Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,390
Total alertas
3275
Críticas
10807
Altas
8
Ransomware
1049
Esta semana
RSS
S Alto vulnerabilidad
23/07/2026
[CVE-2026-65690] Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server. The vulnerability is specific …
M Alto vulnerabilidad
23/07/2026
[CVE-2026-14257] brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand()…
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count …
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65906] In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was po…
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65908] In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executabl…
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65896] Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate …
Grav API Plugin (Composer package getgrav/grav-plugin-api) before 1.0.10 fails to properly validate the slug field in the POST /pages/{route}/move endpoint. PagesController::move() sanitizes the slug only with ltrim($body['slug'], '.'), which strips leading periods but does not neutralize '/' or '..' segments. An authenticated API caller with the api.pages.write permission can supply path traversa…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65897] Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::c…
Grav API Plugin versions before 1.0.10 fail to validate the groups field in InvitationsController::create(), allowing authenticated api.users.write callers to assign invited accounts to groups that grant api.super permissions. Attackers can create invitation records with elevated group membership, and when accepted, the new account gains full super-admin API access without the inviter holding thos…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65540] Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 version…
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65608] Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory…
Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only that the target is callable (is_callable()) without restricting dangerous functions such as exec, system, passthru, or shell_exec. Because FlexDirectory registe…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65895] Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin con…
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials en…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65532] Shop manager SQL Injection in Persian Woocommerce SMS <= 7.2.2 versions.
Shop manager SQL Injection in Persian Woocommerce SMS
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65539] Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65526] Contributor SQL Injection in Visualizer <= 4.0.6 versions.
Contributor SQL Injection in Visualizer
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65510] Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65511] Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education Wor…
Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65516] Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65497] Administrator PHP Object Injection in Complianz <= 7.5.0 versions.
Administrator PHP Object Injection in Complianz
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65500] Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPres…
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65492] Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Dokan Pro
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65493] Subscriber PHP Object Injection in Dokan Pro <= 5.0.2 versions.
Subscriber PHP Object Injection in Dokan Pro
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65494] Subscriber SQL Injection in Dokan Pro <= 5.0.2 versions.
Subscriber SQL Injection in Dokan Pro