Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Ni" — 5671 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
06/06/2026
[CVE-2026-9851] The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover …
The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, and including, 1.7.16. This is due to a missing capability check on the 'updateUser' branch of the package_app_action AJAX endpoint, where the handler only validates a nonce and the dispatcher invokes Schedule::updateUser() with the $administrator argument hard-coded to 1, bypassi…
M Alto vulnerabilidad
06/06/2026
[CVE-2026-7537] The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all version…
The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.7.8.3 via the mdjm_send_comm_email function. This is due to no file type, extension, or MIME type validation being performed on uploaded files. This makes it possible for authenticated attackers, with administrator-level access and above, to upload files that may be executa…
M Alto vulnerabilidad
06/06/2026
[CVE-2026-8901] The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin f…
The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Submission Data in all versions up to, and including, 1.0.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute …
M Alto vulnerabilidad
06/06/2026
[CVE-2026-8438] The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored …
The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.4.7. This is due to insufficient input sanitization in the get_rest_route() function and missing output escaping in the column_default() method of the debug log list table. When the 'Disable REST API for non-logged in users' feature (aiowps_disa…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-36785] Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow i…
Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter of the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-11422] Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability…
Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers can exploit the unsanitized passing of wavedrom block content to window.eval() in the VS Code webview…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-46493] HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `u…
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitable. Version 26.0.1 fixes the issue.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
05/06/2026
[CVE-2026-46392] HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX …
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML files is case-sensitive. An HTML file uploaded with an uppercase extension (`.HTML`, `.Html`, `.HTM…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-49493] Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which…
Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.runInNewContext(), allowing arbitrary code execution. A crafted markdown document containing a malicious bitfield code block executes attacker-controlled code on the server side when the document is rendered or exported. Fixed in 0.8.28 by parsing bitfield…
T Alto vulnerabilidad
05/06/2026
[CVE-2026-45743] Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capa…
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-manager endpoints in Termix prior to version 2.3.2 do not verify that the requesting user owns the SSH session identified by `sessionId`. An authenticated attacker who knows or guesses another user's active `sessionId` can read, write, delete, download, and execute files on the vic…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-36501] An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to ca…
An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-11342] A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affec…
A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of the argument room leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-11344] A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown fu…
A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration Form. Performing a manipulation of the argument photo results in unrestricted upload. The attack may be initiated remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
05/06/2026
[CVE-2025-5088] An authenticated Redis session could be used to obtain full root access to all servers in the CVX cl…
An authenticated Redis session could be used to obtain full root access to all servers in the CVX cluster. Note that this would require an attacker to have both network access to the Redis service on a CVX server and the Redis password. Please note that all Redis communication, including authentication, occurs over plaintext in the present day. TLS support is tracked under RFE1294850.
7 Alto vulnerabilidad
05/06/2026
[CVE-2026-48095] 7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buff…
7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crashes. CInStream::GetCuSize() in the NTFS handler computes the compression-unit buffer size as (UInt32)…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
05/06/2026
[CVE-2026-11334] A vulnerability was detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec8…
A vulnerability was detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This affects an unknown function of the file dashboard_page/forms/fetch.php. Performing a manipulation of the argument department_code results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. Conti…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-50234] Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attack…
Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting directory traversal in the web server context. Attackers can manipulate file path parameters to access sensitive files outside the intended directory structure.
X Alto vulnerabilidad
05/06/2026
[CVE-2026-50258] A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has mu…
A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify or clamp non-canonical key types to XkbMaxShiftLevel. A client can change key types to excessive shift levels and trigger stack overflows. This is caused by an incomplete fix of CVE-2025-26597. This may…
G Alto vulnerabilidad
05/06/2026
Vulnerabilidad alta en Android OS (CVE-2026-21029) con CVSS 7.8 afecta dispositivos en LATAM
Google Android ha publicado un advisory sobre una vulnerabilidad de severidad alta (CVSS 7.8) en Android OS que impacta millones de dispositivos móviles en México y Latinoamérica, representando más del 80% del parque móvil regional. Esta falla de seguridad requiere actualización inmediata en todos los equipos corporativos y personales para prevenir explotación remota.
G Alto vulnerabilidad
05/06/2026
Escalación de privilegios alta en Android OS (CVE-2026-11295) - CVSS 8.8
Vulnerabilidad de escalación de privilegios en Android OS con puntuación CVSS 8.8 afecta dispositivos móviles en México y Latinoamérica, representando riesgo significativo para más del 80% del parque móvil regional. Un atacante podría obtener permisos elevados sin autenticación explícita del usuario. La actualización de seguridad está disponible mediante el canal oficial de Google.