Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-94160] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeStek ThemeStek Extras for LabtechCO Theme themestek-labtechco-extras allows Reflected XSS.This issue affects ThemeStek Extras for LabtechCO Theme: from n/a through 8.4.
M Crítico vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-105889] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tickera Tickera tickera-event-ticketing-system allows Blind SQL Injection.This issue affects Tickera: from n/a through 3.6.0.6.
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-106608] Incorrect Privilege Assignment vulnerability in Automattic WooCommerce woocommerce allows Privilege …
Incorrect Privilege Assignment vulnerability in Automattic WooCommerce woocommerce allows Privilege Escalation.This issue affects WooCommerce: from 9.8.0 through 11.1.2.
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-106609] Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiti…
Missing Authorization vulnerability in Web Impian Bayarcash WooCommerce bayarcash-wc allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bayarcash WooCommerce: from n/a through 4.4.2.
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-62044] Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player al…
Deserialization of Untrusted Data vulnerability in bPlugins Super Video Player super-video-player allows Object Injection.This issue affects Super Video Player: from n/a through 1.8.13.
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-103071] Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page…
Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Code Injection.This issue affects Thank You Page Customizer for WooCommerce: from n/a through 1.2.3.
M Crítico vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-104398] Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooComm…
Deserialization of Untrusted Data vulnerability in VillaTheme AFFI – Affiliate Marketing for WooCommerce affi-affiliate-marketing-for-woo allows Object Injection.This issue affects AFFI – Affiliate Marketing for WooCommerce: from n/a through 1.0.10.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-108550] SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and …
SkillHub before 0.2.22 contains an incorrect authorization vulnerability in AccountMergeService and AccountMergeController that allows authenticated attackers to take over other accounts by abusing the merge flow. Attackers can call the merge initiate endpoint with a target username or OAuth identity, receive the verification token directly, and confirm the merge to inherit the victim's API tokens…
M Crítico vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-108551] openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attack…
openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers can embed a single quote in path keys, parameter names, servers[0].url, or info.version to execute arbitrary JavaScript when generated clients are importe…
M Alto vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-108553] OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows comman…
OpenRefine through 3.10.1 contains a cross-site request forgery vulnerability in the get-rows command that allows remote attackers to execute Jython facet expressions. Attackers can lure a user to a malicious page issuing a cross-origin GET with a crafted engine parameter, executing operating system commands as the OpenRefine user.
M Alto vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-108546] Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler t…
Spotweb through 1.5.8 contains an OS command injection vulnerability in the runcommand NZB handler that allows remote attackers to execute commands by publishing spots with malicious titles. Attackers can post self-signed spots over Usenet with shell metacharacters in the title, which are substituted unescaped for $SPOTTITLE and passed to exec() when a user downloads the spot, running commands as …
M Alto vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-108548] AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's a…
AstronRPA through 1.1.6 contains an authentication bypass vulnerability in the OpenResty gateway's auth_handler.lua that accepts any Bearer token without validation. Unauthenticated attackers can send arbitrary Bearer values to reach /api/resource/ and /api/rpa-ai-service/ routes and spoof X-User-Id or user_id headers to act as any user.
M Alto vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-108549] cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter…
cc-connect through 1.5.0 contains a missing authentication vulnerability in the MAX platform adapter webhook mode in platform/max/max.go that accepts unauthenticated updates when no webhook_secret is configured. Remote attackers reaching the webhook listener on port 8080 can forge updates with an allowed or admin user_id to run privileged commands like /shell on the host.
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-94676] Deserialization of Untrusted Data vulnerability in Tainacan Community Tainacan tainacan allows Objec…
Deserialization of Untrusted Data vulnerability in Tainacan Community Tainacan tainacan allows Object Injection.This issue affects Tainacan: from n/a through 1.3.0.
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-97263] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows Stored XSS.This issue affects WPAdverts: from n/a through 2.3.4.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-97264] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPAdverts wpadverts allows Reflected XSS.This issue affects WPAdverts: from n/a through 2.3.4.
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-105885] Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Inj…
Deserialization of Untrusted Data vulnerability in 10Web Slider by 10Web slider-wd allows Object Injection.This issue affects Slider by 10Web: from n/a through 1.2.62.
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-108161] FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download(…
FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a priv…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-102388] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPMU DEV Forminator forminator allows Stored XSS.This issue affects Forminator: from n/a through 1.57.3.
M Alto vulnerabilidad Nuevo
Hace 7 horas
Vulnerabilidad alta de lectura arbitraria de archivos en plugin Divi Plus para WordPress
El plugin Divi Plus para WordPress (versiones hasta 2.4.0) permite a atacantes sin autenticación leer archivos arbitrarios del servidor mediante el parámetro 'svg_image' en el endpoint REST /wp-json/elicus/v1/dipl-modules/svg-animator. La vulnerabilidad existe porque el controlador de permisos valida de forma insuficiente la entrada, exponiendo datos sensibles en sitios WordPress de empresas y gobierno en LATAM.