Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 43 min
Buscando: "Multiple Vendors" — 13275 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Alto vulnerabilidad
17/06/2026
[CVE-2025-59563] Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.
Subscriber Privilege Escalation in Sonaar
M Alto vulnerabilidad
17/06/2026
[CVE-2025-60085] Unauthenticated Local File Inclusion in Learnify <= 1.15.0 versions.
Unauthenticated Local File Inclusion in Learnify
M Alto vulnerabilidad
17/06/2026
[CVE-2025-60223] Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot <= 13.6.5 versions.
Subscriber Arbitrary File Deletion in WPBot Pro Wordpress Chatbot
M Alto vulnerabilidad
17/06/2026
[CVE-2025-49403] Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress <= 3…
Unauthenticated Arbitrary File Download in Premium Age Verification / Restriction for WordPress
M Alto vulnerabilidad
17/06/2026
[CVE-2025-58924] Unauthenticated Local File Inclusion in Geya <= 1.15 versions.
Unauthenticated Local File Inclusion in Geya
M Alto vulnerabilidad
17/06/2026
[CVE-2025-58952] Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.
Unauthenticated Local File Inclusion in Neuronet < 1.14.0 versions.
M Alto vulnerabilidad
17/06/2026
[CVE-2025-58953] Unauthenticated Local File Inclusion in Joly <= 1.22.0 versions.
Unauthenticated Local File Inclusion in Joly

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/06/2026
[CVE-2025-58954] Unauthenticated Local File Inclusion in HomeRoofer <= 2.11.0 versions.
Unauthenticated Local File Inclusion in HomeRoofer
M Alto vulnerabilidad
17/06/2026
[CVE-2025-59560] Unauthenticated Cross Site Scripting (XSS) in Sonaar <= 4.27.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Sonaar
M Alto vulnerabilidad
17/06/2026
[CVE-2025-31013] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themify Folo allows Reflected XSS. This issue affects Themify Folo: from n/a through 1.9.6.
M Alto vulnerabilidad
17/06/2026
[CVE-2024-49269] Unauthenticated Cross Site Scripting (XSS) in my flatonica <= 0.0.8 versions.
Unauthenticated Cross Site Scripting (XSS) in my flatonica
M Alto vulnerabilidad
17/06/2026
[CVE-2024-32729] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Quan…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8.
M Alto vulnerabilidad
17/06/2026
[CVE-2024-32949] Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly C…
Missing Authorization vulnerability in Prince Integrate Google Drive allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Integrate Google Drive: from n/a through 1.3.8.
M Alto vulnerabilidad
17/06/2026
[CVE-2026-12348] Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain …
Address bar spoofing in Arc Search for Android allows a remote attacker to display a trusted domain in the address bar while rendering attacker-controlled content, enabling phishing.
M Alto vulnerabilidad
16/06/2026
[CVE-2026-22312] The device has a webserver that exposes a REST API authenticated with a constant token. The unauthen…
The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system reboot).

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/06/2026
[CVE-2026-10303] In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not s…
In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 before being used in challenge-file handling, allowing a maliciously crafted token to influence local path/filename usage during validation. An attacker who can supply ACME challenge responses to getssl (for example, a malicious or compromised CA endpoint, or an on…
M Alto vulnerabilidad
16/06/2026
[CVE-2024-39575] update_disk_psu_baseline.sh requires password in plain text
update_disk_psu_baseline.sh requires password in plain text
M Alto vulnerabilidad
16/06/2026
[CVE-2026-42089] Yeoman Environment provides an API to discover, create, and run generators, and to configure where a…
Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator is resolved. Versions 2.9.0 through 6.0.0 install missing local generator packages from caller-supplied package names without user confirmation. In downstream consumers that pass attacker-controlled project configuration into this path, this can result in arbitrary package install…
M Alto vulnerabilidad
16/06/2026
[CVE-2026-44932] Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 co…
Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.
M Alto vulnerabilidad
16/06/2026
[CVE-2025-71261] An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE H…
An attacker with network-level access between the SUSE Virtualization and Rancher Manager in SUSE Harvester before 1.8.0 could interfere with the TLS handshake and abuse it to bypass TLS as a security control.