Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 5 horas
13,735
Total alertas
3106
Críticas
10357
Altas
8
Ransomware
1055
Esta semana
RSS
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73042] SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing…
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73043] SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculat…
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the …
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73044] SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored …
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of style attributes and inject event handlers on every table cell, executing arbitrary code in the Electron renderer with Node integration enabled.
M Alto vulnerabilidad
15/08/2026
[CVE-2026-73045] SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerabil…
SiYuan before 3.7.4 contains an improper restriction of excessive authentication attempts vulnerability in the authFilePublishAccess endpoint that allows unauthenticated attackers to brute-force per-notebook publish passwords. Attackers can submit unbounded password guesses without rate limiting or CAPTCHA to gain access to password-protected published notebooks.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73046] SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middl…
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but never consults the CAPTCHA/lockout gate or increments the failure counter used by the cookie/session login path. This all…
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73050] SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select op…
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73041] SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the se…
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-18855] The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f…
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). E…
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19905] A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHS…
A weakness has been identified in Jinher OA 1.0. Impacted is an unknown function of the file /C6/JHSoft.Web.HrmAttendance/attendance_out_approve.aspx. This manipulation of the argument httpOID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but…
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19901] A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown functi…
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as difficult. The exploit has been released to the public and may be used for attacks. The …
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-19598] The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalatio…
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to, and including, 3.3.9. The vulnerability exists because the pods_admin AJAX router funnels every access check — including the method allowlist, nonce verification, login enforcement, and capability gate — through pods_error(), which under the JSON met…
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19900] A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown …
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit is publicly available and might be used. The vendor was c…
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19899] A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected…
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /edit_teacher.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
15/08/2026
[CVE-2026-18500] @fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verifi…
@fastify/jwt is a JSON Web Token plugin for Fastify. In versions before 10.2.2, a per-request verification key passed to request.jwtVerify({ key }) is silently overridden by the plugin's globally configured secret, because the option merge applies the global key last. Applications that use different keys for different authorization domains, for example separate user and admin keys, therefore accep…
M Alto vulnerabilidad
15/08/2026
[CVE-2026-18549] @fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not…
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the client then aborts the connection before sending the terminating boundary, the abort cleanup finds no stream to destroy, so…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/08/2026
[CVE-2026-19474] @fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not…
@fastify/multipart is a multipart form-data parser for Fastify. In versions from 3.0.0 up to but not including 10.1.1, request.saveRequestFiles() can leave completed temporary files on disk when a client disconnects while the parser is advancing between multipart parts. The iterator rejection that occurs between parts falls outside the per-file cleanup path, so an earlier completed file is never r…
C Informativo vulnerabilidad
15/08/2026
[CVE-2026-74446] In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: hold event_mutex wh…
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: hold event_mutex while checkpointing CRIU events kfd_criu_checkpoint_events() counts the entries in p->event_idr via kfd_get_num_events(), allocates an array sized to that count, and then walks the same IDR to fill it. Neither the count nor the walk holds p->event_mutex. The CRIU checkpoint caller holds only p->mute…
M Alto vulnerabilidad
15/08/2026
Ejecución remota de código en plugin Templately para WordPress (CVE-2026-18438)
El plugin Templately para WordPress (versiones hasta 3.7.1) es vulnerable a ejecución remota de código a través de la función fetch_remote_file, que valida incorrectamente el tipo de archivo permitiendo inyección de código malicioso. Sitios web en México y LATAM que usan este plugin de plantillas de Elementor/Gutenberg están expuestos a compromisos totales del servidor.
M Crítico vulnerabilidad
15/08/2026
Vulnerabilidad crítica de takeover de cuentas en plugin TrueBooker para WordPress (CVE-2026-16142)
El plugin TrueBooker para WordPress (versiones hasta 1.2.6) permite el robo de cuentas de usuario debido a que el manejador AJAX add_front_user_update() acepta parámetros arbitrarios sin validar autenticación ni propiedad, permitiendo a atacantes modificar cuentas administrativas. Esta vulnerabilidad afecta a miles de sitios WordPress en LATAM que utilizan este plugin para gestión de reservas. El riesgo es crítico (CVSS 9.8) ya que facilita comprometer la integridad completa del sitio.
M Alto vulnerabilidad
15/08/2026
Escalada de privilegios alta en Real Estate Manager Pro para WordPress (CVE-2026-15142)
El plugin Real Estate Manager Pro para WordPress es vulnerable a escalada de privilegios en versiones hasta la 12.8.6. Un defecto en la función allow_attachment_actions() permite que usuarios autenticados con acceso de Suscriptor eleven sus permisos al manipular IDs de archivos adjuntos. Esta vulnerabilidad afecta principalmente a inmobiliarias y plataformas de propiedades en LATAM que dependen de este plugin para gestionar contenido multimedia y control de acceso.