Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.4) | 0.24% | — | Electric Studio Download CounterAI | 14/1/2026 | 17/6/2026 | The Electric Studio Download Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and… | |
| Aplazada | Media (5.4) | 0.26% | — | Easy Media DownloadAI | 8/1/2026 | 7/10/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Noor Alam Easy Media Download easy-media-download allows Reflection Injection.This issue affects Easy Media Download: from n/a through <= 1.1.11. | |
| Aplazada | Media (6.4) | 0.22% | — | EDD Download InfoAI | 7/1/2026 | 17/6/2026 | The EDD Download Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'edd_download_info_link' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.3) | 0.20% | — | Download ManagerAI | 6/1/2026 | 30/9/2026 | The Download Manager plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.3.40. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Alta (7.5) | 0.28% | — | Codepeople Sell DownloadsAI | 5/1/2026 | 30/9/2026 | Missing Authorization vulnerability in codepeople Sell Downloads sell-downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sell Downloads: from n/a through <= 1.1.12. | |
| Aplazada | Media (5.3) | 0.23% | — | Marcelotorres Download Media LibraryAI | 31/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in marcelotorres Download Media Library download-media-library allows Retrieve Embedded Sensitive Data.This issue affects Download Media Library: from n/a through <= 0.2.1. | |
| Aplazada | Media (4.3) | 0.35% | 💥 PoC | Easydigitaldownloads Easy Digital DownloadsAI | 31/12/2025 | 17/6/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Unvalidated Redirect in all versions up to, and including, 3.6.2. This is due to insufficient validation on the redirect url supplied via the 'edd_redirect' parameter. This makes it possible for unauthenticated attackers to redirect users with the… | |
| Aplazada | Media (5.3) | 0.27% | — | F70 Lead Document DownloadAI | 20/12/2025 | 1/10/2026 | The F70 Lead Document Download plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'file_download' function in all versions up to, and including, 1.4.4. This makes it possible for unauthenticated attackers to download any file from the WordPress media library by… | |
| Aplazada | Media (5.8) | 0.27% | — | Mkscripts Download After EmailAI | 18/12/2025 | 17/6/2026 | Missing Authorization vulnerability in mkscripts Download After Email download-after-email allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Download After Email: from n/a through 2.1.5-2.1.6. | |
| Aplazada | Media (4.3) | 0.42% | — | Download ManagerAI | 18/12/2025 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to unauthorized access of sensitive information in all versions up to, and including, 3.3.32. This is due to missing authorization and capability checks on the `wpdm_media_access` AJAX action. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (4.3) | 0.12% | — | Download Plugins AND Themes IN ZIP From DashboardAI | 17/12/2025 | 28/9/2026 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.6. This is due to missing or incorrect nonce validation on the download_plugin_bulk and download_theme_bulk functions. This makes it possible for… | |
| Aplazada | Media (4.9) | 0.52% | — | Plugin-planet Simple Download CounterAI | 10/12/2025 | 17/6/2026 | The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.2.2. This is due to insufficient path validation in the `simple_download_counter_parse_path()` function. This makes it possible for authenticated attackers, with Administrator-level access and… | |
| Aplazada | Media (4.3) | 0.26% | — | Shahjada Download ManagerAI | 9/12/2025 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager download-manager allows Retrieve Embedded Sensitive Data.This issue affects Download Manager: from n/a through <= 3.3.32. | |
| Aplazada | Media (4.3) | 0.13% | — | M.code Media Library DownloaderAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in M.Code Media Library Downloader media-library-downloader allows Cross Site Request Forgery.This issue affects Media Library Downloader: from n/a through <= 1.4.0. | |
| Aplazada | Media (4.3) | 0.13% | — | Wpmediadownload Media Library File DownloadAI | 9/12/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpmediadownload Media Library File Download media-download allows Cross Site Request Forgery.This issue affects Media Library File Download: from n/a through <= 1.4. | |
| Aplazada | Media (6.4) | 0.22% | — | Google Drive Upload AND Download LinkAI | 27/11/2025 | 17/6/2026 | The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter of the 'atachfilegoogle' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.22% | — | Download PanelAI | 18/11/2025 | 17/6/2026 | The Download Panel plugin for WordPress is vulnerable to unauthorized settings modification due to a missing capability check on the 'wp_ajax_save_settings' AJAX action in all versions up to, and including, 1.3.3. This is due to the absence of any capability verification in the `dlpn_save_settings()` function. This… | |
| Aplazada | Media (5.3) | 0.22% | — | Download ManagerAI | 8/11/2025 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the deleteExpired() and clearTempDataCPCron() functions in all versions up to, and including, 3.3.30. This makes it possible for unauthenticated attackers to trigger these cron jobs leading to deletion of… | |
| Aplazada | Media (6.4) | 0.21% | — | Neofix Simple Downloads ListAI | 8/11/2025 | 17/6/2026 | The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wp_ajax_neofix_sdl_edit' AJAX endpoint along with many others in all versions up to, and including, 1.4.3. This makes it possible for authenticated attackers, with… | |
| Analizada | Baja (2.2) | 0.20% | — | Qnap Download Station | 7/11/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: Download Station… | |
| Analizada | Baja (2.3) | 0.47% | — | Qnap Download Station | 7/11/2025 | 17/6/2026 | A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Download Station… | |
| Aplazada | Alta (7.5) | 0.44% | — | Anatoly Download CounterAI | 6/11/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Anatoly Download Counter download-counter allows Path Traversal.This issue affects Download Counter: from n/a through <= 1.4. | |
| Aplazada | Media (5.3) | 0.30% | — | Easydigitaldownloads Easy Digital DownloadsAI | 6/11/2025 | 17/6/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including, 3.5.2 due to an order verification bypass. The verification is unconditionally skipped when the POST body includes verification_override=1. Because this value is attacker-supplied, an… | |
| Modificada | Crítica (9.1) | 0.25% | — | Tonec Internet Download Manager | 5/11/2025 | 5/7/2026 | Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections. | |
| Aplazada | Media (5.3) | 0.35% | — | Melabuwp Download Counter ButtonAI | 5/11/2025 | 17/6/2026 | The MelAbu WP Download Counter Button WordPress plugin through 1.8.6.7 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files. |