Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,372
Total alertas
3270
Críticas
10794
Altas
8
Ransomware
1039
Esta semana
RSS
M Alto vulnerabilidad
24/07/2026
[CVE-2026-16519] A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The …
A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link libraries (DLLs) from an unsafe search path, allowing a local attacker to place a malicious DLL in a location searched before the legitimate library location.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-14603] The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorizatio…
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-12497] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict C…
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some v…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-12981] The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation wh…
The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-14172] Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated…
Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, allowing a local low-privileged user to run code as the scan credential (Scan Engine) or as root/SYSTEM (Insight Agent). Fixed in Scan Engine content 1.1.3935 and Insight Agent content component 0.0.245.0.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-16870] Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allo…
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a crafted encryption metadata field to a shared internal stage that a victim proces…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-66138] In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can ach…
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/07/2026
[CVE-2026-66140] Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequ…
Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-66141] Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport i…
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-12736] The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl…
The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to update_option() without any option-name allowlist or value sanitization, while the permission_callback only verifies the…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-56167] Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privi…
Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-35425] Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code…
Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-28698] Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to a…
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-40430] Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability …
Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through the API.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65604] Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open …
Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body exceeds the configured maxBodyBytes limit, Skipper forwards the full payload to the upstream service while OPA evaluates against an empty parsed_body, so policies that deny requests based on body content are not enforced and forb…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65694] Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller …
Microweber CMS through 2.0.20 contains a path traversal vulnerability in the static file controller that allows unauthenticated remote attackers to read arbitrary files by supplying directory traversal sequences in the path query parameter. Attackers can send a single unauthenticated HTTP GET request exploiting the failure of normalize_path() to strip traversal sequences, disclosing sensitive file…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-16765] A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unk…
A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
G Alto vulnerabilidad
23/07/2026
[CVE-2026-16804] Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had c…
Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
23/07/2026
[CVE-2026-16805] Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execut…
Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
23/07/2026
[CVE-2026-16806] Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execu…
Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)