Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Wpdownloadmanager Wpdm Premium PackagesAI | 18/8/2026 | 20/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions. | |
| Aplazada | Alta (7.2) | 0.50% | — | Wpdownloadmanager WP DownloadmanagerAI | 5/8/2026 | 26/8/2026 | The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no… | |
| Aplazada | Alta (8.6) | 0.15% | — | Freedownloadmanager Free Download ManagerAI | 29/4/2026 | 17/6/2026 | Free Download Manager 2.0 Build 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploitation. Attackers can craft a malicious URL file that, when imported through the File > Import > Import lists of downloads… | |
| Aplazada | Media (6.5) | 1.3% | — | Wpdownloadmanager WP DownloadmanagerAI | 18/2/2026 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'file' parameter in the file deletion functionality. This is due to insufficient validation of user-supplied file paths, allowing directory traversal sequences. This makes it possible for… | |
| Aplazada | Baja (2.7) | 0.75% | — | Wpdownloadmanager Wp-downloadmanagerAI | 18/2/2026 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'download_path' configuration parameter. This is due to insufficient validation of the download path setting, which allows directory traversal sequences to bypass the WP_CONTENT_DIR prefix… | |
| Analizada | Media (5.5) | 0.60% | — | Zohocorp Manageengine Admanager Plus | 13/1/2026 | 17/6/2026 | Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module | |
| Analizada | Media (4.3) | 0.44% | — | Zohocorp Manageengine Admanager Plus | 15/12/2025 | 30/9/2026 | Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled. | |
| Analizada | Alta (8.8) | 4.5% | — | Zohocorp Manageengine Admanager Plus | 21/10/2025 | 17/6/2026 | Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component. | |
| Aplazada | Alta (7.2) | 0.66% | — | Wpdownloadmanager Wp-downloadmanagerAI | 26/9/2025 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file in all versions up to, and including, 1.68.11. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on… | |
| Analizada | Alta (7.2) | 0.94% | — | Wp-downloadmanager Project Wp-downloadmanager | 11/6/2025 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary… | |
| Analizada | Media (4.9) | 0.42% | — | Wp-downloadmanager Project Wp-downloadmanager | 11/6/2025 | 17/6/2026 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storing downloads. This makes it possible for authenticated attackers, with Administrator-level access… | |
| Aplazada | Alta (8.6) | 0.35% | — | Reint DownloadmanagerAITypo3AI | 21/5/2025 | 17/6/2026 | The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference. | |
| Aplazada | Crítica (9.6) | 0.26% | — | Huangye Wudeng Hacklog DownloadmanagerAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog DownloadManager hacklog-downloadmanager allows Upload a Web Shell to a Web Server.This issue affects Hacklog DownloadManager: from n/a through <= 2.1.4. | |
| Modificada | Alta (7.2) | 0.46% | — | Wpdownloadmanager Premium Packages - Sell Digital Products Securely | 18/11/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages.This issue affects WPDM – Premium Packages: from n/a through <= 6.0.5. | |
| Analizada | Alta (8.8) | 6.2% | — | Zohocorp Manageengine Admanager Plus | 8/11/2024 | 17/6/2026 | Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option. | |
| Analizada | Alta (8.8) | 3.2% | — | Zohocorp Manageengine Admanager Plus | 4/11/2024 | 17/6/2026 | Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report. | |
| Aplazada | Alta (7.1) | 0.32% | — | Lesterchan Wp-downloadmanagerAI | 6/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lester Chan WP-DownloadManager wp-downloadmanager allows Reflected XSS.This issue affects WP-DownloadManager: from n/a through <= 1.68.8. | |
| Aplazada | Alta (7.5) | 0.56% | — | Amarksteadman PodiantAI | 5/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in amarksteadman Podiant podiant allows PHP Local File Inclusion.This issue affects Podiant: from n/a through <= 1.1. | |
| Analizada | Media (4.3) | 0.18% | — | Wpdownloadmanager Premium Packages - Sell Digital Products Securely | 25/9/2024 | 17/6/2026 | The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce validation on the addRefund() function. This makes it possible for unauthenticated attackers to perform actions such as… | |
| Modificada | Media (5.4) | 0.26% | — | Wpdownloadmanager Download Manager | 5/6/2024 | 17/6/2026 | The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Modificada | Media (5.5) | 0.69% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+35 | 15/11/2023 | 17/6/2026 | An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the… | |
| Modificada | Alta (8.8) | 0.29% | — | NEW Adman Project NEW Adman | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in gl_SPICE New Adman plugin <= 1.6.8 versions. | |
| Modificada | Media (5.4) | 2.4% | — | Zohocorp Manageengine Admanager Plus | 27/9/2023 | 17/6/2026 | Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs. | |
| Modificada | Alta (7.2) | 11% | — | Zohocorp Manageengine Admanager Plus | 11/9/2023 | 17/6/2026 | Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine. | |
| Analizada | Media (4.9) | 3.8% | — | Zohocorp Manageengine Admanager Plus | 31/8/2023 | 17/6/2026 | Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed. |