Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
–

617 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.4%—Widexl Download Tracker18/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
ModificadaAlta (7.5)1.2%—Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+73/12/200516/6/2026
SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote…
ModificadaAlta (7.5)1.1%💥 ExploitPHP Download Manager23/11/200516/6/2026
SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter.
ModificadaAlta (7.5)1.5%—PHP Easy Download21/11/200516/6/2026
PHP Easy Download allows remote attackers to bypass authentication via edit.php.
ModificadaAlta (7.5)1.2%💥 ExploitXoops Wf-downloads18/11/200516/6/2026
SQL injection vulnerability in viewcat.php in XOOPS WF-Downloads module 2.05 allows remote attackers to execute arbitrary SQL commands via the list parameter.
ModificadaAlta (7.5)8.6%💥 ExploitProzilla Download Accelerator5/10/200516/6/2026
Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remote servers to execute arbitrary code via a search response with a crafted string in the HREF field of an <A> tag.
ModificadaMedia (5)1.4%—Sven-ove Bjerkan Downloadprotect13/7/200516/6/2026
Vulnerabilidad de franqueo de directorioes en DownloadProtect anterior a la 1.0.3 permite que atacantes remotos lean ficheros por encima de la carpeta de descarga.
ModificadaAlta (7.5)4.0%💥 ExploitTonec Inc. Internet Download Manager11/7/200516/6/2026
Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.
ModificadaAlta (7.5)1.1%💥 ExploitLoki Download ManagerAI8/6/200516/6/2026
Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp.
ModificadaAlta (7.5)2.9%💥 ExploitPowerscripts.org Powerdownload1/6/200516/6/2026
PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php.
ModificadaAlta (7.5)9.9%💥 ExploitProzilla Download Accelerator2/5/200516/6/2026
Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header.
ModificadaAlta (7.5)2.6%💥 ExploitStadtaus Download Center LiteAI7/3/200516/6/2026
PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code.
ModificadaAlta (10)15%💥 ExploitProzilla Download Accelerator10/1/200516/6/2026
Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute arbitrary code via a long Location header.
ModificadaAlta (7.5)4.2%—Altnet Download ManagerGroksterKazaa Media Desktop31/12/200416/6/2026
Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 4.0.0.4 and earlier, as used in Kazaa Media Desktop 1.3 through 2.6.4 and Grokkster 1.3 through 2.6, allows remote attackers to execute arbitrary code via a long bstrFilepath parameter.
ModificadaBaja (2.6)4.6%💥 ExploitPostnukeAIPostnuke Downloads ModuleAIPostnuke WEB Links ModuleAI21/4/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php.
ModificadaAlta (7.5)7.5%💥 ExploitNetscape Smartdownload2/7/200116/6/2026
Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL.
ModificadaMedia (5)2.1%—Matt Wright Download.cgi9/9/199916/6/2026
Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter.
Orbitaley — Vulnerabilidades