Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-58003] WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the relea…
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session cookie to permanently publish any embargoed video by manipulating the videos_id parameter.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-14951] An low privileged remote attacker can cause authenticated users to perform unintended actions in the…
An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-18848] IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and …
IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the ASMI web interface. An attacker who can lure a logged-in ASMI administrator to visit a crafted web page can, under specific conditions, silently perform administrative actions on the FSP on behalf of that administrator, resulting in a c…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-66602] Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar all…
Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This issue affects HashBar – WordPress Notification Bar: from n/a through 2.0.0.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-66635] Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-19650] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72849] Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff …
Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an external chat identity to a victim's account. Attackers can craft a phishing page that auto-submits a POST request with a leaked confirmation token to bind their chat identity to a victim user's account, enabling impersonation within agent operations and inh…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72658] Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Reque…
Cross-Site Request Forgery (CWE-352) in Kibana can lead to privilege escalation via Cross Site Request Forgery (CAPEC-62). A user who is permitted to create visualizations can save a specially crafted Vega visualization that, when it is opened by another user, causes authenticated requests to be issued to Kibana in the context of the viewing user's session.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-17069] IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrict…
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of anti-CSRF tokens.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-13365] IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could al…
IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73482] phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/a…
phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is triggered via an unauthenticated GET request (?page=admins&delete=N) that is not protected by a CSRF token (the central verifyCsrfGetToken check uses enforce=false and is bypassed when the token parameter is absent). A remote attacker can trick a logge…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-48551] Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protect…
Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users via malicious links.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73292] Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/pas…
Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using the authenticated user's semaphore session cookie without CSRF protection or current-password confirmation, allowing an unauthenticated attacker to change an administrator's or another user's password after user interaction. This issue is fixed in ve…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-73222] Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the…
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The POST /api/execute endpoint passes the prompt request-body field to executeLocalTask(), and POST /api/i…
M Alto vulnerabilidad
10/08/2026
Vulnerabilidad CSRF alta en FreePBX Framework 17.0 permite acciones administrativas no autorizadas
Una vulnerabilidad de falsificación de solicitud entre sitios (CSRF) en FreePBX Framework 17.0 permite a atacantes remotos no autenticados realizar acciones administrativas suplantando a administradores legítimos. Esta falla afecta directamente a sistemas PBX en empresas, centros de contacto y proveedores de telecomunicaciones en LATAM que dependen de esta plataforma para gestionar comunicaciones altas.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
07/08/2026
[CVE-2026-16262] The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login fl…
The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not bind its OAuth social login flow to the initiating user session, allowing an unauthenticated attacker to log a victim into an attacker-controlled account (login CSRF), so that the victim's subsequent activity is stored under and readable by the attacker.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28172] Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager
M Alto vulnerabilidad
05/08/2026
[CVE-2026-70432] A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and…
A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-7326] A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.…
A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-60009] In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /f…
In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deployment. The handler takes an attacker-supplied absolute path from the multipart `uri` field and calls `fs.move(tmp, target, { overwrite: true })` with no workspace confinement and no authentication. In browser (non-Electron) deployments the connection toke…