Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 35 min
Buscando: "Multiple Vendors" — 16643 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-94066] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SpabRice Pond pond allows Reflected XSS.This issue affects Pond: from n/a through 2.6.1.
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-94063] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeREX Education Center education allows Reflected XSS.This issue affects Education Center: from n/a through 3.6.12.
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-62026] Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allo…
Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allows Cross Site Request Forgery.This issue affects Dashboard Notes: from n/a through 1.0.3.
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-104629] A component loading mechanism in openPDC and openHistorian will construct and run any specified type…
A component loading mechanism in openPDC and openHistorian will construct and run any specified type, which may be an invalid component to load. An attacker with an authenticated user account and the ability to place a file on the host filesystem can use this to run arbitrary constructor code, and this code runs with the privileges of the affected service account.
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-105281] The internal data publisher on openPDC accepts network connections without authentication in its def…
The internal data publisher on openPDC accepts network connections without authentication in its default configuration. An unauthenticated network attacker can connect to this interface and retrieve the complete device and measurement topology of the system.
M Crítico vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-100730] A service console interface on openPDC and openHistorian deserializes a client-supplied data structu…
A service console interface on openPDC and openHistorian deserializes a client-supplied data structure. On systems using Windows Authentication, an attacker must already be authenticated to reach this function; on systems without Windows Authentication, this is reachable by an unauthenticated network attacker. This allows an attacker to trigger deserialization of an arbitrary object graph, which c…
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-94061] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designthemes Whistle - Sports Club whistle-sports-club allows Reflected XSS.This issue affects Whistle - Sports Club: from n/a through 4.2.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-94062] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio…
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes Werkstatt werkstatt allows PHP Local File Inclusion.This issue affects Werkstatt: from n/a through 4.8.3.
M Crítico vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-86405] Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment…
Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. PrestaShop Virtual POS Module allows Signature Spoofing by Improper Validation. This issue affects PrestaShop Virtual POS Module: from 26.8.1 before 26.9.1.
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-94058] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Treck treck allows Reflected XSS.This issue affects Treck: from n/a through 1.0.0.
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-94059] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Ogency ogency allows Reflected XSS.This issue affects Ogency: from n/a through 1.0.0.
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-94060] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bracketweb Voldor voldor allows Reflected XSS.This issue affects Voldor: from n/a through 1.0.0.
M Crítico vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-85531] Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment…
Improper verification of cryptographic signature vulnerability in Sipay Electronic Money and Payment Services Inc. OpenCart Virtual POS Module allows Signature Spoofing by Improper Validation. This issue affects OpenCart Virtual POS Module: from 26.8.2 before 26.9.1.
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-105883] Missing Authorization vulnerability in ThemeHunk Th Shop Mania th-shop-mania allows Exploiting Incor…
Missing Authorization vulnerability in ThemeHunk Th Shop Mania th-shop-mania allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Th Shop Mania: from n/a through 1.9.1.
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-104392] Deserialization of Untrusted Data vulnerability in ExpressTech Quiz And Survey Master quiz-master-ne…
Deserialization of Untrusted Data vulnerability in ExpressTech Quiz And Survey Master quiz-master-next allows Object Injection.This issue affects Quiz And Survey Master: from n/a through 11.2.7.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-105318] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Datasolution AcyMailing SMTP Newsletter acymailing allows Reflected XSS.This issue affects AcyMailing SMTP Newsletter: from n/a through 11.1.0.
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-105870] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Delight Star Inc. WP Associate Post R2 wp-associate-post-r2 allows Reflected XSS.This issue affects WP Associate Post R2: from n/a through 5.0.1.
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-105872] Deserialization of Untrusted Data vulnerability in mklacroix Product Configurator for WooCommerce pr…
Deserialization of Untrusted Data vulnerability in mklacroix Product Configurator for WooCommerce product-configurator-for-woocommerce allows Object Injection.This issue affects Product Configurator for WooCommerce: from n/a through 1.7.5.
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-103412] Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apac…
Improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Apache Camel Karavan. A project file name supplied through the project file API was used verbatim as a path segment when the project was written to the working copy for a Git commit, so a name containing `../` sequences caused the file content to be written outside the project directory, to any locat…
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-103413] Improper input validation vulnerability in Apache Camel Karavan. When a deployment was started, K…
Improper input validation vulnerability in Apache Camel Karavan. When a deployment was started, Karavan unmarshalled a project's `kubernetes.yaml` and applied every resource it contained to the cluster without restricting the resource kinds, without rejecting security-sensitive pod options, and without pinning the target namespace. An authenticated user of any role could therefore have Karavan …