Habla con un experto

DIRECTORIO CVE · 2026

Vulnerabilidades conocidas

Página 75 de 95. Los registros están ordenados por fecha oficial de publicación, del más reciente al más antiguo.

Registros 7401–7500 de 9.413

Alta

NGINX · NGINX Open Source / NGINX Plus

CVE-2026-27654: CWE-122: Desbordamiento de búfer en memoria dinámica (Heap-based Buffer Overflow) en NGINX Open Source / NGINX Plus

El registro oficial identifica la vulnerabilidad «CWE-122: Desbordamiento de búfer en memoria dinámica (Heap-based Buffer Overflow)» en NGINX Open Source / NGINX Plus. NGINX Open Source: 1.29.0 hasta 1.29.7, 0.5.13 hasta 1.28.3; NGINX Plus: R36 hasta R36 P3, R35 hasta R35 P2, R34 hasta *, R33 hasta *, R32 hasta R32 P5

Leer análisis →
Alta

WordPress · WP Job Portal – AI-Powered Recruitment System for Company or Job Board website

CVE-2026-4306: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en WP Job Portal – AI-Powered Recruitment System for Company or Job Board website

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP Job Portal – AI-Powered Recruitment System for Company or Job Board website. WP Job Portal – AI-Powered Recruitment System for Company or Job Board website: 0 hasta 2.4.8

Leer análisis →
Media

WordPress · User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

CVE-2026-4056: CWE-862: Falta de autorización en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder. User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder: 0 hasta 5.1.4

Leer análisis →
Alta

WordPress · Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

CVE-2026-4021: CWE-287: Autenticación incorrecta en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe

El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe. Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe: 0 hasta 28.1.5

Leer análisis →
Media

WordPress · Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

CVE-2026-2412: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker. Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker: 0 hasta 10.3.5

Leer análisis →
Media

WordPress · Yoast SEO – Advanced SEO with real-time guidance and built-in AI

CVE-2026-3427: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Yoast SEO – Advanced SEO with real-time guidance and built-in AI

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Yoast SEO – Advanced SEO with real-time guidance and built-in AI. Yoast SEO – Advanced SEO with real-time guidance and built-in AI: 0 hasta 27.1.1

Leer análisis →
Alta

WordPress · WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters

CVE-2026-2580: CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection) en WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters

El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters. WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters: 0 hasta 4.9.1

Leer análisis →
Alta

WordPress · WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation

CVE-2026-4302: CWE-918: vulnerabilidad de seguridad en WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation

El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation. WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation: 0 hasta 1.4.29

Leer análisis →
Media

WordPress · Show Posts list – Easy designs, filters and more

CVE-2026-4022: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Show Posts list – Easy designs, filters and more

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Show Posts list – Easy designs, filters and more. Show Posts list – Easy designs, filters and more: 0 hasta 1.1.0

Leer análisis →
Media

WordPress · Go Night Pro | WordPress Dark Mode Plugin

CVE-2026-1886: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Go Night Pro | WordPress Dark Mode Plugin

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Go Night Pro | WordPress Dark Mode Plugin. Go Night Pro | WordPress Dark Mode Plugin: 0 hasta 1.1.0

Leer análisis →
Media

WordPress · Tour & Activity Operator Plugin for TourCMS

CVE-2026-1806: CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting) en Tour & Activity Operator Plugin for TourCMS

El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Tour & Activity Operator Plugin for TourCMS. Tour & Activity Operator Plugin for TourCMS: 0 hasta 1.7.0

Leer análisis →