Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1807
Esta semana
RSS
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59530] Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0.7 versions.
Unauthenticated Broken Access Control in Stripe For WooCommerce
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59534] Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 versions.
Unauthenticated Broken Access Control in Post My CF7 Form
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59690] A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Objec…
A Missing Authorization vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant allows an authenticated attacker with low privileges to perform privileged administrative operations via the REST API that should not be accessible to their permission level, potentially resulting in a system compromise.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-66027] Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that all…
Suna before 0.9.102 contains a broken access control vulnerability in the message queue API that allows authenticated attackers to access and manipulate queue resources belonging to other users by exploiting missing ownership and account isolation checks. Attackers can read pending prompt queues of all users, read or delete individual sessions, and inject arbitrary prompts into another user's sess…
M Alto vulnerabilidad
24/07/2026
[CVE-2026-10033] The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions u…
The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to grant EventON management capabilities and the upload_files capability to any non-administrator WordPress role or user,…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65916] CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in…
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65895] Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin con…
Grav API Plugin versions before 1.0.10 fail to restrict write access to security-critical plugin configuration scopes, allowing authenticated users with api.config.write privilege to modify rate limiting and CORS settings. Attackers can disable rate limiting site-wide to enable credential brute-forcing attacks and reconfigure CORS policies to include attacker-controlled origins with credentials en…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65500] Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPres…
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65495] Unauthenticated Broken Access Control in Dokan Pro <= 5.0.3 versions.
Unauthenticated Broken Access Control in Dokan Pro
J Alto vulnerabilidad
23/07/2026
[CVE-2026-64814] In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Developme…
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session
M Alto vulnerabilidad
23/07/2026
[CVE-2026-61954] Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
Unauthenticated Broken Access Control in PayU India
M Alto vulnerabilidad
23/07/2026
[CVE-2026-59547] Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce <= 9.1.4 versions…
Unauthenticated Broken Access Control in Payment Gateway for PayPal on WooCommerce
M Alto vulnerabilidad
23/07/2026
[CVE-2026-61943] Unauthenticated Broken Access Control in WPDM – Premium Packages <= 6.2.0 versions.
Unauthenticated Broken Access Control in WPDM – Premium Packages
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57367] Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versions.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-12082] The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of…
The Praison AI SEO WordPress plugin before 5.0.7 does not perform authorization checks on several of its REST API routes, allowing unauthenticated users to modify the permalink of any published post and to read Praison AI SEO WordPress plugin before 5.0.7 configuration data.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13078] A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine uncond…
A vulnerability was discovered in MongoDB Server where the server-side MozJS scripting engine unconditionally registered a module loading hook that enables JavaScript calls to read arbitrary files from the host filesystem using the mongod process's privileges. An authenticated user could exploit this through crafted aggregation pipeline commands to read sensitive files accessible to the MongoDB se…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-61267] Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (componen…
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in unauthorized upd…
O Alto vulnerabilidad
21/07/2026
[CVE-2026-60953] Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite…
Vulnerability in the Oracle Telecommunications Billing Integrator product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Telecommunications Billing Integrator. Successful attacks of this vulnerability can result i…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-47688] FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version…
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node endpoint. This allows remote wiping of host AES encryption credentials and deletion of all power mana…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-47412] PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior …
PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an authorization bypass enabling destructive action. The `DELETE /workspaces/{workspace_id}` endpoint is gated only by `require_workspace_member(workspace_id)` (default `min_role="member"`). Any member of the workspace can issue a single DELETE to wipe the entire workspace, including e…