Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 10500 resultados ✕ Limpiar búsqueda
14,078
Total alertas
3213
Críticas
10592
Altas
8
Ransomware
1069
Esta semana
RSS
M Alto vulnerabilidad
06/08/2026
[CVE-2026-11803] A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read …
A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
M Crítico vulnerabilidad
06/08/2026
[CVE-2025-14561] In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. Thi…
In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing sufficient privileges to invoke these APIs, to perform operations that impact other tenants. The vulnerability allows a privileged user to perform publisher operations such as exposing or modifying API Metadata in another tenant environment. This impact is …
M Alto vulnerabilidad
06/08/2026
[CVE-2026-53977] OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remot…
OpenChamber 1.11.7 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to terminate the server process by sending a POST request to the /api/system/shutdown endpoint, which is registered before the authentication middleware in the Express route handler chain. Attackers can exploit the route registration order in bootstrap-runtime.js to reach the shutdown ha…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18277] Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 2…
Missing authorization in the OcrModelRight create and delete views in Scripta eScriptorium through 26.04.1 allows a remote authenticated user to grant themselves access to another user's private OCR model and to revoke any user's OCR model access via a POST request, because the ownership check is placed in get_context_data() and therefore runs only on the GET rendering path
M Alto vulnerabilidad
06/08/2026
[CVE-2026-18427] @fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. …
@fastify/static before version 10.1.3 contains an incomplete fix for a previous route guard bypass. The static file handler rejected only parent directory segments, but it did not canonicalize dot segments, duplicate slashes, encoded dots, or backslashes before route matching and before delegating to the send layer. As a result, an unauthenticated attacker could request a file protected by a route…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70646] aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHand…
aiosend is a synchronous and asynchronous Crypto Pay API client. Pror to version 3.0.7, `WebhookHandler.feed_update()` deserializes the entire request body before verifying the HMAC signature. This allows an unauthenticated attacker to force expensive parsing of arbitrary JSON payloads that will ultimately be rejected, leading to unnecessary CPU and memory consumption. Version 3.0.7 fixes the issu…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66711] Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency <= 5.5.6 versions.
Subscriber Cross Site Scripting (XSS) in WooCommerce Multilingual & