Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 8 horas
13,736
Total alertas
3106
Críticas
10358
Altas
8
Ransomware
1029
Esta semana
RSS
F Crítico vulnerabilidad
13/07/2026
[CVE-2026-40468] Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may le…
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57811] Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic…
Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57813] Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege …
Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-59515] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-59518] Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injec…
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57770] Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography all…
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57738] Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Inject…
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57739] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57744] Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions a…
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57724] Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This …
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57726] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57710] Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbo…
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57714] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57719] Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-…
Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57702] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57707] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro allows SQL Injection.This issue affects Simple Business Directory Pro: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57401] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brai…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects SureDash: from n/a through
A Crítico vulnerabilidad
13/07/2026
[CVE-2026-41041] URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This …
URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before 1.2.1. Users are recommended to upgrade to version 1.2.1, which fixes the issue.
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-14453] This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-t…
This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution. The message_confirm field is stored without sanitization and rendered via Smarty with no security policy enabled, allowing any authenticated user, to inject and execute arbitrary code on the server. This results in disclosure of environment secrets …
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-4769] Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability durin…
Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionality is not formally documented and becomes accessible without authentication for a brief period in the early boot phase. During this window, an unauthenticated remote attacker can gain access to the internal system processes, resulting in full system co…