Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 13334 resultados ✕ Limpiar búsqueda
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1261
Esta semana
RSS
M Alto vulnerabilidad
02/07/2026
[CVE-2026-52187] Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to…
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_483ba0 component
M Alto vulnerabilidad
02/07/2026
[CVE-2026-7311] The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary fil…
The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_converted_image_size function in all versions up to, and including, 3.6.13. This makes it possible for authenticated attackers, with author-level access and above, to delete arbitrary files on the server, which can easily lead to remo…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-58465] Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in …
Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that allows unauthenticated remote attackers to exhaust server memory by sending a sequence of Block1 PUT requests with incrementing block numbers. Attackers can target the registration endpoint over UDP without authentication, causing the server to repeat…
M Alto vulnerabilidad
02/07/2026
[CVE-2024-58352] Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attac…
Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitrary Hibernate entity classes by injecting malicious HQL syntax into the uid POST parameter of the wechatLoginHelper.do endpoint. Attackers can exploit the lack of input sanitization in the string-concatenated filter expression passed to the Hibernate findList() call to extract se…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-12167] The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local …
The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access privileged driver functionality via a communication interface that lacks appropriate access restrictions.
M Alto vulnerabilidad
02/07/2026
[CVE-2026-12168] An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a loc…
An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and execute arbitrary code in kernel mode via crafted messages sent through a Minifilter communication port.
M Alto vulnerabilidad
02/07/2026
[CVE-2026-58652] luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd se…
luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only a frontend restriction. The backend travelmate service (running as root) reads th…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57761] Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57765] Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.
Contributor SQL Injection in WP EasyCart
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57766] Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 ver…
Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57752] Contributor SQL Injection in iNET Webkit 1.2.4 versions.
Contributor SQL Injection in iNET Webkit 1.2.4 versions.
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57756] Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.
Contributor SQL Injection in nicen-localize-image
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57757] Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57758] Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 ve…
Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57759] Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57746] Subscriber Broken Access Control in Booked <= 3.0.0 versions.
Subscriber Broken Access Control in Booked
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57748] Contributor Local File Inclusion in Shopify <= 1.0.0 versions.
Contributor Local File Inclusion in Shopify
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57749] Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.
Contributor Local File Inclusion in SportsPress Pro
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57751] Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57686] Unauthenticated Cross Site Scripting (XSS) in WowAddons <= 1.6.14 versions.
Unauthenticated Cross Site Scripting (XSS) in WowAddons