Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Crítico vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-93933] Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object …
Deserialization of Untrusted Data vulnerability in ThemeREX Group Rosalinda rosalinda allows Object Injection.This issue affects Rosalinda: from n/a through 1.2.4.
M Crítico vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-93934] Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Inje…
Deserialization of Untrusted Data vulnerability in ThemeREX Group Partiso partiso allows Object Injection.This issue affects Partiso: from n/a through 1.1.13.
M Crítico vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-93935] Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Objec…
Deserialization of Untrusted Data vulnerability in ThemeREX Group Let's Play playhockey allows Object Injection.This issue affects Let's Play: from n/a through 1.1.15.
M Crítico vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-104803] The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, …
The WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerability exists because the `login` function's social-login flow performs no nonce validation, no OAuth state verification, and no per-visitor namespace isolation i…
M Crítico vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-62045] Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Objec…
Deserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0.
M Crítico vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-62046] Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object …
Deserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12.
M Crítico vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-104801] The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbi…
The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the rename_files function in all versions up to, and including, 34.0.10 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad Nuevo
Hace 13 horas
[CVE-2026-97670] The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all version…
The Avada (Fusion) Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16.1. This is due to the plugin not properly verifying authorization before dispatching a WordPress action hook whose name is taken from an attacker-supplied form-field value (via the notification email_message [field] placeholder and the {action_hook,...} dynamic-data toke…
M Crítico vulnerabilidad Nuevo
Hace 13 horas
[CVE-2026-103889] The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execut…
The 3D Product configurator for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.16.2 via the 'xpv_image' parameter parameter. This is due to missing authentication and nonce checks on the wp_loaded handler combined with no sanitization of the xpv_image POST parameter before it is echoed unescaped into a Dompdf-rendered HTML template w…
M Crítico vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-94589] The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for Word…
The Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection) plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.4.5 via the extcf7_submit function. This is due to missing file extension, MIME type, and size validation in the signature field's validation_filter(), combined with the absence of PHP-execution guards in the upload…
M Crítico vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-107645] The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, …
The Blocksy Companion plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.1.58 This is due to the implement_user_registration() AJAX handler explicitly disabling Dokan's vendor-registration nonce check (via add_filter('dokan_register_nonce_check', '__return_false')) and then trusting an attacker-supplied $_POST['role'] value when invoking wc_create_new_cu…
M Crítico vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-104732] The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions …
The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed `user_id`; compoun…
M Crítico vulnerabilidad Nuevo
Hace 18 horas
[CVE-2026-108474] In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of sever…
In JetBrains Exposed before 1.5.1 sQL injection was possible via unescaped string arguments of several SQL functions
M Crítico vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-108261] Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /…
Tina is a headless content management system. Prior to tinacms 3.14.0 and @tinacms/app 2.5.14, the /~/* admin preview route in packages/tinacms/src/admin/index.tsx can turn an attacker-controlled hash-router splat into an off-origin iframe URL through packages/@tinacms/app/src/preview.tsx, while packages/@tinacms/app/src/lib/preview-origin.ts derives expectedOrigin from that same URL for the Graph…
M Crítico vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-108263] Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the…
Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow code-node path through /console-api/workflow/code/run and /workflow/v1/run selects LocalExecutor in core/workflow/engine/nodes/code/code_node.py when CODE_EXEC_TYPE is not explicitly changed. LocalExecutor supplies complete Python builtins to dynamic code execution without the docu…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-108264] Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other medi…
Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py in the application's non-sandboxed Jinja2 environment with application globals exposed. An authenticated user able to create steps, or an administrator …
M Crítico vulnerabilidad Nuevo
Hace 22 horas
[CVE-2026-107845] Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor…
Contao is an Open Source CMS. From version 4.0.0 until 5.3.50 and 5.7.12, an unauthenticated visitor can submit a comment whose email or website metadata is rendered without sufficient attribute and URL encoding by listComments() in comments-bundle/contao/dca/tl_comments.php. When a backend user opens the Comments module, attacker-controlled script can execute in the Contao backend origin under th…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-15340] lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-108109] PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password res…
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-108107] PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.p…
PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.