WordPress · AI Engine
CVE-2026-27407: CWE-266: Asignación incorrecta de privilegios en AI Engine
El registro oficial identifica la vulnerabilidad «CWE-266: Asignación incorrecta de privilegios» en AI Engine. AI Engine: n/a hasta 3.4.9
DIRECTORIO CVE · 2026
Página 107 de 163. Los registros están ordenados por fecha oficial de publicación, del más reciente al más antiguo.
Registros 10601–10700 de 16.277
WordPress · AI Engine
El registro oficial identifica la vulnerabilidad «CWE-266: Asignación incorrecta de privilegios» en AI Engine. AI Engine: n/a hasta 3.4.9
WordPress · Paid Videochat Turnkey Site
El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en Paid Videochat Turnkey Site. Paid Videochat Turnkey Site: n/a hasta 7.3.23
WordPress · WpTravelly
El registro oficial identifica la vulnerabilidad «CWE-290: vulnerabilidad de seguridad» en WpTravelly. WpTravelly: n/a hasta 2.1.7
WordPress · Broadcast Live Video
El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en Broadcast Live Video. Broadcast Live Video: n/a hasta 7.1.3
WordPress · Essential Addons for Elementor
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en Essential Addons for Elementor. Essential Addons for Elementor: n/a hasta 6.6.0
WordPress · User Registration
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en User Registration. User Registration: n/a hasta 5.1.2
WordPress · PowerPress Podcasting
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en PowerPress Podcasting. PowerPress Podcasting: n/a hasta 11.15.10
WordPress · Redirection for Contact Form 7
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Redirection for Contact Form 7. Redirection for Contact Form 7: n/a hasta 3.2.8
cPanel/WHM · cPanel Plugin
El registro oficial identifica la vulnerabilidad «CWE-61: vulnerabilidad de seguridad» en cPanel Plugin. cPanel Plugin: 2.3 hasta 2.4.8
WordPress · Customer Support Ticket System & Helpdesk
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Customer Support Ticket System & Helpdesk. Customer Support Ticket System & Helpdesk: 0 hasta 6.0.4
WordPress · Canvas
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Canvas. Canvas: 0 hasta 2.5.2
WordPress · Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel. Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel: 0 hasta 3.1.31
WordPress · GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites. GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites: 0 hasta 2.31
WordPress · Store Locator WordPress
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en Store Locator WordPress. Store Locator WordPress: 0 hasta 1.6.9
WordPress · Store Locator WordPress
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Store Locator WordPress. Store Locator WordPress: 0 hasta 1.6.9
WordPress · Online Scheduling and Appointment Booking System – Bookly
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Online Scheduling and Appointment Booking System – Bookly. Online Scheduling and Appointment Booking System – Bookly: 0 hasta 27.2
WordPress · Page Builder: Pagelayer – Drag and Drop website builder
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Page Builder: Pagelayer – Drag and Drop website builder. Page Builder: Pagelayer – Drag and Drop website builder: 0 hasta 2.0.9
WordPress · Page Builder: Pagelayer – Drag and Drop website builder
El registro oficial identifica la vulnerabilidad «CWE-863: vulnerabilidad de seguridad» en Page Builder: Pagelayer – Drag and Drop website builder. Page Builder: Pagelayer – Drag and Drop website builder: 0 hasta 2.0.9
WordPress · Meow Gallery
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en Meow Gallery. Meow Gallery: 0 hasta 5.4.4
WordPress · LWS Optimize – All-in-One Speed Booster & Cache Tools
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en LWS Optimize – All-in-One Speed Booster & Cache Tools. LWS Optimize – All-in-One Speed Booster & Cache Tools: 0 hasta 3.3.19
WordPress · Secure Copy Content Protection and Content Locking
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Secure Copy Content Protection and Content Locking. Secure Copy Content Protection and Content Locking: 0 hasta 5.1.5
WordPress · Presto Player
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Presto Player. Presto Player: 0 hasta 4.2.0
WordPress · WordPress-Toolkit
El registro oficial identifica la vulnerabilidad «CWE-88: vulnerabilidad de seguridad» en WordPress-Toolkit. WordPress-Toolkit: 0 hasta 6.11.0
Microsoft Office · questbot
