Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 4186 resultados ✕ Limpiar búsqueda
13,598
Total alertas
3086
Críticas
10240
Altas
8
Ransomware
1806
Esta semana
RSS
M Alto vulnerabilidad
17/08/2026
[CVE-2026-19962] A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setW…
A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /goform/setWAN. Executing a manipulation of the argument pppUserName/pptpUserName/L2TPUserName can lead to command injection. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respo…
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-19961] A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of…
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-19959] A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetu…
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclos…
M Alto vulnerabilidad
16/08/2026
[CVE-2026-19960] A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function form…
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such manipulation of the argument rootAPmac leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-74790] Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter change…
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.
M Alto vulnerabilidad
16/08/2026
[CVE-2026-74792] Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested …
Scriban before 7.0.0 (affected versions
M Alto vulnerabilidad
16/08/2026
[CVE-2026-74794] Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the Objec…
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and triggering an uncatchable StackOverflowException that terminates the hosting process.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/08/2026
[CVE-2026-74783] Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails t…
Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an uncatchable StackOverflowException that immediately terminates the host process.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-73056] SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication atte…
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an …
M Alto vulnerabilidad
16/08/2026
[CVE-2026-73057] stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing att…
stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhaustion. Attackers can host malicious SVGs with extremely large width and height values and trigger concurrent requests to exhaust available memory across proxy replicas.
M Alto vulnerabilidad
16/08/2026
[CVE-2026-73060] Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRan…
Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on lazy sequences to execute billions of uncharged iterations, pinning CPU cores and exhausting garbage collection resources even when LoopLimit is set to 1…
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-73061] Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that al…
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.
M Alto vulnerabilidad
16/08/2026
[CVE-2026-73062] Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multipli…
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force multi-gigabyte memory allocations, causing resource exhaustion and availability degradation.
M Alto vulnerabilidad
16/08/2026
Inyección SQL alta en plugin The Gallery by BestWebSoft para WordPress (versiones ≤4.7.9)
El plugin The Gallery by BestWebSoft para WordPress contiene una vulnerabilidad de inyección SQL (CVE-2026-2497, CVSS 7.2) en el parámetro '_gallery_order_{post_id}' que afecta todas las versiones hasta la 4.7.9. La falta de escape y sanitización de datos POST permite a atacantes ejecutar consultas SQL maliciosas. Esta vulnerabilidad expone datos sensibles en sitios web empresariales y e-commerce en México y Latinoamérica que utilizan este plugin.
M Alto vulnerabilidad
16/08/2026
Vulnerabilidad XSS almacenado alta en plugin Infility Global para WordPress (CVE-2026-10734)
El plugin Infility Global para WordPress es vulnerable a Cross-Site Scripting (XSS) almacenado en el endpoint /cf7_record_log en versiones hasta 2.15.21. Atacantes no autenticados pueden inyectar scripts maliciosos que se ejecutan cuando usuarios acceden a páginas comprometidas, comprometiendo datos de formularios de contacto y sesiones de clientes. Afecta a sitios en WordPress que utilizan este complemento para gestionar registros de formularios Contact Form 7.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/08/2026
Vulnerabilidad XSS almacenado en plugin Bookly para WordPress afecta tiendas en línea
El plugin de reservas Bookly para WordPress (versiones hasta 27.7) permite a atacantes no autenticados inyectar scripts maliciosos mediante la acción AJAX bookly_speed_up_update_addons, aprovechando sanitización insuficiente. Afecta directamente a pequeñas y medianas empresas en LATAM que dependen de WordPress para gestión de citas y reservas. La ejecución del código malicioso ocurre en páginas visitadas por clientes y administradores.
M Alto vulnerabilidad
16/08/2026
Inyección de código en plugin WCPOS para WooCommerce afecta tiendas en línea
El plugin WCPOS (Point of Sale) para WooCommerce en WordPress contiene una vulnerabilidad alta de inyección de código en el motor de plantillas 'thermal' hasta la versión 1.9.14. Atacantes autenticados pueden ejecutar código PHP arbitrario a través del renderizador de recibos, comprometiendo datos de ventas y clientes en tiendas electrónicas de México y Latinoamérica que utilizan este sistema POS.
M Crítico vulnerabilidad
16/08/2026
Plugin Solace Extra para WordPress vulnerable a modificación no autorizada de datos (CVE-2026-18316)
El plugin Solace Extra en versiones hasta 1.6.0 permite a atacantes no autenticados modificar o eliminar datos a través de la función import_zip() que carece de validación de permisos. La vulnerabilidad afecta sitios WordPress en México y LATAM que usan este plugin, exponiendo contenido, configuraciones y bases de datos. La verificación de nonce insuficiente permite bypass de controles de seguridad estándar de WordPress.
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica de escalada de privilegios en plugin Frontend Admin para WordPress (CVE-2026-18432)
El plugin Frontend Admin by DynamiApps para WordPress contiene una falla de escalada de privilegios en versiones hasta 3.29.9 que permite a usuarios no autenticados obtener permisos de administrador. La vulnerabilidad reside en la función ActionUser::conditions_logic() que omite validaciones de autorización cuando recibe parámetros no numéricos, afectando directamente a sitios WordPress en México y LATAM que usan este plugin. Con puntuación CVSS 9.8, representa riesgo crítico para tiendas de comercio electrónico, portales corporativos y sistemas de contenido.
M Alto vulnerabilidad
16/08/2026
Ejecución remota de código en plugin Query Wrangler para WordPress (CVE-2026-14498)
El plugin Query Wrangler para WordPress en versiones hasta 1.5.57 permite ejecución remota de código (RCE) a través del parámetro 'options' en el manejador wp_ajax_qw_form_ajax. La vulnerabilidad existe por falta de verificación de capacidades, ausencia de validación de nonce y sanitización deficiente que permite a atacantes reemplazar opciones de consulta y ejecutar funciones arbitrarias. Afecta alta­mente a sitios WordPress en LATAM que utilizan este plugin sin actualizar, poniendo en riesgo datos empresariales y continuidad operativa.