Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades conocidas

Página 50 de 95. Los registros están ordenados por fecha oficial de publicación, del más reciente al más antiguo.

Registros 4901–5000 de 9.413

Media

WordPress · Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

CVE-2026-6566: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery. Photo Gallery, Sliders, Proofing and Themes – NextGEN Gallery: 0 hasta 4.2.0

Leer análisis →
Media

WordPress · Anomify AI – Anomaly Detection and Alerting

CVE-2026-6404: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Anomify AI – Anomaly Detection and Alerting

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Anomify AI – Anomaly Detection and Alerting. Anomify AI – Anomaly Detection and Alerting: 0 hasta 0.3.6

Leer análisis →
Media

WordPress · Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

CVE-2026-6394: CWE-918: vulnerabilidad de seguridad en Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE

El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE. Nexa Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE: 0 hasta 1.1.1

Leer análisis →
Media

WordPress · 診断ジェネレータ作成プラグイン

CVE-2026-5293: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en 診断ジェネレータ作成プラグイン

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en 診断ジェネレータ作成プラグイン. 診断ジェネレータ作成プラグイン: 0 hasta 1.4.16

Leer análisis →
Alta

WordPress · AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

CVE-2026-5200: CWE-862: Falta de autorización en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress. AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress: 0 hasta 10.8.2

Leer análisis →
Media

WordPress · All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic

CVE-2026-5075: CWE-200: Exposición de información sensible a un actor no autorizado en All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic

El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic. All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic: 0 hasta 4.9.7

Leer análisis →
Alta

WordPress · Creative Mail – Easier WordPress & WooCommerce Email Marketing

CVE-2026-3985: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Creative Mail – Easier WordPress & WooCommerce Email Marketing

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Creative Mail – Easier WordPress & WooCommerce Email Marketing. Creative Mail – Easier WordPress & WooCommerce Email Marketing: 0 hasta 1.6.9

Leer análisis →
Media

WordPress · AI Chatbot & Workflow Automation by AIWU

CVE-2026-2955: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en AI Chatbot & Workflow Automation by AIWU

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en AI Chatbot & Workflow Automation by AIWU. AI Chatbot & Workflow Automation by AIWU: 0 hasta 1.4.14

Leer análisis →
Alta

WordPress · Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

CVE-2026-8912: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe. Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: 0 hasta 28.1.6

Leer análisis →
Media

Windows Server · Windows 11 Version 24H2 / Windows 11 Version 25H2 / Windows 11 version 26H1

CVE-2026-45585: CWE-77: vulnerabilidad de seguridad en Windows 11 Version 24H2 / Windows 11 Version 25H2 / Windows 11 version 26H1

El registro oficial identifica la vulnerabilidad «CWE-77: vulnerabilidad de seguridad» en Windows 11 Version 24H2 / Windows 11 Version 25H2 / Windows 11 version 26H1. Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655; Windows 11 version 26H1: 10.0.28000.0 hasta 10.0.28000.2269; Windows Server 2025: 10.0.26100.0 hasta 10.0.26100.32995; Windows Server 2025 (Server Core installation): 10.0.26100.0 hasta 10.0.26100.32995

Leer análisis →
Crítica

Linux · Linux

CVE-2026-43493: vulnerabilidad de seguridad en Linux

El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: 5a1436beec5744029f3ac90b6fe71a698dcd6155 hasta ae7e95638d956d556d74b9abb9e780d3bd3dcd9e, 5a1436beec5744029f3ac90b6fe71a698dcd6155 hasta 1d7f07df450bac3301938fbc4251f2611be4084e, 5a1436beec5744029f3ac90b6fe71a698dcd6155 hasta 76641449b28979ebd6c02e9598367e119e385236, 5a1436beec5744029f3ac90b6fe71a698dcd6155 hasta 9f1cbca178c03188e201ed175251372149bb25f2, 5a1436beec5744029f3ac90b6fe71a698dcd6155 hasta eb34e243df57e32f4c08fa191f3602ea19076276, 5a1436beec5744029f3ac90b6fe71a698dcd6155 hasta 77d55bc8675ee851ed639dc9be77325a8024cf67; Linux: 2.6.34, 0 hasta 2.6.34, 5.10.258 hasta 5.10.*, 5.15.209 hasta 5.15.*, 6.1.175 hasta 6.1.*, 6.6.140 hasta 6.6.*

