Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3040▲ 560 respecto a la semana anterior
Críticas / altas1452▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

95 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.25%—Wpdownloadmanager Wpdm Premium PackagesAI18/8/202620/8/2026
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
AplazadaAlta (7.2)0.50%—Wpdownloadmanager WP DownloadmanagerAI5/8/202626/8/2026
The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_can('manage_downloads')) to upload arbitrary files via download-add.php with no extension or MIME-type validation of any kind - no wp_check_filetype_and_ext, no…
AplazadaAlta (8.6)0.15%—Freedownloadmanager Free Download ManagerAI29/4/202617/6/2026
Free Download Manager 2.0 Build 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploitation. Attackers can craft a malicious URL file that, when imported through the File > Import > Import lists of downloads…
AplazadaMedia (6.5)1.3%—Wpdownloadmanager WP DownloadmanagerAI18/2/202617/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'file' parameter in the file deletion functionality. This is due to insufficient validation of user-supplied file paths, allowing directory traversal sequences. This makes it possible for…
AplazadaBaja (2.7)0.75%—Wpdownloadmanager Wp-downloadmanagerAI18/2/202617/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.69 via the 'download_path' configuration parameter. This is due to insufficient validation of the download path setting, which allows directory traversal sequences to bypass the WP_CONTENT_DIR prefix…
AnalizadaMedia (5.5)0.60%—Zohocorp Manageengine Admanager Plus13/1/202617/6/2026
Zohocorp ManageEngine ADManager Plus versions below 7230 are vulnerable to Path Traversal in the User Management module
AnalizadaMedia (4.3)0.44%—Zohocorp Manageengine Admanager Plus15/12/202530/9/2026
Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is exploitable only by technicians who have the “Impersonate as Admin” option enabled.
AnalizadaAlta (8.8)4.5%—Zohocorp Manageengine Admanager Plus21/10/202517/6/2026
Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.
AplazadaAlta (7.2)0.66%—Wpdownloadmanager Wp-downloadmanagerAI26/9/202517/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the download-add.php file in all versions up to, and including, 1.68.11. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on…
AnalizadaAlta (7.2)0.94%—Wp-downloadmanager Project Wp-downloadmanager11/6/202517/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file deletion due to lack of restriction on the directory a file can be deleted from in all versions up to, and including, 1.68.10. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary…
AnalizadaMedia (4.9)0.42%—Wp-downloadmanager Project Wp-downloadmanager11/6/202517/6/2026
The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.68.10. This is due to a lack of restriction on the directory an administrator can select for storing downloads. This makes it possible for authenticated attackers, with Administrator-level access…
AplazadaAlta (8.6)0.35%—Reint DownloadmanagerAITypo3AI21/5/202517/6/2026
The reint_downloadmanager extension through 5.0.0 for TYPO3 allows Insecure Direct Object Reference.
AplazadaCrítica (9.6)0.26%—Huangye Wudeng Hacklog DownloadmanagerAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog DownloadManager hacklog-downloadmanager allows Upload a Web Shell to a Web Server.This issue affects Hacklog DownloadManager: from n/a through <= 2.1.4.
ModificadaAlta (7.2)0.46%—Wpdownloadmanager Premium Packages - Sell Digital Products Securely18/11/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages.This issue affects WPDM – Premium Packages: from n/a through <= 6.0.5.
AnalizadaAlta (8.8)6.2%—Zohocorp Manageengine Admanager Plus8/11/202417/6/2026
Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option.
AnalizadaAlta (8.8)3.2%—Zohocorp Manageengine Admanager Plus4/11/202417/6/2026
Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report.
AplazadaAlta (7.1)0.32%—Lesterchan Wp-downloadmanagerAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lester Chan WP-DownloadManager wp-downloadmanager allows Reflected XSS.This issue affects WP-DownloadManager: from n/a through <= 1.68.8.
AplazadaAlta (7.5)0.56%—Amarksteadman PodiantAI5/10/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in amarksteadman Podiant podiant allows PHP Local File Inclusion.This issue affects Podiant: from n/a through <= 1.1.
AnalizadaMedia (4.3)0.18%—Wpdownloadmanager Premium Packages - Sell Digital Products Securely25/9/202417/6/2026
The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce validation on the addRefund() function. This makes it possible for unauthenticated attackers to perform actions such as…
ModificadaMedia (5.4)0.26%—Wpdownloadmanager Download Manager5/6/202417/6/2026
The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpdm_modal_login_form' shortcode in all versions up to, and including, 3.2.93 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaAlta (8.8)0.29%—NEW Adman Project NEW Adman13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in gl_SPICE New Adman plugin <= 1.6.8 versions.
ModificadaMedia (5.4)2.4%—Zohocorp Manageengine Admanager Plus27/9/202317/6/2026
Zoho ManageEngine ADManager Plus before 7203 allows 2FA bypass (for AuthToken generation) in REST APIs.
ModificadaAlta (7.2)11%—Zohocorp Manageengine Admanager Plus11/9/202317/6/2026
Zoho ManageEngine ADManager Plus before Build 7200 allows admin users to execute commands on the host machine.
AnalizadaMedia (4.9)3.8%—Zohocorp Manageengine Admanager Plus31/8/202317/6/2026
Zoho ManageEngine ADManager Plus before 7203 allows Help Desk Technician users to read arbitrary files on the machine where this product is installed.