El registro oficial identifica la vulnerabilidad «CWE-20: vulnerabilidad de seguridad» en questbot. questbot: < 1.1.6
WordPress · Hash Elements
El registro oficial identifica la vulnerabilidad «CWE-497: vulnerabilidad de seguridad» en Hash Elements. Hash Elements: n/a hasta 1.5.4
WordPress · Hippoo Mobile App for WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-266: Asignación incorrecta de privilegios» en Hippoo Mobile App for WooCommerce. Hippoo Mobile App for WooCommerce: n/a hasta 1.9.4
WordPress · fediverse-embeds-wordpress-plugin
El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en fediverse-embeds-wordpress-plugin. fediverse-embeds-wordpress-plugin: < 1.5.9
WordPress · fediverse-embeds-wordpress-plugin
El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en fediverse-embeds-wordpress-plugin. fediverse-embeds-wordpress-plugin: < 1.5.8
WordPress · SliceWP
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en SliceWP. SliceWP: n/a hasta 1.2.6
WordPress · JoomSport
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en JoomSport. JoomSport: n/a hasta 5.7.7
WordPress · Product Filter by WBW
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Product Filter by WBW. Product Filter by WBW: n/a hasta 3.1.2
WordPress · Open User Map PRO
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Open User Map PRO. Open User Map PRO: 0 hasta 1.4.31
WordPress · UpdraftPlus: WP Backup & Migration Plugin
El registro oficial identifica la vulnerabilidad «CWE-347: vulnerabilidad de seguridad» en UpdraftPlus: WP Backup & Migration Plugin. UpdraftPlus: WP Backup & Migration Plugin: 0 hasta 1.26.4
WordPress · Schema & Structured Data for WP & AMP
El registro oficial identifica la vulnerabilidad «CWE-434: vulnerabilidad de seguridad» en Schema & Structured Data for WP & AMP. Schema & Structured Data for WP & AMP: 0 hasta 1.60
WordPress · Store Locator WordPress
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Store Locator WordPress. Store Locator WordPress: 0 hasta 1.6.6
WordPress · Easy Image Collage
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Easy Image Collage. Easy Image Collage: 0 hasta 1.13.6
WordPress · MW WP Form
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en MW WP Form. MW WP Form: 0 hasta 5.1.3
WordPress · aThemes Addons for Elementor
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en aThemes Addons for Elementor. aThemes Addons for Elementor: 0 hasta 1.1.8
WordPress · Anti-Spam by CleanTalk. Spam protection
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Anti-Spam by CleanTalk. Spam protection. Anti-Spam by CleanTalk. Spam protection: 0 hasta 6.79
WordPress · WPZOOM Portfolio
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WPZOOM Portfolio. WPZOOM Portfolio: n/a hasta 1.4.21
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-22: Limitación incorrecta de una ruta a un directorio restringido (Path Traversal)» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-287: Autenticación incorrecta» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-601: vulnerabilidad de seguridad» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-20: vulnerabilidad de seguridad» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-78: vulnerabilidad de seguridad» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-918: vulnerabilidad de seguridad» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-90: vulnerabilidad de seguridad» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-20: vulnerabilidad de seguridad» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-20: vulnerabilidad de seguridad» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en roxy-wi. roxy-wi: <= 8.2.6.4
NGINX · roxy-wi
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en roxy-wi. roxy-wi: <= 8.2.6.4
WordPress · Xstore
El registro oficial identifica la vulnerabilidad «CWE-89: SQL Injection» en Xstore. Xstore: 0 hasta 9.7.3
WordPress · Newsletters
El registro oficial identifica la vulnerabilidad «CWE-89: Neutralización incorrecta de elementos especiales en una consulta (SQL Injection)» en Newsletters. Newsletters: 0 hasta 4.13
WordPress · Recover Exit For WooCommerce
El registro oficial identifica la vulnerabilidad «CWE-98: vulnerabilidad de seguridad» en Recover Exit For WooCommerce. Recover Exit For WooCommerce: 0 hasta 1.0.3
WordPress · 6Storage Rentals
El registro oficial identifica la vulnerabilidad «CWE-639: Evasión de autorización mediante una clave controlada por el usuario» en 6Storage Rentals. 6Storage Rentals: 0 hasta 2.22.0
WordPress · Custom Block Builder
