Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 8 horas
13,736
Total alertas
3106
Críticas
10358
Altas
8
Ransomware
1029
Esta semana
RSS
B Alto vulnerabilidad
15/06/2026
[CVE-2026-47261] Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a file…
Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and FilePerms::READ without FilePerms::WRITE, this access control mechanism can be bypassed via the wasip2 descriptor.open-at or wasip1 path_open interfaces by opening a file with only the OpenFlags::TRUNCATE oflag. The root cause is that the clause handling O…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-45437] Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor <= 1.0.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Product Filter Widget for Elementor
M Alto vulnerabilidad
15/06/2026
[CVE-2026-45441] Unauthenticated Other Vulnerability Type in WpEvently <= 5.3.3 versions.
Unauthenticated Other Vulnerability Type in WpEvently
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42775] Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.7.2 versions.
Unauthenticated Cross Site Scripting (XSS) in AutomatorWP
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42664] Unauthenticated Broken Access Control in AI Product Search for WooCommerce &#8211; Motive Commerce S…
Unauthenticated Broken Access Control in AI Product Search for WooCommerce &#8211; Motive Commerce Search
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42666] Unauthenticated Broken Access Control in Salon booking system <= 10.30.25 versions.
Unauthenticated Broken Access Control in Salon booking system
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42667] Unauthenticated Sensitive Data Exposure in Bookly <= 27.4 versions.
Unauthenticated Sensitive Data Exposure in Bookly

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42668] Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versi…
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42686] Subscriber Cross Site Scripting (XSS) in EventPrime <= 4.3.2.1 versions.
Subscriber Cross Site Scripting (XSS) in EventPrime
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42687] Unauthenticated PHP Object Injection in EventPrime <= 4.3.2.1 versions.
Unauthenticated PHP Object Injection in EventPrime
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42658] Unauthenticated Cross Site Scripting (XSS) in Classified Listing <= 5.3.8 versions.
Unauthenticated Cross Site Scripting (XSS) in Classified Listing
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42661] Custom role Path Traversal in WP Customer Area <= 8.3.4 versions.
Custom role Path Traversal in WP Customer Area
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42384] Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
Unauthenticated Sensitive Data Exposure in Simply Schedule Appointments < 1.6.11.2 versions.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42411] Unauthenticated Broken Authentication in CloudSecure WP Security <= 1.4.7 versions.
Unauthenticated Broken Authentication in CloudSecure WP Security
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42649] Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator <= 1.2.11 versions.
Unauthenticated Cross Site Scripting (XSS) in Favicon Rotator

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42650] Unauthenticated Cross Site Scripting (XSS) in AutomatorWP <= 5.6.7 versions.
Unauthenticated Cross Site Scripting (XSS) in AutomatorWP
M Alto vulnerabilidad
15/06/2026
[CVE-2026-40788] Subscriber Broken Access Control in ChatBot <= 7.9.7 versions.
Subscriber Broken Access Control in ChatBot
M Alto vulnerabilidad
15/06/2026
[CVE-2026-40789] Unauthenticated Sensitive Data Exposure in Amelia <= 2.2 versions.
Unauthenticated Sensitive Data Exposure in Amelia
M Alto vulnerabilidad
15/06/2026
[CVE-2026-40791] Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form <= 1.2.46 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Time Slots Booking Form
M Alto vulnerabilidad
15/06/2026
[CVE-2026-40774] Unauthenticated Broken Access Control in Booking Package <= 1.7.06 versions.
Unauthenticated Broken Access Control in Booking Package