Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

615 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.26%—Easydigitaldownloads Easy Digital DownloadsAI6/10/20266/10/2026
Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.7.1 versions.
Pendiente de análisisCrítica (9.1)0.41%—Image-downloaderAI2/10/20263/10/2026
Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory.
AplazadaMedia (5.3)0.33%—Shahjada Download ManagerAI2/10/20262/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71.
AplazadaMedia (6.4)0.22%—Download ManagerAI2/10/20263/10/2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject…
AplazadaAlta (7.2)0.31%—Download MonitorAI2/10/20262/10/2026
The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
AplazadaMedia (6.4)0.20%—Download ManagerAI1/10/20261/10/2026
The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue,…
AplazadaMedia (5.5)0.28%—Athlon1600 Youtube-downloaderAI28/9/202628/9/2026
A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and…
AplazadaAlta (8.8)0.28%—Download ManagerAI27/9/202628/9/2026
The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects…
AplazadaAlta (7.6)0.29%—Easydigitaldownloads Easy Digital DownloadsAI23/9/202623/9/2026
Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions.
AplazadaMedia (6.5)0.41%—Download ManagerAI18/9/202618/9/2026
The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any…
AplazadaAlta (8.1)0.91%—Paid DownloadsAI17/9/202619/9/2026
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin()…
AplazadaAlta (8.5)0.15%—Tonec Internet Download ManagerAI13/9/202615/9/2026
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. Internet Download Manager for…
AplazadaAlta (7.5)0.68%—Direct Download FOR WoocommerceAI10/9/202610/9/2026
The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive…
AplazadaMedia (6.5)0.68%—Joomunited WP File DownloadAI5/9/20268/9/2026
The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain…
AplazadaAlta (8.7)0.50%—Douyin Tiktok Download APIAI4/9/202610/9/2026
Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata…
AplazadaAlta (8.1)0.52%—Joomunited WP File DownloadAI2/9/20264/9/2026
The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead…
AplazadaAlta (8.7)0.35%—Actions Upload-artifactAIActions Download-artifactAI24/8/202624/9/2026
act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and DeleteArtifact, accept a caller-supplied workflow_run_backend_id and…
AplazadaMedia (5.3)0.44%—Phoca DownloadAI20/8/202626/8/2026
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
AplazadaAlta (7.1)0.25%—Wpdownloadmanager Wpdm Premium PackagesAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
AplazadaMedia (5.3)0.30%—Download MonitorAI8/8/202626/8/2026
The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics.
AplazadaAlta (7.2)0.50%—Wpdownloadmanager WP DownloadmanagerAI5/8/202626/8/2026
The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no…
AplazadaMedia (6.4)0.42%—Download ManagerAI1/8/202612/8/2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to…
AplazadaMedia (5.4)0.27%—Download ManagerAI1/8/202626/8/2026
The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated…
AplazadaAlta (7.2)1.2%—Easydigitaldownloads Easy Digital DownloadsAI29/7/202630/7/2026
The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in the edd_do_ajax_import_file_upload() function , which only checks the client-supplied $_FILES['edd-import-file']['type'] Content-Type header…
AplazadaMedia (4.9)0.50%—Easydigitaldownloads Easy Digital DownloadsAI27/7/202627/7/2026
Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions.