Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 30 min
Buscando: "Multiple Vendors" — 16902 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1253
Esta semana
RSS
M Crítico vulnerabilidad
26/06/2026
[CVE-2026-54825] Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
Unauthenticated SQL Injection in wpDataTables
M Alto vulnerabilidad
26/06/2026
[CVE-2026-54826] Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.
Subscriber Insecure Direct Object References (IDOR) in SupportCandy
M Crítico vulnerabilidad
26/06/2026
[CVE-2026-54827] Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
Unauthenticated SQL Injection in Real Estate 7
M Crítico vulnerabilidad
26/06/2026
[CVE-2026-54831] Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
Unauthenticated SQL Injection in GeoDirectory
M Alto vulnerabilidad
26/06/2026
[CVE-2026-54832] Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
Unauthenticated Broken Access Control in Gutenverse Companion
M Alto vulnerabilidad
26/06/2026
[CVE-2026-54833] Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.
Unauthenticated Backdoor in Enable CORS
M Alto vulnerabilidad
26/06/2026
[CVE-2026-54834] Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
26/06/2026
[CVE-2026-54820] Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
Unauthenticated SQL Injection in JetBooking
M Alto vulnerabilidad
26/06/2026
[CVE-2026-30041] An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to ex…
An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.
M Alto vulnerabilidad
26/06/2026
[CVE-2025-68052] Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking
M Alto vulnerabilidad
26/06/2026
[CVE-2025-68063] Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Ho…
Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey
M Alto vulnerabilidad
26/06/2026
[CVE-2025-68064] Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57915] It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA …
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-40711] Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-power…
Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Crítico vulnerabilidad
26/06/2026
[CVE-2025-55017] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users are recommended to upgrade to version 1.3.6 and 2.0.6, which fixes the issue.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
26/06/2026
[CVE-2025-64152] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apac…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.6 and 2.0.7, which fixes the issue.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57912] Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited s…
Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57913] Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meetin…
Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57918] libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_sock…
libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-11625] Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. …
Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in multiprocess applications are predictable across processes.