Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
615 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.26% | — | Easydigitaldownloads Easy Digital DownloadsAI | 6/10/2026 | 6/10/2026 | Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.7.1 versions. | |
| Pendiente de análisis | Crítica (9.1) | 0.41% | — | Image-downloaderAI | 2/10/2026 | 3/10/2026 | Path traversal in image-downloader 4.3.0 allows an attacker who can control the download URL to cause downloaded response data to be written outside the configured destination directory. | |
| Aplazada | Media (5.3) | 0.33% | — | Shahjada Download ManagerAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Shahjada Download Manager allows Retrieve Embedded Sensitive Data. This issue affects Download Manager: from n/a through 3.3.71. | |
| Aplazada | Media (6.4) | 0.22% | — | Download ManagerAI | 2/10/2026 | 3/10/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject… | |
| Aplazada | Alta (7.2) | 0.31% | — | Download MonitorAI | 2/10/2026 | 2/10/2026 | The Download Monitor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Origin postMessage to Admin Editor in all versions up to, and including, 5.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.4) | 0.20% | — | Download ManagerAI | 1/10/2026 | 1/10/2026 | The Download Manager WordPress plugin before 3.3.71 does not sufficiently sanitise and escape a package setting before outputting it back in a page, which could allow users with the Author role and above to perform Stored Cross-Site Scripting attacks against any visitor who opens the package's download dialogue,… | |
| Aplazada | Media (5.5) | 0.28% | — | Athlon1600 Youtube-downloaderAI | 28/9/2026 | 28/9/2026 | A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and… | |
| Aplazada | Alta (8.8) | 0.28% | — | Download ManagerAI | 27/9/2026 | 28/9/2026 | The Download Manager WordPress plugin before 7.5.6 does not sanitise and escape data submitted through its email-locked download subscription form before outputting it back in an admin page, which could allow unauthenticated attackers to perform Stored Cross-Site Scripting attacks against administrators. This affects… | |
| Aplazada | Alta (7.6) | 0.29% | — | Easydigitaldownloads Easy Digital DownloadsAI | 23/9/2026 | 23/9/2026 | Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. | |
| Aplazada | Media (6.5) | 0.41% | — | Download ManagerAI | 18/9/2026 | 18/9/2026 | The Download Manager plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.3.68 via the duplicate() function hooked on admin_init. This is due to the handler only verifying the generic 'edit_posts' capability and a plugin-wide static nonce (NONCE_KEY) without any… | |
| Aplazada | Alta (8.1) | 0.91% | — | Paid DownloadsAI | 17/9/2026 | 19/9/2026 | The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin()… | |
| Aplazada | Alta (8.5) | 0.15% | — | Tonec Internet Download ManagerAI | 13/9/2026 | 15/9/2026 | A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. Internet Download Manager for… | |
| Aplazada | Alta (7.5) | 0.68% | — | Direct Download FOR WoocommerceAI | 10/9/2026 | 10/9/2026 | The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive… | |
| Aplazada | Media (6.5) | 0.68% | — | Joomunited WP File DownloadAI | 5/9/2026 | 8/9/2026 | The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain… | |
| Aplazada | Alta (8.7) | 0.50% | — | Douyin Tiktok Download APIAI | 4/9/2026 | 10/9/2026 | Douyin_TikTok_Download_API through 4.1.2 contains a server-side request forgery vulnerability in the /api/download and /api/hybrid/video_data endpoints that allows unauthenticated attackers to fetch arbitrary URLs by supplying a url query parameter. Attackers can request internal services including cloud metadata… | |
| Aplazada | Alta (8.1) | 0.52% | — | Joomunited WP File DownloadAI | 2/9/2026 | 4/9/2026 | The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead… | |
| Aplazada | Alta (8.7) | 0.35% | — | Actions Upload-artifactAIActions Download-artifactAI | 24/8/2026 | 24/9/2026 | act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and DeleteArtifact, accept a caller-supplied workflow_run_backend_id and… | |
| Aplazada | Media (5.3) | 0.44% | — | Phoca DownloadAI | 20/8/2026 | 26/8/2026 | Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdownloadmanager Wpdm Premium PackagesAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | |
| Aplazada | Media (5.3) | 0.30% | — | Download MonitorAI | 8/8/2026 | 26/8/2026 | The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the nonce protecting it to unauthenticated visitors, allowing unauthenticated users to inject arbitrary download log entries and inflate a site's download statistics. | |
| Aplazada | Alta (7.2) | 0.50% | — | Wpdownloadmanager WP DownloadmanagerAI | 5/8/2026 | 26/8/2026 | The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no… | |
| Aplazada | Media (6.4) | 0.42% | — | Download ManagerAI | 1/8/2026 | 12/8/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and including, 3.3.66 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to… | |
| Aplazada | Media (5.4) | 0.27% | — | Download ManagerAI | 1/8/2026 | 26/8/2026 | The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in the front-end package templates, allowing users with the Author role or above to store a title that results in arbitrary JavaScript execution in the browser of any user, including unauthenticated… | |
| Aplazada | Alta (7.2) | 1.2% | — | Easydigitaldownloads Easy Digital DownloadsAI | 29/7/2026 | 30/7/2026 | The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insufficient file type validation in the edd_do_ajax_import_file_upload() function , which only checks the client-supplied $_FILES['edd-import-file']['type'] Content-Type header… | |
| Aplazada | Media (4.9) | 0.50% | — | Easydigitaldownloads Easy Digital DownloadsAI | 27/7/2026 | 27/7/2026 | Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6.9 versions. |