El registro oficial identifica la vulnerabilidad «CWE-79: Cross-Site Scripting (XSS)» en Custom Block Builder. Custom Block Builder: 0 hasta 4.3.0
WordPress · WP GDPR Cookie Consent
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP GDPR Cookie Consent. WP GDPR Cookie Consent: 0 hasta 1.0.0
WordPress · WP Meta Sort Posts
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en WP Meta Sort Posts. WP Meta Sort Posts: 0 hasta 0.9
WordPress · WP Emoticon Rating
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en WP Emoticon Rating. WP Emoticon Rating: 0 hasta 1.0.1
WordPress · WpMobi
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en WpMobi. WpMobi: 0 hasta 0.0.3
WordPress · WP-Ultimate-Map
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en WP-Ultimate-Map. WP-Ultimate-Map: 0 hasta 1.1
WordPress · FastPicker, an order picker and order management system (oms) for WooCommerce on steroids
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en FastPicker, an order picker and order management system (oms) for WooCommerce on steroids. FastPicker, an order picker and order management system (oms) for WooCommerce on steroids: 0 hasta 1.0.2
WordPress · AJAX Report Comments
El registro oficial identifica la vulnerabilidad «CWE-352: vulnerabilidad de seguridad» en AJAX Report Comments. AJAX Report Comments: 0 hasta 2.0.4
WordPress · kk blog card
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en kk blog card. kk blog card: 0 hasta 1.3
WordPress · Global Body Mass Index Calculator
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Global Body Mass Index Calculator. Global Body Mass Index Calculator: 0 hasta 1.2
WordPress · WP ApplicantStack Jobs Display
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en WP ApplicantStack Jobs Display. WP ApplicantStack Jobs Display: 0 hasta 1.1.1
WordPress · RomanCart Ecommerce
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en RomanCart Ecommerce. RomanCart Ecommerce: 0 hasta 2.0.8
WordPress · Extra Settings for RocketChat
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Extra Settings for RocketChat. Extra Settings for RocketChat: 0 hasta 0.1
WordPress · Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages. Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages: 0 hasta 1.3.3
WordPress · MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails. MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails: 0 hasta 2.0.4
WordPress · Helpfulcrowd Product Reviews
El registro oficial identifica la vulnerabilidad «CWE-843: vulnerabilidad de seguridad» en Helpfulcrowd Product Reviews. Helpfulcrowd Product Reviews: 0 hasta 1.2.9
WordPress · Blocksy
El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en Blocksy. Blocksy: 0 hasta 2.1.41
WordPress · Plugin Name: ePaperFlip Publisher
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Plugin Name: ePaperFlip Publisher. Plugin Name: ePaperFlip Publisher: 0 hasta 1
WordPress · FV Flowplayer Video Player
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en FV Flowplayer Video Player. FV Flowplayer Video Player: 0 hasta 7.5.49.7212
WordPress · Slider Revolution
El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Slider Revolution. Slider Revolution: 7.0 hasta 7.0.10
WordPress · Enable Media Replace
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Enable Media Replace. Enable Media Replace: 0 hasta 4.1.8
Linux · Linux
El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: 1f2353f5a1af995efbf7bea44341aa0d03460b28 hasta 73e119036b3a799170ed89907b4273c07306d611, 1f2353f5a1af995efbf7bea44341aa0d03460b28 hasta e4056b84af0fc18c84b4e5741df04ecd8ca17973; Linux: 6.19, 0 hasta 6.19, 7.0.4 hasta 7.0.*, 7.1 hasta *
Linux · Linux
El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: 1f3e4142c0eb178089ea0cbc97506a061470ad27 hasta b8f037e87a083291190204b959cda417aaf01058, 1f3e4142c0eb178089ea0cbc97506a061470ad27 hasta da2346a48a5a1fed86c3fe3d73c0b60e7b3027c9; Linux: 6.19, 0 hasta 6.19, 7.0.4 hasta 7.0.*, 7.1 hasta *
Linux · Linux
El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: d8f867fa0825fb3e358457566d7326d8aab2406a hasta 1de2db19a6028abe7d905875922faef5b873de67, d8f867fa0825fb3e358457566d7326d8aab2406a hasta 89b6226b6c2a4add3939f361653a47c212d6ab75, d8f867fa0825fb3e358457566d7326d8aab2406a hasta 95093e5cb4c5b50a5b1a4b79f2942b62744bd66a; Linux: 6.18, 0 hasta 6.18, 6.18.30 hasta 6.18.*, 7.0.4 hasta 7.0.*, 7.1 hasta *
Linux · Linux
