Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90566] A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5…
A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. Affected by this vulnerability is the function createUserAccount of the file register.php of the component Registration Handler. Executing a manipulation of the argument usertype can lead to improper authorization. It is possible to launch the attack remotely. The exploit has been…
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90523] A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eef…
A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/UsersController.java of the component User Register Endpoint. Such manipulation of the argument UsersEntity leads to improper privilege management. The attack can be launched remotely. …
M Alto vulnerabilidad
13/09/2026
[CVE-2026-90493] A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The …
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is an unknown function of the file idmwfp.sys of the component Kernel Driver. The manipulation results in improper access controls. Attacking locally is a requirement. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62102] Subscriber Privilege Escalation in Gato GraphQL <= 19.2.3 versions.
Subscriber Privilege Escalation in Gato GraphQL
M Alto vulnerabilidad
11/09/2026
[CVE-2026-62106] Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.9 versions.
Subscriber Privilege Escalation in SMS Alert Order Notifications
M Alto vulnerabilidad
11/09/2026
[CVE-2026-8303] Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Instit…
Incorrect privilege assignment vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-software allows Privilege Escalation. This issue affects Pardus-software: before 1.0.5.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81805] Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
Unauthenticated Privilege Escalation in SiteSkite

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86482] In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escal…
In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation
M Crítico vulnerabilidad
06/09/2026
[CVE-2026-86153] A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::Set…
A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation leads to improper privilege management. Remote exploitation of the attack is possible.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-84814] Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.
Subscriber Privilege Escalation in Bricksforge
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84756] Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
Subscriber Privilege Escalation in WCFM Membership
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-81294] Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
Unauthenticated Privilege Escalation in Authorizer
M Alto vulnerabilidad
02/09/2026
[CVE-2026-81769] Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation…
Incorrect Privilege Assignment vulnerability in LiquidThemes Booking Hub allows Privilege Escalation. This issue affects Booking Hub: from n/a through 1.3.1.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84115] A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown functio…
A vulnerability was found in Cleo Harmony up to 5.8.1.10. The affected element is an unknown function of the file /api/connections of the component JWT Refresh Token Handler. Performing a manipulation of the argument Bearer results in improper privilege management. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 5.8.1.11 i…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-81297] Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack <= 6.2.12 versions.
Subscriber Privilege Escalation in Fluent Forms Pro Add On Pack

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82815] A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file…
A flaw has been found in MegaEase EaseProbe up to 2.3.0. Affected is the function realIP of the file web/server.go of the component Middleware. This manipulation of the argument X-Forwarded-For/X-Real-IP/True-Client-IP causes improper access controls. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did n…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82807] A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown …
A vulnerability was determined in ieungSoft Ultra RAMDisk Pro 1.82. This issue affects some unknown processing in the library URDSCSI.sys of the component Kernel Driver. This manipulation causes improper privilege management. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82628] A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function …
A vulnerability was found in Colorful iGameCenter 2.0.0.81. This vulnerability affects the function sub_11504 in the library WinRing0x64.sys of the component IOCTL Dispatch. Performing a manipulation of the argument PhysicalAddress/AlignNumer/AlignSize results in improper privilege management. Attacking locally is a requirement.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78271] Editor Privilege Escalation in FluentCRM Pro <= 3.1.12 versions.
Editor Privilege Escalation in FluentCRM Pro
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-32566] Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.6…
Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress