Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 13 horas
13,736
Total alertas
3106
Críticas
10358
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73356] Unauthenticated Arbitrary Content Deletion in Breeze <= 2.5.12 versions.
Unauthenticated Arbitrary Content Deletion in Breeze
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73190] Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages <= 7.0.5 versions.
Unauthenticated Cross Site Scripting (XSS) in WPDM – Premium Packages
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73338] Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Autopay
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73342] Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Multilang
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73181] Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 ver…
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66793] A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Man…
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and …
M Alto vulnerabilidad
18/08/2026
[CVE-2026-68567] Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Convert Pro

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/08/2026
[CVE-2026-69189] Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.use…
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history ide…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66667] Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Templately
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66635] Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web <= 1.2.62 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Slider by 10Web
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66046] Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic compl…
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes …
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66620] Editor PHP Object Injection in OptionTree <= 2.7.3 versions.
Editor PHP Object Injection in OptionTree
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66621] Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66622] Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.
Unauthenticated SQL Injection in Depicter Slider
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66629] Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Kirki

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/08/2026
[CVE-2026-66633] Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-61407] Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Acce…
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-63639] Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey…
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream payload that assigns one Pending Entry List NACK to multiple consumers during stream consumer-group deserialization, causing a use-after-free when one consumer is deleted while another still references the shared NACK and potentially allowing remote …
M Alto vulnerabilidad
18/08/2026
[CVE-2026-56684] Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey…
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This …
M Alto vulnerabilidad
18/08/2026
[CVE-2026-59825] Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from…
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq backgro…