Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
133 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 27% | 💥 Exploit | Cisco Activetouch General Plugin ContainerCisco Download ManagerCisco Gpccontainer ClassCisco Webex+2 | 1/2/2017 | 17/6/2026 | An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on… | |
| Modificada | Media (4.7) | 0.28% | — | SAP Download Manager | 14/12/2016 | 17/6/2026 | SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of a hardcoded key in the program code and a computer BIOS serial number, aka SAP… | |
| Modificada | Media (4.7) | 0.29% | — | SAP Download Manager | 14/12/2016 | 17/6/2026 | SAP Download Manager 2.1.142 and earlier uses a hardcoded encryption key to protect stored data, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of this key, aka SAP Security Note 2282338. | |
| Modificada | Alta (10) | 14% | 💥 Exploit | Creative Minds CM Download Manager | 5/12/2014 | 17/6/2026 | The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdownloads/, which is processed by the PHP create_function function. | |
| Modificada | Media (6.8) | 1.5% | — | Cminds CM Download Manager | 5/12/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the addons_title parameter in the CMDM_admin_settings page… | |
| Modificada | Media (5) | 2.9% | — | W3eden Download Manager | 4/11/2014 | 17/6/2026 | Directory traversal vulnerability in the WordPress Download Manager plugin for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the fname parameter to (1) views/file_download.php or (2) file_download.php. | |
| Modificada | Media (4.3) | 1.6% | — | HOT Files\ File Sharing AND Download Manager Project | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in tpls/editmedia.php in the Hot Files: File Sharing and Download Manager (wphotfiles) plugin 1.0.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the mediaid parameter. | |
| Modificada | Alta (9.3) | 17% | 💥 Exploit | Freedownloadmanager Free Download Manager | 18/3/2014 | 17/6/2026 | Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name, which is then deleted from the download… | |
| Modificada | Alta (10) | 61% | 💥 Exploit | Getgosoft Getgo Download Manager | 5/3/2014 | 17/6/2026 | Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long HTTP Response Header. | |
| Modificada | Media (4.3) | 4.6% | 💥 Exploit | W3eden Download Manager | 6/2/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Phux Download Manager | 2/2/2012 | 16/6/2026 | SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter. | |
| Modificada | Alta (7.1) | 1.7% | — | Freedownloadmanager Free Download Manager | 17/5/2010 | 16/6/2026 | Directory traversal vulnerability in Free Download Manager (FDM) before 3.0.852 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file. | |
| Modificada | Alta (10) | 6.4% | — | Freedownloadmanager Free Download Manager | 17/5/2010 | 16/6/2026 | Multiple stack-based buffer overflows in Free Download Manager (FDM) before 3.0.852 allow remote attackers to execute arbitrary code via vectors involving (1) the folders feature in Site Explorer, (2) the websites feature in Site Explorer, (3) an FTP URI, or (4) a redirect. | |
| Modificada | Alta (9.3) | 8.1% | — | Tonec Internet Download Manager | 6/5/2010 | 16/6/2026 | Stack-based buffer overflow in Internet Download Manager (IDM) before 5.19 allows remote attackers to execute arbitrary code via a crafted FTP URI that causes unspecified "test sequences" to be sent from client to server. | |
| Modificada | Alta (9.3) | 5.2% | — | NOS Microsystems Getplus Download ManagerAdobe Download Manager | 23/2/2010 | 16/6/2026 | A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a… | |
| Modificada | Alta (9.3) | 3.3% | — | Akamai Technologies Download Manager | 23/7/2009 | 16/6/2026 | Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a Redswoosh download, a different vulnerability than CVE-2007-1891 and CVE-2007-1892. | |
| Modificada | Alta (7.2) | 5.6% | 💥 Exploit | NOS Microsystems Getplus Download ManagerAdobe Acrobat ReaderCorel Getplus Download Manager | 21/7/2009 | 16/6/2026 | NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus Download Manager before 1.5.0.48, and possibly other products, installs NOS\bin\getPlus_HelperSvc.exe with insecure permissions (Everyone:Full Control), which allows local users to gain SYSTEM… | |
| Modificada | Alta (9.3) | 28% | 💥 Exploit | Free Download Manager | 3/2/2009 | 16/6/2026 | Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file. | |
| Modificada | Alta (10) | 67% | 💥 Exploit | Free Download Manager | 3/2/2009 | 16/6/2026 | Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allows remote attackers to execute arbitrary code via a long Authorization header in an HTTP request. | |
| Modificada | Alta (9.3) | 4.0% | — | NOS Microsystems Getplus Download Manager | 8/12/2008 | 16/6/2026 | Stack-based buffer overflow in the getPlus ActiveX control in gp.ocx 1.2.2.50 in NOS Microsystems getPlus Download Manager, as used for the Adobe Reader 8.1 installation process and other downloads, allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2008-4817. | |
| Modificada | Alta (7.8) | 5.7% | 💥 Exploit | Tonec Inc. Internet Download Manager | 9/10/2008 | 16/6/2026 | Stack-based buffer overflow in the file parsing function in Tonec Internet Download Manager, possibly 5.14 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AppleDouble file containing a long string. NOTE: this is probably a different… | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Akamai Download Manager | 4/6/2008 | 16/6/2026 | CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an encoded LF followed by a malicious target line. | |
| Modificada | Media (6.8) | 11% | — | Akamai Technologies Download Manager | 1/5/2008 | 16/6/2026 | The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified "undocumented object parameters." | |
| Modificada | Media (6.8) | 4.2% | 💥 Exploit | Linux WEB Shop PHP Download Manager | 27/2/2008 | 16/6/2026 | Directory traversal vulnerability in include/body.inc.php in Linux Web Shop (LWS) php Download Manager 1.0 and 1.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the content parameter. | |
| Modificada | Media (6.8) | 30% | 💥 Exploit | Altnet Download ManagerGroksterKazaa Media Desktop | 5/10/2007 | 16/6/2026 | Stack-based buffer overflow in the ADM4 ActiveX control in adm4.dll in Altnet Download Manager 4.0.0.6, as used in (1) Kazaa 3.2.7 and (2) Grokster, allows remote attackers to execute arbitrary code via a long argument to the Install method. NOTE: the provenance of this information is unknown; the details are obtained… |