Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-102262] Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working…
Newell Brands DYMO ID 1.5.1.71 resolves its plugin Modules directory relative to the process working directory. An attacker could store a job file alongside malicious modules / DLL that sets the process working directory to the job file's folder when a victim clicks on the file, resulting in code execution at the victim's privilege level. Fixed in 1.6.0.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-97257] Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-pla…
Deserialization of Untrusted Data vulnerability in PressTigers Simple Event Planner simple-event-planner allows Object Injection.This issue affects Simple Event Planner: from n/a through 1.5.7.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-93617] Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-ca…
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart sunshine-photo-cart allows Object Injection.This issue affects Sunshine Photo Cart: from n/a through 3.7.1.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105679] Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content…
Ghost is a Node.js content management system. From 6.22.1 until 6.64.0, Ghost restricted the content type used to serve uploaded files to prevent browsers from executing them. On sites using the default local storage adapter, this restriction was not applied, so files uploaded by any staff user were served with a content type derived from their file extension. This could be used to host scripts on…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105651] Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark car…
Ghost is a Node.js content management system. From 5.94.0 until 6.64.0, when creating a bookmark card, Ghost could store non-image files fetched from an external website as bookmark icons or thumbnails. This allowed any staff user, including Contributors, to host arbitrary HTML on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in versi…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105675] Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission …
Ghost is a Node.js content management system. From 4.39.0 until 6.64.0, staff users with permission to view staff invites were able to discover the secret token of pending invites, including invites for roles with higher privileges than their own. This could allow a staff user to escalate their privileges by accepting a pending invite. This issue is fixed in version 6.64.0.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105677] Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost…
Ghost is a Node.js content management system. From 6.10.3 until 6.64.0, a vulnerability in how Ghost loads theme translation files allowed an authenticated Administrator to execute arbitrary code on the server via a crafted theme. This issue is fixed in version 6.64.0.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105649] Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG…
Ghost is a Node.js content management system. From 4.22.0 until 6.65.0, SVG media thumbnails and SVG images uploaded with a non-SVG file extension were stored without sanitization. This allowed any staff user, including Contributors, to host scripts on the site's domain, possibly resulting in compromise of other staff users' admin sessions. This issue is fixed in version 6.65.0.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105650] Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attac…
Ghost is a Node.js content management system. From 2.1.0 until 6.64.0, embedding a URL from an attacker-controlled website could result in untrusted scripts being stored in post content. These scripts could run in the Ghost editor, on the published site, and in newsletter emails, possibly resulting in compromise of a staff user's admin session. This issue is fixed in version 6.64.0.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105392] A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an …
A vulnerability has been found in Lybbn Django-Vue-Lyadmin up to 3.2.12. The impacted element is an unknown function of the file backend/application/settings.py of the component JWT Signing. The manipulation of the argument SECRET_KEY leads to use of hard-coded cryptographic key . Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The proj…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-103066] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP BASE WP BASE Booking wp-base-booking-of-appointments-services-and-events allows Blind SQL Injection.This issue affects WP BASE Booking: from n/a through 6.4.0.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-103348] Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate…
Deserialization of Untrusted Data vulnerability in Smackcoders Inc. WP Ultimate Exporter wp-ultimate-exporter allows Object Injection.This issue affects WP Ultimate Exporter: from n/a through 3.0.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-100511] Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-goog…
Deserialization of Untrusted Data vulnerability in Vektor Inc. VK Google Job Posting Manager vk-google-job-posting-manager allows Object Injection.This issue affects VK Google Job Posting Manager: from n/a through 1.3.1.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-100506] Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allo…
Deserialization of Untrusted Data vulnerability in WP Spell Check WP Spell Check wp-spell-check allows Object Injection.This issue affects WP Spell Check: from n/a through 12.1.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-97303] Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-g…
Missing Authorization vulnerability in Apps Mav Scratch & Win – Giveaways and Contests scratch-win-giveaways-for-website-facebook allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scratch & Win – Giveaways and Contests: from n/a through 3.0.2.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-58859] In multiple places, there is a possible denial of service due to an uncaught exception. This could …
In multiple places, there is a possible denial of service due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-58865] In multiple functions of PduParser.java, there is a possible persistent denial of service due to a m…
In multiple functions of PduParser.java, there is a possible persistent denial of service due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-58880] In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a…
In handle_app_val_response of btif_rc.cc, there is a possible way to achieve code execution due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-55270] In dialInternal in multiple locations, there is a possible permission bypass due to a confused deput…
In dialInternal in multiple locations, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-55280] In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could…
In multiple locations, there is a possible out-of-bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.