Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

133 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.2%—W3eden Download Manager13/6/202217/6/2026
The Download Manager Plugin for WordPress is vulnerable to reflected Cross-Site Scripting in versions up to, and including 3.2.42. This is due to insufficient input sanitization and output escaping on the 'frameid' parameter found in the ~/src/Package/views/shortcode-iframe.php file.
ModificadaAlta (7.5)1.5%—W3eden Download Manager11/4/202217/6/2026
The Download Manager WordPress plugin before 3.2.34 uses the uniqid php function to generate the master key for a download, allowing an attacker to brute force the key with reasonable resources giving direct download access regardless of role based restrictions or password protections set for the download.
ModificadaAlta (7.5)1.5%—W3eden Download Manager7/3/202217/6/2026
The Download Manager WordPress plugin before 3.2.35 does not have any authorisation checks in some of the REST API endpoints, allowing unauthenticated attackers to call them, which could lead to sensitive information disclosure, such as posts passwords (fixed in 3.2.24) and files Master Keys (fixed in 3.2.25).
AnalizadaAlta (8.8)1.5%—W3eden Download Manager21/2/202217/6/2026
The Download Manager WordPress plugin before 3.2.34 does not sanitise and escape the package_ids parameter before using it in a SQL statement, leading to a SQL injection, which can also be exploited to cause a Reflected Cross-Site Scripting issue
ModificadaMedia (5.4)0.60%—W3eden Download Manager27/12/202117/6/2026
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape Template data before outputting it in various pages (such as admin dashboard and frontend). Due to the lack of authorisation and CSRF checks in the wpdm_save_template AJAX action, any authenticated users such as subscriber is…
ModificadaMedia (4.8)2.9%—W3eden Download Manager1/11/202117/6/2026
The WordPress Download Manager WordPress plugin before 3.2.16 does not escape some of the Download settings when outputting them, allowing high privilege users to perform XSS attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (6.7)0.41%—Tonec Internet Download Manager22/10/202117/6/2026
Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Search function. This vulnerability allows attackers to escalate local process privileges via unspecified vectors.
ModificadaAlta (7.1)0.41%—Tonec Internet Download Manager22/10/202117/6/2026
Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Export/Import function. This vulnerability allows attackers to escalate local process privileges via a crafted ef2 file.
ModificadaAlta (8.8)0.58%—W3eden Download Manager5/8/202117/6/2026
Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+) users to upload files with a double extension, e.g. "payload.php.png" which is executable in some configurations. This issue affects: WordPress Download Manager version 3.1.24 and prior versions.
ModificadaMedia (6.5)1.3%—W3eden Download Manager5/8/202117/6/2026
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated (Contributor+) users to obtain sensitive configuration file information, as well as allowing Author+ users to perform XSS attacks, by setting Download template to a file containing configuration information or an uploaded…
ModificadaAlta (8.1)1.7%—Cminds CM Download Manager7/7/202117/6/2026
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.
ModificadaMedia (6.1)1.00%—Cminds CM Download Manager7/7/202117/6/2026
Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action.
ModificadaMedia (6.1)1.0%—Cminds CM Download Manager21/10/202017/6/2026
The cm-download-manager plugin before 2.8.0 for WordPress allows XSS.
ModificadaAlta (7.8)4.8%—Adobe Download Manager17/7/202017/6/2026
Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
ModificadaAlta (7.8)0.96%—Symantec Norton Download Manager14/1/202017/6/2026
A vulnerability was found in Symantec Norton Download Manager versions prior to 5.6. A remote user can create a specially crafted DLL file that, when placed on the target user's system, will cause the Norton Download Manager component to load the remote user's DLL instead of the intended DLL and execute arbitrary code…
ModificadaCrítica (9.8)3.3%—Adobe Download Manager17/10/201917/6/2026
Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.
ModificadaMedia (6.1)11%💥 ExploitW3eden Download Manager3/9/201917/6/2026
The download-manager plugin before 2.9.94 for WordPress has XSS via the category shortcode feature, as demonstrated by the orderby or search[publish_date] parameter.
ModificadaCrítica (9.8)0.77%—Canonical Ubuntu Download Manager22/4/201917/6/2026
UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications. Before UDM version 1.2+16.04.20160408-0ubuntu1 any confined application could make use of the UDM C++ API to run…
ModificadaCrítica (9.8)2.9%—Shdesigns Resident Download Manager13/7/201817/6/2026
SHDesigns' Resident Download Manager provides firmware update capabilities for Rabbit 2000/3000 CPU boards, which according to the reporter may be used in some industrial control and embedded applications. The Resident Download Manager does not verify that the firmware is authentic before executing code and deploying…
ModificadaMedia (6.1)0.92%—W3eden Download Manager16/1/201817/6/2026
The download-manager plugin before 2.9.52 for WordPress has XSS via the id parameter in a wpdm_generate_password action to wp-admin/admin-ajax.php.
ModificadaCrítica (9.8)40%💥 ExploitXi-soft Nettransport Download Manager29/12/201717/6/2026
A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP response.
ModificadaCrítica (9.8)19%💥 ExploitGetgosoft Getgo Download Manager27/12/201717/6/2026
A buffer overflow vulnerability in GetGo Download Manager 5.3.0.2712 and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long response.
ModificadaAlta (8.8)11%💥 ExploitW3eden Download Manager7/8/201717/6/2026
The basic_settings function in the download manager plugin for WordPress before 2.7.3 allows remote authenticated users to update every WordPress option.
ModificadaMedia (6.1)1.5%—W3eden Download Manager7/7/201717/6/2026
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (6.1)1.4%—W3eden Download Manager7/7/201717/6/2026
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Orbitaley — Vulnerabilidades