a malicious URL file that, when imported through the File > Import > Import lists of downloads… | |
| Aplazada | Media (5.5) | 0.47% | — | Dmitryglhf Mcp-url-downloaderAI | 27/4/2026 | 17/6/2026 | A vulnerability has been found in dmitryglhf mcp-url-downloader up to 4b8cf2de55f6e8864a77d108e8a94a5b8e4394c6. Affected by this issue is the function _validate_url_safe of the file src/mcp_url_downloader/server.py. Such manipulation of the argument url leads to server-side request forgery. The attack can be executed… | |
| Analizada | Alta (8.4) | 0.18% | — | Liveon Canonnwcamplugin.exeLiveon Canonnwcampluginforadmin.exeLiveon Downloader5installer.exeLiveon Downloader5installerforadmin.exe | 23/4/2026 | 17/6/2026 | The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at the same directory,… | |
| Aplazada | Baja (1.9) | 1.4% | — | Aandrew-me YtdownloaderAI | 13/4/2026 | 17/6/2026 | A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of the component Compressor Feature. This manipulation causes command injection. The attack can only be executed locally. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5.3) | 0.45% | — | Aandrew-me YtdownloaderAI | 13/4/2026 | 17/6/2026 | A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode of the component Error Details Panel. The manipulation results in cross site scripting. The attack may be performed from remote. The vendor was contacted early about this disclosure. | |
| Aplazada | Media (4.3) | 0.36% | — | Download ManagerAI | 10/4/2026 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `makeMediaPublic()` and `makeMediaPrivate()` functions in all versions up to, and including, 3.3.51. This is due to the functions only checking for `edit_posts` capability without… |