Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 8747 resultados ✕ Limpiar búsqueda
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1856
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-78267] Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.
Unauthenticated Privilege Escalation in TranslatePress
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-78268] Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat But…
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-78282] Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-77384] libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the re…
libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE requests for the same reservation, causing unbounded listener and closure growth in @lib…
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-78259] Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Unauthenticated Broken Authentication in WPLegalPages
M Crítico vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-78262] Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.
Unauthenticated PHP Object Injection in WP Project Manager
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-32560] Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Gen…
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-32561] Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Subscriber Privilege Escalation in Booking Hub
M Crítico vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-32563] Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 ver…
Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress
M Crítico vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-32554] Unauthenticated SQL Injection in WooBeWoo Product Filter Pro <= 3.1.8 versions.
Unauthenticated SQL Injection in WooBeWoo Product Filter Pro
M Crítico vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-32555] Unauthenticated SQL Injection in Boost <= 2.0.4 versions.
Unauthenticated SQL Injection in Boost
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-32556] Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Boost
M Crítico vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-32559] Subscriber Arbitrary File Upload in UltimateAI <= 3.1.0 versions.
Subscriber Arbitrary File Upload in UltimateAI
M Alto vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-7455] A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Wri…
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
M Alto vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-77567] Filament is a collection of full-stack components for accelerated Laravel development. Prior to vers…
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-16783] A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Wri…
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
M Alto vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-19568] A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption …
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
M Alto vulnerabilidad Nuevo
Hace 17 horas
[CVE-2026-76098] Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vul…
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can exceed Python's recursion limit and raise RecursionError, allowing crafted Markdown to crash a parsing pr…
M Alto vulnerabilidad Nuevo
Hace 17 horas
[CVE-2026-61419] Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A …
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
M Alto vulnerabilidad Nuevo
Hace 18 horas
[CVE-2026-71504] Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that…
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and…