Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.35% | — | ALL Video DownloaderAI | 11/11/2024 | 17/6/2026 | The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component. | |
| Aplazada | Alta (8.1) | 0.35% | — | Superfast Video DownloaderAIBluesky BrowserAI | 11/11/2024 | 17/6/2026 | The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component. | |
| Aplazada | Crítica (9.1) | 0.38% | — | SYQ Com.downloader.video.fastAI | 11/11/2024 | 17/6/2026 | The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.video.fast.SpeedMainAct component. | |
| Aplazada | Media (5.4) | 0.24% | — | DS Allvideo.downloader.browserAI | 11/11/2024 | 17/6/2026 | The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component. | |
| Analizada | Media (5.3) | 0.51% | — | Projectworlds Free Download Online Shopping System | 11/11/2024 | 17/6/2026 | A vulnerability was found in Project Worlds Free Download Online Shopping System up to 192.168.1.88. It has been rated as critical. This issue affects some unknown processing of the file /online-shopping-webvsite-in-php-master/success.php. The manipulation of the argument id leads to sql injection. The attack may be… | |
| Aplazada | Alta (8.5) | 0.40% | — | Reza19 Download-mirror-counterAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in reza19 Download-Mirror-Counter wp-download-mirror-counter allows SQL Injection.This issue affects Download-Mirror-Counter: from n/a through <= 1.1. | |
| Aplazada | Alta (8.1) | 0.40% | — | Inshot Video Downloader - XdownloaderAI | 7/11/2024 | 17/6/2026 | The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.privatebrowser.activity.PrivateMainActivity component. | |
| Aplazada | Alta (8.8) | 0.46% | — | ASD Com.rocks.video.downloaderAIGoogle AndroidAI | 7/11/2024 | 17/6/2026 | The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitrary JavaScript code via the com.rocks.video.downloader.MainBrowserActivity component. | |
| Analizada | Alta (8.8) | 0.49% | — | Awesomemotive Easy Digital Downloads | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.2.12. | |
| Aplazada | Alta (8.1) | 0.34% | — | Apptool Browser Video ALL Video DownloaderAI | 30/10/2024 | 17/6/2026 | The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component. | |
| Aplazada | Crítica (9.8) | 1.0% | 💥 PoC | Daschmi Ds.downloadlistAI | 30/10/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Daschmi DS.DownloadList dsdownloadlist allows Object Injection.This issue affects DS.DownloadList: from n/a through <= 1.3. | |
| Analizada | Media (5.4) | 0.31% | — | W3eden Download Manager | 30/10/2024 | 17/6/2026 | The Download Manager WordPress plugin before 3.3.00 doesn't sanitize some of it's shortcode parameters, leading to cross site scripting. | |
| Aplazada | Media (4.3) | 0.41% | — | Download MonitorAI | 30/10/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_search_users function in all versions up to, and including, 5.0.13. This makes it possible for authenticated attackers, with Subscriber-level access and above, to obtain usernames… | |
| Aplazada | Media (4.3) | 0.45% | — | Ironikus Download MonitorAI | 26/10/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_handle_api_key_actions function in all versions up to, and including, 5.0.12. This makes it possible for authenticated attackers, with Subscriber-level access and above, to revoke… | |
| Analizada | Media (6.5) | 0.41% | — | Metagauss Download Plugin | 23/10/2024 | 17/6/2026 | The Download Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability checks on the 'dpwap_handle_download_user' and 'dpwap_handle_download_comment' functions in all versions up to, and including, 2.2.0. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.6) | 0.59% | — | Codeflock Free Download ManagerAI | 17/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER free-download-manager allows Path Traversal.This issue affects FREE DOWNLOAD MANAGER: from n/a through <= 1.0.0. | |
| Analizada | Alta (7.5) | 0.47% | — | Wpchill Download Monitor | 16/10/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several REST-API routes related to reporting in versions up to, and including, 4.7.51. This makes it possible for unauthenticated attackers to view user data and other sensitive information intended for… | |
| Aplazada | Media (6.1) | 0.38% | — | Download Plugins AND Themes IN ZIP From DashboardAI | 11/10/2024 | 17/6/2026 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.1. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Alta (7.1) | 0.32% | — | Lesterchan Wp-downloadmanagerAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lester Chan WP-DownloadManager wp-downloadmanager allows Reflected XSS.This issue affects WP-DownloadManager: from n/a through <= 1.68.8. | |
| Analizada | Media (4.3) | 0.37% | — | Wpchill Download Monitor | 26/9/2024 | 17/6/2026 | The Download Monitor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the enable_shop() function in all versions up to, and including, 5.0.9. This makes it possible for authenticated attackers, with Subscriber-level access and above, to enable shop… | |
| Analizada | Media (4.3) | 0.18% | — | Wpdownloadmanager Premium Packages - Sell Digital Products Securely | 25/9/2024 | 17/6/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce validation on the addRefund() function. This makes it possible for unauthenticated attackers to perform actions such as… | |
| Analizada | Alta (7.2) | 0.69% | — | Awesomemotive Easy Digital Downloads | 24/9/2024 | 17/6/2026 | The Easy Digital Downloads – Simple eCommerce for Selling Digital Files plugin for WordPress is vulnerable to deserialization of untrusted input via the 'upload[file]' parameter in versions up to, and including 3.3.3. This makes it possible for authenticated administrative users to call files using a PHAR wrapper,… | |
| Analizada | Alta (7) | 0.25% | — | Qnap Download Station | 6/9/2024 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Download Station 5.8.6.283 ( 2024/06/21 ) and later | |
| Analizada | Crítica (9.8) | 2.6% | 💥 Exploit | Awesomemotive Easy Digital Downloads | 29/8/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Easy Digital Downloads allows SQL Injection.This issue affects Easy Digital Downloads: from n/a through 3.2.12. | |
| Aplazada | Media (4.2) | 0.17% | — | Download Plugins AND Themes IN ZIP From DashboardAI | 16/8/2024 | 17/6/2026 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.8.7. This is due to missing or incorrect nonce validation on the download_theme() function. This makes it possible for unauthenticated attackers to download… |