Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 44 min
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-107809] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired acce…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, AuthRequired accepts a browser-managed token cookie as an API credential after the front end stores the JWT in that cookie. Because management endpoints do not universally require a CSRF token or perform Origin or Referer validation, a remote attacker can induce a logged-in administrator's browser to submit authenti…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-62026] Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allo…
Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allows Cross Site Request Forgery.This issue affects Dashboard Notes: from n/a through 1.0.3.
M Alto vulnerabilidad Nuevo
Hace 11 horas
Vulnerabilidad CSRF alta en Featured Image from URL (fifu.app) versiones hasta 6.0.7
Se detectó una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) en el plugin Featured Image from URL para WordPress que permite a atacantes ejecutar acciones no autorizadas en sitios afectados. La vulnerabilidad impacta versiones desde la inicial hasta la 6.0.7, afectando miles de sitios WordPress en LATAM que utilizan este plugin para gestión de imágenes destacadas. Con CVSS 8.8, representa un riesgo alta para la integridad y disponibilidad de contenido.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107337] The Malcolm kiosk Flask application exposes a POST /script_call/<script> endpoint with zero authenti…
The Malcolm kiosk Flask application exposes a POST /script_call/ endpoint with zero authentication and wildcard CORS (CORS(app)). An attacker can force the operator's browser to execute arbitrary management commands via CSRF, including control.py --wipe which permanently deletes all captured network traffic and forensic logs, or control.py --stop which blinds the security monitoring.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107295] Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. …
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A website visited by a developer can submit a browser-compatible request to a loopback-hosted chat server, causing the served agent to run and execute tools wi…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-62142] Cross-Site Request Forgery (CSRF) vulnerability in Melapress WP 2FA wp-2fa allows Cross Site Request…
Cross-Site Request Forgery (CSRF) vulnerability in Melapress WP 2FA wp-2fa allows Cross Site Request Forgery.This issue affects WP 2FA: from n/a through 4.1.0.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-66479] Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allo…
Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through 2.9.5.6.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-106611] Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Forminator forminator allows Cross Site …
Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Forminator forminator allows Cross Site Request Forgery.This issue affects Forminator: from n/a through 1.57.3.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105783] Joplin is an open source note-taking and to-do application that organises notes and lists into noteb…
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with the opt-in Web Clipper server enabled, the server in packages/lib/ClipperServer.ts sends Access-Control-Allow-Origin: * and allows an arbitrary website to call POST /auth and GET /auth/check because the pairing endpoints do not reject HTTP o…
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad CSRF alta en Blubrry PowerPress Podcasting hasta versión 11.17.9
Se ha identificado una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) en el plugin Blubrry PowerPress Podcasting para WordPress que afecta versiones hasta 11.17.9. Esta falla permite a atacantes ejecutar acciones no autorizadas en plataformas de podcasting, incluyendo modificación de contenido y configuraciones administrativas. Es especialmente alta para medios, productoras de contenido y plataformas de distribución de audio en LATAM que utilizan este plugin.