Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,971
Total alertas
3188
Críticas
10511
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12784] A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown fu…
A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not r…
L Alto vulnerabilidad
21/06/2026
[CVE-2026-52911] In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slow…
In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound sessions only When the binding SESSION_SETUP sets conn->binding = true, the flag stays set after the call so that the global session lookup in ksmbd_session_lookup_all() can find the session, which was not added to conn->sessions. Because the flag is connection-wide, the global lookup…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12781] A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unk…
A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly available and might be used. You should upgrade the affected component. The vendor explains: "We have confir…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12778] A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affect…
A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12779] A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unkno…
A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did …
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12780] A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in th…
A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any …
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12775] A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909…
A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
L Alto vulnerabilidad
21/06/2026
[CVE-2026-12773] A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyA…
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The ven…
V Alto vulnerabilidad
20/06/2026
[CVE-2026-56340] vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings p…
vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with malformed (negative or out-of-bounds) tensor indices, when the prompt-embeds feature is enabled, to trigger crashes or resource exhaustion (denial of service), with p…
M Alto vulnerabilidad
20/06/2026
[CVE-2026-56341] AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plu…
AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction data including agreement IDs, user financial records, and API responses via direct GET requests to vulnerable endpoints.
M Alto vulnerabilidad
20/06/2026
[CVE-2026-56345] AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecord…
AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verification. An attacker with knowledge of the Meet shared secret can craft a malicious file upload with a filename containing an arbitrary users_id to invoke passwordless User->login() and establish an au…
M Alto vulnerabilidad
20/06/2026
[CVE-2020-37255] WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows un…
WordPress Time Capsule Plugin 1.21.16 contains an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by sending a crafted POST request with the IWP_JSON_PREFIX header. Attackers can exploit this flaw to obtain valid administrator session cookies and access the WordPress dashboard without providing credentials.
M Alto vulnerabilidad
20/06/2026
[CVE-2026-11912] The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insuff…
The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization checks in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete and modify files on the serve. This vulnerability is exploitable even when the administrator has not enabled the AllowFrontManage setting, because the is_admin() ch…
M Alto vulnerabilidad
20/06/2026
[CVE-2026-11911] The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficie…
The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the eeSFL_DeleteFile function in all versions up to, and including, 6.3.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). T…
M Alto vulnerabilidad
20/06/2026
[CVE-2026-9843] The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbi…
The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the view_page function in all versions up to, and including, 1.5.1. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is dele…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
20/06/2026
[CVE-2026-56214] Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC end…
Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org and is_paying_org that allows unauthenticated attackers to enumerate organizations and disclose billing status using the public sb_publishable key. Attackers can invoke these endpoints to determine organization existence via distinguishable return values and identify paying custo…
M Alto vulnerabilidad
20/06/2026
[CVE-2026-56215] Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbi…
Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning endpoint trusts as an account-merge key. Attackers can pre-position their account with a victim's corporate SSO email, causing the provision-user endpoint to merge the victim's SSO identity into the attacker-controlled account.
M Alto vulnerabilidad
20/06/2026
[CVE-2026-56216] Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey end…
Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows app-limited API keys to mint unrestricted keys by setting empty limits. Attackers with a compromised app-limited key can create an unrestricted key with org-wide access to resources like app listings and other protected endpoints.
M Alto vulnerabilidad
19/06/2026
[CVE-2026-56082] Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURI…
Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and callable with only the public Supabase publishable (sb_publishable_*) anon key. An unauthenticated attacker can insert rows into public.build_logs for arbitrary organizations and, because the function u…
Q Alto vulnerabilidad
19/06/2026
[CVE-2026-50559] Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3…
Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies can be bypassed using encoded semicolons (%3B) to smuggle matrix parameters past the security layer, and using encoded slashes (%2F) or backslashes (%5C) to access protected static resources. This is a…