Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,046
Total alertas
3206
Críticas
10568
Altas
8
Ransomware
1052
Esta semana
RSS
M Alto vulnerabilidad
02/07/2026
[CVE-2026-27060] Contributor PHP Object Injection in ARMember Premium <= 7.0 versions.
Contributor PHP Object Injection in ARMember Premium
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69156] Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme <= 5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Kids Zone - Children WordPress Theme
M Alto vulnerabilidad
02/07/2026
[CVE-2026-11946] An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service …
An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM ind…
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69094] Subscriber SQL Injection in Unicamp <= 2.2.2 versions.
Subscriber SQL Injection in Unicamp
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69133] Subscriber Local File Inclusion in Tourmaster <= 5.4.5 versions.
Subscriber Local File Inclusion in Tourmaster
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69134] Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 version…
Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69152] Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress <= 2.2.2 versio…
Unauthenticated Cross Site Scripting (XSS) in Artale | Wedding Photography WordPress

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69153] Unauthenticated Cross Site Scripting (XSS) in Trendy Travel <= 6.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Trendy Travel
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69154] Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme <= 6.7 versions.
Unauthenticated Cross Site Scripting (XSS) in SpaLab | Beauty Salon WordPress Theme
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69155] Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme <= 5.7 versions.
Unauthenticated Cross Site Scripting (XSS) in Fitness Zone WordPress Theme
M Alto vulnerabilidad
02/07/2026
[CVE-2025-58902] Unauthenticated Local File Inclusion in Lighthouse <= 1.2.12 versions.
Unauthenticated Local File Inclusion in Lighthouse
M Alto vulnerabilidad
02/07/2026
[CVE-2026-9834] The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is …
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to OS Command Injection in all versions up to and including 7.11 via the `wp_db_exclude_table` parameter. This is due to the direct concatenation of user-supplied `$_POST['wp_db_exclude_table']` values into the `mysqldump` shell command string in the `mysqldump()` function of `includes/ad…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-13369] The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the att…
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the process() method returns early due to a client-supplied saveProgress flag, bypassing all upload validation, path normalizat…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-14336] PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' …
PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An attacker can craft an issuer such as https://ci.eclipse.org@evil.host (userinfo trick) or https://ci.eclipse.org.evil.host (suffix trick) that satisfies the prefix…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-8441] The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' p…
The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'notinstring' parameter of the wprp_load_more_revs AJAX action in versions up to, and including, 12.7.2. The parameter is read via $_POST['notinstring'] and passed through sanitize_text_field() — which strips HTML and whitespace but does not provide SQL safety. The value is then concatenated directly into a numeri…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/07/2026
[CVE-2026-13251] The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and…
The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the Local Google Fonts feature to be enabled (disabled by default), pretty permalinks to…
L Alto vulnerabilidad
02/07/2026
[CVE-2026-8147] In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoint…
In MLflow versions prior to 3.14.0, when running with authentication enabled, the trace API endpoints lack proper authorization validators. This allows any authenticated user to bypass experiment-level authorization controls on all trace operations, including reading, deleting, and modifying traces on experiments they do not have permission to access. The issue arises from the `_before_request` ha…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-9563] In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not e…
In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume excessive CPU and memory by processing very large documents, including large arrays, objects, strings, numbers, whitespace, o…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-33592] An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service i…
An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field of FindServersRequest is not validated for length or array size. An attacker can declare an arbitrarily large string (up to ~3.9 GB) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until th…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-5821] The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to …
The Image Optimizer plugin for WordPress is vulnerable to arbitrary file deletion in versions up to and including 1.7.4. This is due to insufficient path validation in the Image_Backup::remove() function where backup file paths stored in post meta are used directly in file deletion operations without verifying they are within the uploads directory. The plugin stores backup file paths in the image_…