Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,331
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1201
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-25291] Memory corruption when performing concurrent operations on shared memory page lists due to lack of p…
Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105701] The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to…
The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is due to missing capability check on the REST API form creation endpoint and unsandboxed Twig environment rendering email templates. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on t…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105776] A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to…
A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. T…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-25267] Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-39760] Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook <= 5.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Real 3D FlipBook
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-39789] Unauthenticated Broken Access Control in Fluent Affiliate Pro <= 1.6.4 versions.
Unauthenticated Broken Access Control in Fluent Affiliate Pro
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-41558] Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro <= 1.16.1 versions.
Subscriber Bypass Vulnerability in WP Migration Plugin DB & Files – WP Synchro

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-41563] Unauthenticated Sensitive Data Exposure in Sitemovr <= 1.0.1 versions.
Unauthenticated Sensitive Data Exposure in Sitemovr
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-75962] The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP…
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-39723] Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.
Unauthenticated Broken Access Control in Morning for WooCommerce
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105072] Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
Unauthenticated Broken Access Control in FluentBooking Pro < 2.5.0 versions.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105704] A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unk…
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105486] A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of t…
A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d9…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105571] A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function …
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early throu…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-82988] There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unkno…
There exists an arbitrary file download in vCast APK delivery mechanism in ViewSonic ViewBoard unknown allows a remote, unauthenticated attacker to trigger unprivileged APK installation via serving a malicious APK URL through an unauthenticated download endpoint

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105762] Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/…
Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105782] Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, Refe…
Scrapy is a high-level web crawling and scraping framework for Python. From 1.4.0 until 2.14.2, RefererMiddleware in scrapy/spidermiddlewares/referer.py treated a Referrer-Policy response-header value that resembled a Python import path as a referrer policy class, imported the referenced object, and called it. A malicious website could supply a callable such as sys.exit and terminate a crawler pro…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105783] Joplin is an open source note-taking and to-do application that organises notes and lists into noteb…
Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.13, when Joplin Desktop is running with the opt-in Web Clipper server enabled, the server in packages/lib/ClipperServer.ts sends Access-Control-Allow-Origin: * and allows an arbitrary website to call POST /auth and GET /auth/check because the pairing endpoints do not reject HTTP o…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105471] A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757…
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. Impacted is an unknown function of the file signup.php of the component Registration Handler. The manipulation of the argument fname results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105761] Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/&lt;…
Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/&lt;app_id&gt;/server endpoint in api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to retrieve an AppMCPServer by the client-supplied server ID without verifying that the server belonged to the requested application and tenant. An authenticated workspace member could therefore…