El registro oficial identifica la vulnerabilidad «vulnerabilidad de seguridad» en Linux. Linux: c0bfe34330b5fafdbbc63a7124841711651b96b9 hasta 5edd564ccb002ffc830e7818c1c4a992db774678, c0bfe34330b5fafdbbc63a7124841711651b96b9 hasta 4404d7d2dda4f3cc84a8fb6ac5417a2afc3b22d6, c0bfe34330b5fafdbbc63a7124841711651b96b9 hasta 843c0247cf21364e33bb5a8ffc9af57107d04d05, c0bfe34330b5fafdbbc63a7124841711651b96b9 hasta 6597ff1d8de3f583be169587efeafd8af134e138; Linux: 6.12, 0 hasta 6.12, 6.12.86 hasta 6.12.*, 6.18.27 hasta 6.18.*, 7.0.4 hasta 7.0.*, 7.1 hasta *
Windows Server · Windows 10 Version 1607 / Windows 11 version 22H2 / Windows Server 2012
El registro oficial identifica la vulnerabilidad «CWE-200: Exposición de información sensible a un actor no autorizado» en Windows 10 Version 1607 / Windows 11 version 22H2 / Windows Server 2012. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9234; Windows 11 version 22H2: 10.0.22621.0 hasta 10.0.22631.7219; Windows Server 2012: 6.2.9200.0 hasta 6.2.9200.26132; Windows Server 2012 (Server Core installation): 6.2.9200.0 hasta 6.2.9200.26132; Windows Server 2012 R2: 6.3.9600.0 hasta 6.3.9600.23228; Windows Server 2012 R2 (Server Core installation): 6.3.9600.0 hasta 6.3.9600.23228; Windows Server 2016: 10.0.14393.0 hasta 10.0.14393.9234; Windows Server 2016 (Server Core installation): 10.0.14393.0 hasta 10.0.14393.9234
Windows Server · Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2
El registro oficial identifica la vulnerabilidad «CWE-306: vulnerabilidad de seguridad» en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9234; Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8880; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7417; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7417; Windows 11 version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655
Fortinet · FortiPortal
El registro oficial identifica la vulnerabilidad «Vulnerabilidad de seguridad» en FortiPortal. FortiPortal: 7.4.0 hasta 7.4.7, 7.2.0 hasta 7.2.8, 7.0.0 hasta 7.0.14
WordPress · WPForms
El registro oficial identifica la vulnerabilidad «CWE-862: Falta de autorización» en WPForms. WPForms: 1.10.0.1 hasta 1.10.0.5
Windows Server · Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2
El registro oficial identifica la vulnerabilidad «CWE-400: vulnerabilidad de seguridad» en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9234; Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8880; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7417; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7417; Windows 11 version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655
Windows Server · Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2
El registro oficial identifica la vulnerabilidad «CWE-416: Uso de memoria después de liberarla (Use After Free)» en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9234; Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8880; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7417; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7417; Windows 11 version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655
Windows Server · Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2
El registro oficial identifica la vulnerabilidad «CWE-284: vulnerabilidad de seguridad» en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9234; Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8880; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7417; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7417; Windows 11 version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655
Windows Server · Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2
El registro oficial identifica la vulnerabilidad «CWE-1329: vulnerabilidad de seguridad» en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9234; Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8880; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7417; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7417; Windows 11 version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655
Windows Server · Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2
El registro oficial identifica la vulnerabilidad «CWE-693: vulnerabilidad de seguridad» en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9234; Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8880; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7417; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7417; Windows 11 version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655
Windows Server · Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2
