Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Perl" — 131 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1002
Esta semana
RSS
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-72839] filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is ena…
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing unrestricted access to all files.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-72841] luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowin…
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code execution by placing SSH keys in system directories accessible on reboot.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-16770] PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in…
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file source, the constructor collects every element in the document head through _pdf_webkit_meta_tags and turns each one into a wkhtmltopdf command line option. KEY is normalized to an option name matching --[…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-63294] A link following vulnerability in LXD allows an attacker to achieve root command execution on the ho…
A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of crafted image or backup archives, LXD fails to properly validate and confine the backup.yaml file when it exists as a symbolic link. An attacker can exploit this flaw by providing a malicious archive with a symlinked backup.yaml file, causing LXD to proce…
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-18366] The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, di…
The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress already made for unrelated privileged actions, which allows unauthenticated users to change the password of, escalate to Administrator, or delete any account whose user ID happens to match the ID of one of the Events Manager WordPress plugin before 7.…
M Crítico vulnerabilidad
11/08/2026
[CVE-2026-48056] Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions p…
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.
M Crítico vulnerabilidad
10/08/2026
[CVE-2026-18948] A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored i…
A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'dill' library. This allows a remote attacker to store a malicious UDF, leading to unauthenticated arbitrary code execution on the feature server in default configurations. An authenticated attacker can also achieve arbitrary code execution on the regis…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
08/08/2026
Plugin AI Copilot – Content Generator para WordPress vulnerable a bypass de autorización
El plugin AI Copilot – Content Generator en WordPress (versiones hasta 1.5.6) presenta una vulnerabilidad crítica de bypass de autorización (CVSS 9.8) que permite a atacantes no autenticados crear cuentas de administrador y comprometer completamente el sitio web. Esta vulnerabilidad afecta especialmente a empresas en LATAM que utilizan WordPress para presencia digital y e-commerce.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de takeover de cuentas en plugin TrueBooker para WordPress (CVE-2026-14364)
El plugin TrueBooker para WordPress (versiones hasta 1.2.3) permite a atacantes no autenticados resetear contraseñas de usuarios arbitrarios mediante validación insuficiente de identidad. Afecta directamente a sitios de servicios (salones, clínicas, agencias) en LATAM que usan este plugin para reservas. Un atacante podría acceder a cuentas administrativas y comprometer datos de clientes.
M Crítico vulnerabilidad
07/08/2026
Vulnerabilidad crítica de omisión de autenticación en plugin TrueBooker para WordPress
El plugin TrueBooker – Appointment Booking and Scheduler System para WordPress contiene una falla de autorización que permite a atacantes no autenticados cambiar contraseñas de cuentas administrativas en versiones hasta la 1.2.3. Esta vulnerabilidad afecta principalmente a pequeñas y medianas empresas en LATAM que utilizan WordPress para gestión de citas y reservas, exponiendo el control total de sus sitios web.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-12713] The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a para…
The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks. This affects a code path distinct from the one addressed by CVE-2024-44004.
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-15360] The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter …
The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated attackers to perform time-based blind SQL injection and extract sensitive data from the database.
M Crítico vulnerabilidad
04/08/2026
[CVE-2026-16618] The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking …
The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file with the attacker-supplied extension into a publicly accessible directory, allowing unauthenticated users to upload executable PHP files and achieve remote code execution.
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-9487] XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml()…
XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolves the SignedInfo Reference/@URI to a node with the XPath expression "//*[@ID='$id']" and returns the first node of the resulting node set. A document in which two elements share that ID value is accepted: the digest and signature are checked against w…
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-9390] XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed…
XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions by concatenating the SignedInfo/Reference/@URI value read from the document being verified. The value is neither escaped nor checked against the NCName grammar that XML requires of an ID, so a URI containing a single quote closes the string literal in…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-18108] Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_asser…
Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature. _verify_encrypted_assertion decrypts the EncryptedAssertion and returns it as verified when it carries no signature, via "return $xml unless $xpath->exists('dsig:Signature', $assert);". The signature check and the trus…
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-16300] The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, all…
The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
M Crítico vulnerabilidad
03/08/2026
[CVE-2026-16532] The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied…
The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
M Crítico vulnerabilidad
31/07/2026
[CVE-2026-14919] The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting tes…
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.
M Crítico vulnerabilidad
29/07/2026
[CVE-2026-16326] In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless…
In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authentication token to be used for subsequent requests from other clients. This vulnerability (CVE-2026-16326) is fixed in consul-mcp-server 0.1.4.