Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 2011 resultados ✕ Limpiar búsqueda
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1772
Esta semana
RSS
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-19961] A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of…
A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a manipulation of the argument selSSID results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-19959] A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetu…
A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This manipulation of the argument pppUserName causes stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclos…
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-74790] Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter change…
Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to expose members that should be hidden. Attackers can access filtered properties and fields by reusing a TemplateContext after tightening its MemberFilter, bypassing sandbox policies across requests or tenants.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-73056] SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication atte…
SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an …
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-73061] Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that al…
Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties without setter-visibility checks. Attackers can modify properties with private, internal, or init-only setters, and perform mass assignment on public-setter properties, permanently altering live host objects after template rendering.
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica de inyección de objetos PHP en plugin ARForms para WordPress
El plugin ARForms (Contact Form, Survey, Quiz & Popup Form Builder) para WordPress contiene una vulnerabilidad de inyección de objetos PHP (CVE-2024-13784, CVSS 9.8) en versiones hasta 1.8.5 que permite a atacantes no autenticados inyectar objetos maliciosos mediante deserialización de datos en envíos de formularios. Aunque actualmente no hay cadenas POP conocidas explotadas, esta vulnerabilidad expone sitios web en México y Latinoamérica que utilicen este plugin, afectando formularios de contacto, encuestas y popups que interactúan directamente con usuarios.
M Crítico vulnerabilidad
16/08/2026
Plugin Solace Extra para WordPress vulnerable a modificación no autorizada de datos (CVE-2026-18316)
El plugin Solace Extra en versiones hasta 1.6.0 permite a atacantes no autenticados modificar o eliminar datos a través de la función import_zip() que carece de validación de permisos. La vulnerabilidad afecta sitios WordPress en México y LATAM que usan este plugin, exponiendo contenido, configuraciones y bases de datos. La verificación de nonce insuficiente permite bypass de controles de seguridad estándar de WordPress.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica de escalada de privilegios en plugin Frontend Admin para WordPress (CVE-2026-18432)
El plugin Frontend Admin by DynamiApps para WordPress contiene una falla de escalada de privilegios en versiones hasta 3.29.9 que permite a usuarios no autenticados obtener permisos de administrador. La vulnerabilidad reside en la función ActionUser::conditions_logic() que omite validaciones de autorización cuando recibe parámetros no numéricos, afectando directamente a sitios WordPress en México y LATAM que usan este plugin. Con puntuación CVSS 9.8, representa riesgo crítico para tiendas de comercio electrónico, portales corporativos y sistemas de contenido.
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica de carga arbitraria de archivos en plugin ProSolution WP Client para WordPress
El plugin ProSolution WP Client para WordPress (versiones hasta 2.0.10) permite a atacantes cargar archivos arbitrarios explotando validación insuficiente en la función proSol_handleFileUpload. La vulnerabilidad reside en la falta de validación del encabezado Content-Disposition, que puede sobrescribir nombres de archivo permitidos. Con CVSS 9.8, afecta directamente a sitios empresariales, e-commerce y portales de clientes en LATAM que utilicen este plugin.
M Crítico vulnerabilidad
16/08/2026
Vulnerabilidad crítica en plugin ProSolution WP Client permite eliminación arbitraria de archivos
El plugin ProSolution WP Client para WordPress (versiones ≤2.0.8) contiene una falla de validación de rutas que permite a atacantes no autenticados eliminar archivos arbitrarios del servidor. Esta vulnerabilidad puede ser explotada para ejecutar código remoto eliminando archivos críticos de WordPress, comprometiendo completamente el sitio web. Afecta directamente a pequeñas y medianas empresas en LATAM que utilizan este plugin en plataformas de comercio electrónico y gestión de contenidos.
M Crítico vulnerabilidad
16/08/2026
[CVE-2026-19924] A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability…
A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of the component httpd. The manipulation leads to improper authentication. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73052] SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them d…
SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the sort menu. Attackers can inject markup by renaming a database field to execute arbitrary JavaScript when users open the sort menu, with Node integration enabled in the desktop client enabling code execution.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73053] SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji func…
SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch output. Attackers can craft document icons with hex-encoded markup that executes in the renderer with Node integration enabled, achieving arbitrary code execution on the host system.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73042] SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing…
SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open group, view, or field-edit menus. Attackers can inject markup through field descriptions or names that close containing elements and execute arbitrary code via event handlers, reaching Node built-ins due to Electron's insecure configuration.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73043] SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculat…
SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go templates and stores output verbatim without sanitization. Attackers can inject malicious HTML and JavaScript into template calculations that execute in the desktop client renderer with Node integration enabled, allowing arbitrary code execution when the …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73044] SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored …
SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attributes. Attackers can inject malicious payloads through the setAttrViewColWidth API that break out of style attributes and inject event handlers on every table cell, executing arbitrary code in the Electron renderer with Node integration enabled.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73046] SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middl…
SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, which guards nearly the entire /api/* surface, accepts the workspace access code (Conf.AccessAuthCode) as the Basic Auth password but never consults the CAPTCHA/lockout gate or increments the failure counter used by the cookie/session login path. This all…
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73050] SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select op…
SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting through eight unescaped render sites. Attackers can inject event-handler attributes by including quotation marks in the color value, executing arbitrary JavaScript when viewing databases containing the malicious select field.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-73041] SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the se…
SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject malicious markup into annotation fields that execute as script in the PDF renderer with full Node.js access when a user opens an annotated PDF.
M Crítico vulnerabilidad
15/08/2026
[CVE-2026-18855] The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient f…
The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). E…