Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
N Crítico vulnerabilidad
13/07/2026
[CVE-2026-57433] Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted S…
Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative coun…
P Crítico vulnerabilidad
13/07/2026
[CVE-2026-13221] Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternati…
Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision tab…
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-60121] Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/aj…
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. The endpoint applies escapeshellarg() to the user-supplied host POST parameter before passing it to a system wrapper, but the wrapper retrieves the decod…
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-61498] Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/aj…
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote unauthenticated attackers to execute arbitrary commands by supplying shell metacharacters in the start, end, key, or format HTTP GET parameters. Attackers can exploit the lack of input sanitization in the graph generation script, which passes user-suppli…
F Crítico vulnerabilidad
13/07/2026
[CVE-2026-40469] Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine)…
Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program to crash. It affects 32-bit builds of gawk in versions 5.4.0 and below.
F Crítico vulnerabilidad
13/07/2026
[CVE-2026-40468] Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may le…
Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57811] Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic…
Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows Remote Code Inclusion.This issue affects Realtyna Organic IDX plugin: from n/a through

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57813] Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege …
Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-59515] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows Blind SQL Injection.This issue affects AIWU: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-59518] Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injec…
Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57770] Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography all…
Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Photography: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57738] Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Inject…
Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57739] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP Newsletter acymailing allows Blind SQL Injection.This issue affects AcyMailing SMTP Newsletter: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57744] Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions a…
Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Theme 18 | Extensions: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57724] Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This …
Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57726] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.This issue affects Kirki: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57710] Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbo…
Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Max: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57714] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL Injection.This issue affects LatePoint: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57719] Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-…
Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affects Aimogen Pro: from n/a through
M Crítico vulnerabilidad
13/07/2026
[CVE-2026-57702] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking allows Blind SQL Injection.This issue affects Amelia: from n/a through