Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 3587 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-77009] The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console,…
The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-4357] The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files vi…
The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.
M Crítico vulnerabilidad
02/09/2026
[CVE-2025-9314] The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload…
The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-73475] Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue…
Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica de XSS almacenado en SiYuan anterior a v3.8.2 permite robo de tokens API
SiYuan versiones anteriores a v3.8.2 contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en el servidor de activos debido a una lista de bloqueo de extensiones incompleta. Atacantes pueden cargar archivos con extensiones como .xht, .ehtml, .xsl, .xbl o .rdf que se resuelven como tipos de medios ejecutables, permitiendo ejecutar JavaScript para robar tokens API y comprometer espacios de trabajo. El CVSS de 9.0 indica severidad crítica con alto impacto en confidencialidad e integridad.
M Crítico vulnerabilidad
02/09/2026
Vulnerabilidad crítica en Craft CMS anterior a 5.10.11 permite escalación de privilegios
Craft CMS versiones anteriores a 5.10.11 no valida correctamente la bandera de administrador durante el registro de usuarios, permitiendo que atacantes hereden permisos administrativos registrándose con direcciones de correo de cuentas administrador desactivadas. Esta vulnerabilidad afecta especialmente a instancias con registro público habilitado y verificación de correo desactivada, exponiendo sistemas de gestión de contenidos en empresas mexicanas y latinoamericanas.
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-81286] Unauthenticated SQL Injection in WCFM Marketplace <= 3.8.1 versions.
Unauthenticated SQL Injection in WCFM Marketplace

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-81294] Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
Unauthenticated Privilege Escalation in Authorizer
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-78657] The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletio…
The SigmaForms Pro – AI Generated Forms plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_submission_files function in all versions up to, and including, 1.4.11. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted…
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-9055] The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerab…
The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 - 9.6.2. This is due to insufficient validation of the attacker-controlled 'type' parameter in the customer update endpoint, which allows customers to set their role to 'manager' and trigger creation of a WordPress user with the wpamelia-manager role when t…
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84699] Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local ac…
Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users to gain unauthorized access.
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84352] Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attac…
Use after free in WebGL in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84353] Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a …
Use after free in Shared Tab Groups in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84354] Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attac…
Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84333] Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attack…
Use after free in Dawn in Google Chrome on on Android prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84324] Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute…
Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High)
M Crítico vulnerabilidad
02/09/2026
[CVE-2026-84325] Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote a…
Improper input validation in DataTransfer in Google Chrome prior to 152.0.7977.75 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a co-installed app. (Chromium security severity: High)
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84479] WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely o…
WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. An attacker who submits valid credentials and sets User-Agent: AVideoEncoder bypasses two…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84480] WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, al…
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84372] Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 un…
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode("\r\n") instead of honoring RESP length prefixes. Attacker-controlled keys or values containing CRLF s…