Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.27% | — | ALL IN ONE Video DownloaderAI | 4/6/2026 | 22/7/2026 | All in One Video Downloader 1.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send requests to the admin interface with UNION-based SQL injection payloads in the id parameter to extract… | |
| Aplazada | Alta (8.1) | 0.35% | — | ALL Video DownloaderAI | 11/11/2024 | 17/6/2026 | The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component. | |
| Aplazada | Alta (8.1) | 0.35% | — | Superfast Video DownloaderAIBluesky BrowserAI | 11/11/2024 | 17/6/2026 | The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component. | |
| Aplazada | Media (5.4) | 0.24% | — | DS Allvideo.downloader.browserAI | 11/11/2024 | 17/6/2026 | The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component. | |
| Aplazada | Alta (8.1) | 0.40% | — | Inshot Video Downloader - XdownloaderAI | 7/11/2024 | 17/6/2026 | The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.privatebrowser.activity.PrivateMainActivity component. | |
| Aplazada | Alta (8.8) | 0.46% | — | ASD Com.rocks.video.downloaderAIGoogle AndroidAI | 7/11/2024 | 17/6/2026 | The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitrary JavaScript code via the com.rocks.video.downloader.MainBrowserActivity component. | |
| Aplazada | Alta (8.1) | 0.34% | — | Apptool Browser Video ALL Video DownloaderAI | 30/10/2024 | 17/6/2026 | The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component. | |
| Modificada | Alta (7.5) | 1.2% | — | Story Saver FOR Instagram - Video Downloader Project Story Saver FOR Instagram - Video Downloader | 1/6/2023 | 17/6/2026 | Story Saver for Instragram - Video Downloader 1.0.6 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application is opened.… | |
| Modificada | Crítica (9.8) | 1.3% | — | Story Saver FOR Instagram - Video Downloader Project Story Saver FOR Instagram - Video Downloader | 31/5/2023 | 17/6/2026 | Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application is opened.… | |
| Modificada | Alta (7.5) | 2.0% | — | Ninjateam Video Downloader FOR Tiktok | 7/7/2021 | 17/6/2026 | Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter. | |
| Modificada | Crítica (9.8) | 1.7% | — | Ninjateam Video Downloader FOR Tiktok | 7/7/2021 | 17/6/2026 | Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open ports, local network hosts and execute… | |
| Modificada | Media (6.1) | 1.8% | — | Avast Secure BrowserAVG Secure BrowserVideo Downloader Project Video Downloader | 13/1/2020 | 17/6/2026 | XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute their code in the context of this component. While Video Downloader is technically a browser extension, it is granted a very wide set of privileges and can for example… | |
| Modificada | Media (6.1) | 0.60% | — | Videodownloaderultimate Video Downloader | 11/4/2018 | 17/6/2026 | The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to a link64_msgAddLinks event. | |
| Modificada | Alta (7.5) | 4.7% | — | Converto Video Downloader & Converter Project Converto Video Downloader & Converter | 29/10/2017 | 17/6/2026 | ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php. | |
| Modificada | Media (5.4) | 0.27% | — | Easy Video Downloader Project Easy Video Downloader | 16/10/2014 | 17/6/2026 | The Easy Video Downloader (aka com.simon.padillar.EasyVideo) application 4.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. |