Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Multiple Vendors" — 13279 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
22/06/2026
[CVE-2023-45795] A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a…
A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device.
M Alto vulnerabilidad
22/06/2026
[CVE-2026-8157] The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned…
The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoints, allowing authenticated users with a custom Vitepos WordPress plugin before 3.4.2 role to escalate privileges to administrator.
M Alto vulnerabilidad
22/06/2026
[CVE-2026-4259] The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a p…
The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
M Alto vulnerabilidad
22/06/2026
[CVE-2026-6858] The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displaye…
The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12806] A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function for…
A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early ab…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-56396] phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRig…
phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.
M Alto vulnerabilidad
21/06/2026
[CVE-2026-56382] Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code exec…
Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
21/06/2026
[CVE-2026-56239] Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_us…
Capgo before 12.128.2 contains a potential privilege escalation vulnerability in the public.apply_usage_overage SECURITY DEFINER function, which performs sensitive billing operations without enforcing internal authorization checks (no validation of auth.uid(), org membership, or check_min_rights). Because the function runs with the owner's privileges, it bypasses Row Level Security. If EXECUTE per…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-56242] Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_…
Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that returns the owning user_id for supplied API keys, creating an API key validity oracle and user identity disclosure primitive. Attackers can call this endpoint with valid or invalid API keys to confirm key validity and map keys to user identifiers, then chain results into other exposed RPCs…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-56253] Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_member…
Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that allows unauthenticated attackers to enumerate organization members. Attackers can invoke the endpoint using only the public sb_publishable_* key and an organization UUID to retrieve sensitive member information including email addresses, user IDs, roles, and pending invitations.
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12786] A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this i…
A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue is some unknown functionality in the library bootpt64.sys of the component Kernel Driver. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12782] A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is a…
A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation results in improper access controls. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The affected component should be upgraded. The vendor ex…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12784] A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown fu…
A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not r…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12781] A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unk…
A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly available and might be used. You should upgrade the affected component. The vendor explains: "We have confir…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12778] A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affect…
A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12779] A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unkno…
A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did …
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12780] A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in th…
A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any …
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12775] A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909…
A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery…
M Alto vulnerabilidad
20/06/2026
[CVE-2026-56341] AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plu…
AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction data including agreement IDs, user financial records, and API responses via direct GET requests to vulnerable endpoints.
M Alto vulnerabilidad
20/06/2026
[CVE-2026-56345] AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecord…
AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verification. An attacker with knowledge of the Meet shared secret can craft a malicious file upload with a filename containing an arbitrary users_id to invoke passwordless User->login() and establish an au…