Leer análisis →
Sin clasificar

Linux · Linux

CVE-2026-43492: vulnerabilidad de seguridad en Linux

El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: 2d4d1eea540b27c72488fd1914674c42473d53df hasta a1793a48881ec8d26e9c79b0ee65753f1c6846a4, 2d4d1eea540b27c72488fd1914674c42473d53df hasta 1abd50fc3cfa16fc2074a3c8c2729c50fd9d7043, 2d4d1eea540b27c72488fd1914674c42473d53df hasta 6d63615c796c085b4984e3031b9fa77fffb47360, 2d4d1eea540b27c72488fd1914674c42473d53df hasta 2aa77a18dc7f2670497fe3ee5acbeda0b57659e5, 2d4d1eea540b27c72488fd1914674c42473d53df hasta 26d3a97ad46c7a9226ec04d4bf35bd4998a97d16, 2d4d1eea540b27c72488fd1914674c42473d53df hasta 8637dfb4c1d8a7026ef681f2477c6de8b71c4003; Linux: 4.4, 0 hasta 4.4, 5.10.259 hasta 5.10.*, 5.15.210 hasta 5.15.*, 6.1.176 hasta 6.1.*, 6.6.140 hasta 6.6.*

Leer análisis →
Sin clasificar

Linux · Linux

CVE-2026-43491: vulnerabilidad de seguridad en Linux

El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: 0c2204a4ad710d95d348ea006f14ba926e842ffd hasta e6f6cd501fb54060940a6eb3f4103eeb5e426ae7, 0c2204a4ad710d95d348ea006f14ba926e842ffd hasta 3efaad55cad1ded429e3a873bfece389058a526b, 0c2204a4ad710d95d348ea006f14ba926e842ffd hasta 35fb4a0c077c5d1049c2628b769e0a1b1e65df0d, 0c2204a4ad710d95d348ea006f14ba926e842ffd hasta 868202aa2adae427060a42d5bd663b4d782ec02c, 0c2204a4ad710d95d348ea006f14ba926e842ffd hasta d5ee2ff98322337951c56398e79d51815acbf955; Linux: 5.7, 0 hasta 5.7, 6.6.140 hasta 6.6.*, 6.12.86 hasta 6.12.*, 6.18.27 hasta 6.18.*, 7.0.4 hasta 7.0.*

Leer análisis →
Media

WordPress · Classified Listing – AI-Powered Classified ads & Business Directory Plugin

CVE-2026-7563: CWE-862: Falta de autorización en Classified Listing – AI-Powered Classified ads & Business Directory Plugin

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Classified Listing – AI-Powered Classified ads & Business Directory Plugin. Classified Listing – AI-Powered Classified ads & Business Directory Plugin: 0 hasta 5.3.10

Leer análisis →
Media

WordPress · NEX-Forms – Ultimate Forms Plugin for WordPress

CVE-2026-7046: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en NEX-Forms – Ultimate Forms Plugin for WordPress

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en NEX-Forms – Ultimate Forms Plugin for WordPress. NEX-Forms – Ultimate Forms Plugin for WordPress: 0 hasta 9.1.12

Leer análisis →
Media

WordPress · The7 — Website and eCommerce Builder for WordPress

CVE-2026-6646: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en The7 — Website and eCommerce Builder for WordPress

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en The7 — Website and eCommerce Builder for WordPress. The7 — Website and eCommerce Builder for WordPress: 0 hasta 14.3.2

Leer análisis →
Media

WordPress · Advanced Custom Fields: Font Awesome Field

CVE-2026-6415: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Advanced Custom Fields: Font Awesome Field

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Advanced Custom Fields: Font Awesome Field. Advanced Custom Fields: Font Awesome Field: 0 hasta 5.0.2

Leer análisis →
Crítica

WordPress · Receive Notifications After Form Submitting – Form Notify for Any Forms