El registro oficial identifica la vulnerabilidad «CWE-122: Desbordamiento de búfer en memoria dinámica (Heap-based Buffer Overflow)» en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9234; Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8880; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7417; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7417; Windows 11 version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655
Windows Server · Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2
El registro oficial identifica la vulnerabilidad «CWE-1329: vulnerabilidad de seguridad» en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9234; Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8880; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7417; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7417; Windows 11 version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655
Windows Server · Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2
El registro oficial identifica la vulnerabilidad «CWE-693: vulnerabilidad de seguridad» en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9234; Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8880; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7417; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7417; Windows 11 version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655
Windows Server · Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2
El registro oficial identifica la vulnerabilidad «CWE-693: vulnerabilidad de seguridad» en Windows 10 Version 1607 / Windows 10 Version 1809 / Windows 10 Version 21H2. Windows 10 Version 1607: 10.0.14393.0 hasta 10.0.14393.9234; Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8880; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7417; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7417; Windows 11 version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655
Windows Server · Windows 11 Version 24H2 / Windows 11 Version 25H2 / Windows 11 version 26H1
El registro oficial identifica la vulnerabilidad «CWE-125: Lectura fuera de límites (Out-of-bounds Read)» en Windows 11 Version 24H2 / Windows 11 Version 25H2 / Windows 11 version 26H1. Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8457; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8457; Windows 11 version 26H1: 10.0.28000.0 hasta 10.0.28000.2113; Windows Server 2025: 10.0.26100.0 hasta 10.0.26100.32860; Windows Server 2025 (Server Core installation): 10.0.26100.0 hasta 10.0.26100.32860
Windows Server · Windows 10 Version 1809 / Windows 10 Version 21H2 / Windows 10 Version 22H2
El registro oficial identifica la vulnerabilidad «CWE-416: Uso de memoria después de liberarla (Use After Free)» en Windows 10 Version 1809 / Windows 10 Version 21H2 / Windows 10 Version 22H2. Windows 10 Version 1809: 10.0.17763.0 hasta 10.0.17763.8880; Windows 10 Version 21H2: 10.0.19044.0 hasta 10.0.19044.7417; Windows 10 Version 22H2: 10.0.19045.0 hasta 10.0.19045.7417; Windows 11 version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 23H2: 10.0.22631.0 hasta 10.0.22631.7219; Windows 11 Version 24H2: 10.0.26100.0 hasta 10.0.26100.8655; Windows 11 Version 25H2: 10.0.26200.0 hasta 10.0.26200.8655; Windows 11 version 26H1: 10.0.28000.0 hasta 10.0.28000.2269
Microsoft Office · Microsoft SharePoint Enterprise Server 2016 / Microsoft SharePoint Server 2019 / Microsoft SharePoint Server Subscription Edition
El registro oficial identifica la vulnerabilidad «CWE-79: Neutralización incorrecta de entrada durante la generación de páginas web (Cross-Site Scripting)» en Microsoft SharePoint Enterprise Server 2016 / Microsoft SharePoint Server 2019 / Microsoft SharePoint Server Subscription Edition. Microsoft SharePoint Enterprise Server 2016: 16.0.0 hasta 16.0.5556.1005; Microsoft SharePoint Server 2019: 16.0.0 hasta 16.0.10417.20153; Microsoft SharePoint Server Subscription Edition: 16.0.0 hasta 16.0.19725.20384
Microsoft Office · Microsoft SharePoint Enterprise Server 2016 / Microsoft SharePoint Server 2019 / Microsoft SharePoint Server Subscription Edition
El registro oficial identifica la vulnerabilidad «CWE-502: Deserialización de datos no confiables» en Microsoft SharePoint Enterprise Server 2016 / Microsoft SharePoint Server 2019 / Microsoft SharePoint Server Subscription Edition. Microsoft SharePoint Enterprise Server 2016: 16.0.0 hasta 16.0.5556.1005; Microsoft SharePoint Server 2019: 16.0.0 hasta 16.0.10417.20153; Microsoft SharePoint Server Subscription Edition: 16.0.0 hasta 16.0.19725.20384