Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 321 respecto a la semana anterior
Críticas / altas1271▼ 203 respecto a la semana anterior
Nueva explotación activa (KEV)8→ sin cambios respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 108 respecto a la semana anterior
617 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.4% | — | Widexl Download Tracker | 18/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in down.pl in Widexl Download Tracker 1.06 allows remote attackers to inject arbitrary web script or HTML via the ID parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Duware DuamazonDuware DuarticleDuware DuclassifiedDuware Dudirectory+7 | 3/12/2005 | 16/6/2026 | SQL injection vulnerability in type.asp, as used in multiple DUware products including (1) DUamazon 3.1, (2) DUarticle 1.1, (3) DUclassified 4.2, (4) DUdirectory 3.1 and DUdirectory Pro 3.0 and 3.0 SQL, (5) DUdownload 1.1, (6) DUgallery 3.3, (7) DUnews 1.1, and (8) DUpaypal 3.1 and DUpaypal Pro 3.0, allows remote… | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | PHP Download Manager | 23/11/2005 | 16/6/2026 | SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | PHP Easy Download | 21/11/2005 | 16/6/2026 | PHP Easy Download allows remote attackers to bypass authentication via edit.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Xoops Wf-downloads | 18/11/2005 | 16/6/2026 | SQL injection vulnerability in viewcat.php in XOOPS WF-Downloads module 2.05 allows remote attackers to execute arbitrary SQL commands via the list parameter. | |
| Modificada | Alta (7.5) | 8.6% | 💥 Exploit | Prozilla Download Accelerator | 5/10/2005 | 16/6/2026 | Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option enabled, allows remote servers to execute arbitrary code via a search response with a crafted string in the HREF field of an <A> tag. | |
| Modificada | Media (5) | 1.4% | — | Sven-ove Bjerkan Downloadprotect | 13/7/2005 | 16/6/2026 | Vulnerabilidad de franqueo de directorioes en DownloadProtect anterior a la 1.0.3 permite que atacantes remotos lean ficheros por encima de la carpeta de descarga. | |
| Modificada | Alta (7.5) | 4.0% | 💥 Exploit | Tonec Inc. Internet Download Manager | 11/7/2005 | 16/6/2026 | Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Loki Download ManagerAI | 8/6/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Loki download manager 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) password field to default.asp or (2) cat parameter to catinfo.asp. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Powerscripts.org Powerdownload | 1/6/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in pdl_header.inc.php in PowerDownload 3.0.2 and 3.0.3 allows remote attackers to execute arbitrary PHP code via the incdir parameter to downloads.php. | |
| Modificada | Alta (7.5) | 9.9% | 💥 Exploit | Prozilla Download Accelerator | 2/5/2005 | 16/6/2026 | Format string vulnerability in ProZilla 1.3.7.3 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the Location header. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Stadtaus Download Center LiteAI | 7/3/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in download_center_lite.inc.php for Download Center Lite 1.6 allows remote attackers to execute arbitrary PHP code by modifying the script_root parameter to reference a URL on a remote web server that contains the code. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Prozilla Download Accelerator | 10/1/2005 | 16/6/2026 | Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute arbitrary code via a long Location header. | |
| Modificada | Alta (7.5) | 4.2% | — | Altnet Download ManagerGroksterKazaa Media Desktop | 31/12/2004 | 16/6/2026 | Buffer overflow in the IsValidFile function in the ADM ActiveX control for Altnet Download Manager 4.0.0.4 and earlier, as used in Kazaa Media Desktop 1.3 through 2.6.4 and Grokkster 1.3 through 2.6, allows remote attackers to execute arbitrary code via a long bstrFilepath parameter. | |
| Modificada | Baja (2.6) | 4.6% | 💥 Exploit | PostnukeAIPostnuke Downloads ModuleAIPostnuke WEB Links ModuleAI | 21/4/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in PostNuke 0.726 allows remote attackers to inject arbitrary web script or HTML via the (1) lid and query parameters to the Downloads module, (2) query parameter to the Web_links module, or (3) hlpfile parameter to openwindow.php. | |
| Modificada | Alta (7.5) | 7.5% | 💥 Exploit | Netscape Smartdownload | 2/7/2001 | 16/6/2026 | Buffer overflow in Netscape SmartDownload 1.3 allows remote attackers (malicious web pages) to execute arbitrary commands via a long URL. | |
| Modificada | Media (5) | 2.1% | — | Matt Wright Download.cgi | 9/9/1999 | 16/6/2026 | Matt Wright's download.cgi 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. |