Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1777
Esta semana
RSS
M Alto vulnerabilidad
23/06/2026
[CVE-2026-56222] Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings …
Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify app_id ownership during app-scoped role binding creation. An attacker with administrative privileges in one organization can create role bindings targeting applications owned by other organizations, enabling unauthorized read and modification of victim applications.
M Alto vulnerabilidad
22/06/2026
[CVE-2026-56424] MISP core contained multiple broken access-control flaws where authorization checks were performed a…
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affected subsystems, a lower-privileged authenticated user with the relevant feature permission could cause the application to authorize one object but mutate another, or could modify objects that were mer…
M Alto vulnerabilidad
20/06/2026
[CVE-2026-56215] Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbi…
Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, which the SSO provisioning endpoint trusts as an account-merge key. Attackers can pre-position their account with a victim's corporate SSO email, causing the provision-user endpoint to merge the victim's SSO identity into the attacker-controlled account.
M Alto vulnerabilidad
19/06/2026
[CVE-2026-49338] gonic is a music streaming server / free-software subsonic server API implementation. Prior to versi…
gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/deletePlaylist.view` and `/rest/getPlaylist.view` perform no per-resource authorization. Once authenticated as any user (admin or not), an attacker can delete any playlist owned by any other user (including admin) by passing its `id` and read the full con…
M Alto vulnerabilidad
19/06/2026
[CVE-2026-49339] gonic is a music streaming server / free-software subsonic server API implementation. The maintainer…
gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6dd71e6a3c966867ef8c900d359a7df75789f410` added an ownership check based on `playlist.UserID`. However, `playlist.UserID` is derived from the first path segment of the attacker-controlled playlist ID, with no path containment on the resolved file path. Any authenticated Subsonic u…
M Alto vulnerabilidad
17/06/2026
[CVE-2026-48759] TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Referenc…
TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability through cross-workspace Theme Template modification and deletion. The handleSaveThemeTemplate and handleDeleteThemeTemplate handlers validate that the authenticated user is a non-guest member of the provided workspaceId, but then operate on themeTemplateId via Prisma queries that do …
M Alto vulnerabilidad
17/06/2026
[CVE-2026-50194] Steeltoe is an open source project that provides a collection of libraries that helps users build cl…
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. When Steeltoe management endpoints versions 3.2.2 through 3.3.0 and 4.1.0 are configured to listen on an alternate port (`Management:Endpoints:Port` is configured), the middleware responsible for restricting access to the endpoints uses the `Host` HTTP header rather than the…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/06/2026
[CVE-2026-54184] Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Clean Login
M Alto vulnerabilidad
17/06/2026
[CVE-2026-40768] Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system <= 10.30.24 version…
Unauthenticated Insecure Direct Object References (IDOR) in Salon booking system
O Alto vulnerabilidad
16/06/2026
[CVE-2026-53863] OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers th…
OpenClaw before 2026.4.25 contains an input validation vulnerability in tool group policy callers that accept unvalidated group IDs. Attackers who can supply a group ID to the policy resolver could trigger incorrect group-policy decisions for tool invocations, potentially bypassing intended access controls.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-52699] Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.
Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar
M Alto vulnerabilidad
15/06/2026
[CVE-2026-48868] Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart <= 5.2.9 versions.
Unauthenticated Insecure Direct Object References (IDOR) in Simple Shopping Cart
M Alto vulnerabilidad
15/06/2026
[CVE-2026-48872] Unauthenticated Sensitive Data Exposure in EmbedPress <= 4.5.2 versions.
Unauthenticated Sensitive Data Exposure in EmbedPress
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39518] Subscriber Insecure Direct Object References (IDOR) in EventPrime <= 4.3.0.0 versions.
Subscriber Insecure Direct Object References (IDOR) in EventPrime
M Alto vulnerabilidad
15/06/2026
[CVE-2025-59133] Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions.
Custom role Insecure Direct Object References (IDOR) in Projectopia

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-12204] A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderC…
A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the file app/api/controller/Crontab.php of the component Scheduled Task Endpoint. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The v…
M Alto vulnerabilidad
12/06/2026
[CVE-2026-42947] A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind …
A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently reassign a device to an arbitrary account. Because the affected endpoints validate request signatures but do not confirm legitimate ownership, an attacker with any account can take over a device without user interaction while the device remains online and unaware.
T Alto vulnerabilidad
12/06/2026
[CVE-2026-45830] A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows …
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.
T Alto vulnerabilidad
12/06/2026
[CVE-2026-45832] All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database…
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.
L Alto vulnerabilidad
11/06/2026
[CVE-2026-7787] IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive i…
IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.