Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1780
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-54795] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-54796] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-56088] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-43961] A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expressio…
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
M Alto vulnerabilidad
Hace 5 días
[CVE-2020-37267] Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authori…
Renovate versions >=19.180.0 and
M Alto vulnerabilidad
Hace 5 días
[CVE-2024-58376] Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 m…
Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations, gaining full access to Renovate's execution environm…
M Alto vulnerabilidad
Hace 5 días
[CVE-2019-25766] Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comme…
Renovate versions >= 13.87.0 and

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-76235] A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every …
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73387] Unauthenticated Local File Inclusion in Resido <= 1.5 versions.
Unauthenticated Local File Inclusion in Resido
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73394] Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
Unauthenticated Broken Access Control in Stitch Express
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73354] Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.
Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73384] Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73385] Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.
Unauthenticated Broken Access Control in Outranking Plugin Options
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73386] Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 …
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73182] Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.
Unauthenticated Cross Site Scripting (XSS) in BBQ Pro

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73184] Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Global Gallery
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-66596] Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Newsletter
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-66668] Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.
Subscriber SQL Injection in Community by PeepSo
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-61986] Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-32552] Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.
Subscriber SQL Injection in YITH WooCommerce Membership Premium