Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Crítico vulnerabilidad
20/06/2026
[CVE-2022-50972] WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute ar…
WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-product-images.php endpoint with unsanitized product-type values to write malicious PHP files to the web root.
M Crítico vulnerabilidad
17/06/2026
[CVE-2026-36418] JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling…
JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator expression engine without adequate validation allowing attackers to execute arbitrary code.
F Crítico vulnerabilidad
17/06/2026
[CVE-2026-47103] Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that …
Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by supplying malicious SCXML documents containing crafted `` attributes evaluated unsafely. The SCXMLProcessor passes attacker-controlled expression strings through a call chain ending in Python's built-in eval() without sandboxing, enablin…
M Alto vulnerabilidad
17/06/2026
[CVE-2026-54816] Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads…
Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21.
M Alto vulnerabilidad
17/06/2026
[CVE-2026-49113] Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
M Crítico vulnerabilidad
17/06/2026
[CVE-2026-40783] Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.
Contributor Remote Code Execution (RCE) in Blocksy Companion Pro
M Crítico vulnerabilidad
17/06/2026
[CVE-2026-25470] Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom …
Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion. This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
O Crítico vulnerabilidad
17/06/2026
[CVE-2026-46850] Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The suppo…
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attack…
O Alto vulnerabilidad
17/06/2026
[CVE-2026-46851] Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (compone…
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in takeover of PeopleSoft E…
N Alto vulnerabilidad
16/06/2026
[CVE-2026-24155] NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploi…
NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-49774] Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station al…
Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-48017] DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reade…
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScript code template without any sanitization or validation. An authenticated user (with basic access, no special permissions required) can inject arbitrary JavaScript code that executes on the server with…
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-48836] Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.
Unauthenticated Remote Code Execution (RCE) in Easy Invoice
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-39465] Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.
Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50880] An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to e…
An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50871] An OS command injection vulnerability in the media archiving and export pipeline component of kanish…
An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50872] An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attacker…
An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a crafted HTTP request.
R Crítico vulnerabilidad
15/06/2026
[CVE-2026-30120] remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability…
remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-52704] Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce P…
Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.
K Alto vulnerabilidad
12/06/2026
[CVE-2026-54057] Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-con…
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization. Version 0.47.3 fixes the issue.