CVE-2026-5229: CWE-287: Autenticación incorrecta en Receive Notifications After Form Submitting – Form Notify for Any Forms

El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en Receive Notifications After Form Submitting – Form Notify for Any Forms. Receive Notifications After Form Submitting – Form Notify for Any Forms: 0 hasta 1.1.10

Leer análisis →
Alta

Linux · Linux

CVE-2026-46333: CWE-269: Gestión incorrecta de privilegios en Linux

El registro oficial identifica la vulnerabilidad «CWE-269: Gestión incorrecta de privilegios» en Linux. Linux: bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 hasta 93d4ba49d18e3d7fb41a9927c2d0cca5e9dfefd6, bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 hasta 15b828a46f305ae9f05a7c16914b3ce273474205, bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 hasta 4709234fd1b95136ceb789f639b1e7ea5de1b181, bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 hasta 8f907d345bae8f4b3f004c5abc56bf2dfb851ea7, bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 hasta 6e5b51e74a40d377bcd3081dd33fbaa0e1aa7e3d, bfedb589252c01fa505ac9f6f2a3d5d68d707ef4 hasta 2a93a4fac7b6051d3be7cd1b015fe7320cd0404d; Linux: 4.10, 0 hasta 4.10, 5.10.256 hasta 5.10.*, 5.15.207 hasta 5.15.*, 6.1.173 hasta 6.1.*, 6.6.139 hasta 6.6.*

Leer análisis →
Alta

Linux · Linux

CVE-2026-43490: vulnerabilidad de seguridad en Linux

El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 hasta a7fb771314fb3a265d30f8ac245869a367ab065c, e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 hasta 47c6e37a77b10e74f70d845ba4ea5d3cafa00336, e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 hasta 1aa60fea7f637c071f529ad6784aecca2f2f0c5f, e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 hasta c1d95c995d5bcb24b639200a899eda59cb1e6d64, e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 hasta 996454bc0da84d5a1dedb1a7861823087e01a7ae; Linux: 5.15, 0 hasta 5.15, 6.6.141 hasta 6.6.*, 6.12.88 hasta 6.12.*, 6.18.30 hasta 6.18.*, 7.0.7 hasta 7.0.*

Leer análisis →
Crítica

WordPress · Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)

CVE-2026-8181: CWE-287: Autenticación incorrecta en Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative)

El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative). Burst Statistics – Privacy-Friendly WordPress Analytics (Google Analytics Alternative): 3.4.0 hasta 3.4.1.1

Leer análisis →
Media

WordPress · LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

CVE-2026-7648: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en LearnPress – WordPress LMS Plugin for Create and Sell Online Courses. LearnPress – WordPress LMS Plugin for Create and Sell Online Courses: 0 hasta 4.3.5

Leer análisis →
Media

WordPress · Royal Addons for Elementor – Addons and Templates Kit for Elementor

CVE-2026-6504: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Royal Addons for Elementor – Addons and Templates Kit for Elementor

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Royal Addons for Elementor – Addons and Templates Kit for Elementor. Royal Addons for Elementor – Addons and Templates Kit for Elementor: 0 hasta 1.7.1058

Leer análisis →
Media

WordPress · Meta Field Block – Display custom fields in the Block Editor without coding

CVE-2026-6252: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Meta Field Block – Display custom fields in the Block Editor without coding

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Meta Field Block – Display custom fields in the Block Editor without coding. Meta Field Block – Display custom fields in the Block Editor without coding: 0 hasta 1.5.2

Leer análisis →
Media

WordPress · Taskbuilder – Project Management & Task Management Tool With Kanban Board

CVE-2026-6225: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Taskbuilder – Project Management & Task Management Tool With Kanban Board

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Taskbuilder – Project Management & Task Management Tool With Kanban Board. Taskbuilder – Project Management & Task Management Tool With Kanban Board: 0 hasta 5.0.6

Leer análisis →
Media

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-6145: CWE-862: Falta de autorización en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.5

Leer análisis →
Alta

WordPress · Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

CVE-2026-5396: CWE-639: Evasión de autorización mediante una clave controlada por el usuario en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder

El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder. Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder: 0 hasta 6.1.21

Leer análisis →