Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66461] Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce <= 1.0.5 versions.
Unauthenticated Broken Access Control in SMEPay: UPI Gateway for WooCommerce
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66466] Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Up…
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66431] Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLIN…
Unauthenticated Broken Access Control in Bitcoin Lightning Payment Gateway for WooCommerce (via CLINK)
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66441] Unauthenticated Broken Access Control in MultiVendorX <= 5.0.10 versions.
Unauthenticated Broken Access Control in MultiVendorX
M Alto vulnerabilidad
13/08/2026
[CVE-2026-61984] Unauthenticated Broken Access Control in WPMobile.App <= 11.77 versions.
Unauthenticated Broken Access Control in WPMobile.App
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28186] Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 versions.
Subscriber Broken Access Control in Travelfic Toolkit
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28188] Unauthenticated Broken Access Control in Hydra Booking <= 1.2.2 versions.
Unauthenticated Broken Access Control in Hydra Booking

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28173] Customer Arbitrary Content Deletion in WP Event SOlution <= 4.1.19 versions.
Customer Arbitrary Content Deletion in WP Event SOlution
M Alto vulnerabilidad
13/08/2026
[CVE-2026-27535] Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
Subscriber Broken Access Control in Solace Extra
M Alto vulnerabilidad
13/08/2026
[CVE-2026-27345] Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce
M Alto vulnerabilidad
13/08/2026
[CVE-2026-6471] Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION priv…
Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
M Alto vulnerabilidad
13/08/2026
Vulnerabilidad de autorización faltante en SiYuan v3.7.3 y anteriores (CVE-2026-73608)
SiYuan contiene una vulnerabilidad de autorización ausente en el endpoint /api/av/getAttributeViewSearchTarget que permite acceso no autorizado a vistas de atributos sin validación de permisos. La falla afecta la rama de desarrollo y versiones previas a v3.7.4. Organizaciones que utilizan SiYuan para gestión de bases de datos están expuestas a exfiltración de información sensible si acceden versiones vulnerables.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-73326] CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privile…
CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime across the attack, front_cache, cama_meta_tag, and cama_contact_form plugins to al…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72795] SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBloc…
SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and getBlockDOMsWithEmbed endpoints. Attackers can request published blocks containing embed queries to read content from password-protected, hidden, or forbidden documents without authorization.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72798] SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeVie…
SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block ty…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72789] SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating the…
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-16494] GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 …
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to modify project settings restricted to higher-privileged roles, due to missing authorization checks on a project update endpoint.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-66375] A low-privilege authenticated user may permanently remove protected internal metadata across reposit…
A low-privilege authenticated user may permanently remove protected internal metadata across repositories under specific conditions.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-53996] NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerabil…
NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to invoke the HDAUDIO_FGRP_SETCONFIG ioctl without elevated permissions by exploiting the absence of an access check on /dev/hdaudioN device nodes. Attackers can repeatedly issue HDAUDIO_FGRP_SETCONFIG from one thread while keeping DMA and IRQs live from …
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18789] The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content ex…
The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as to persistently change some of its settings.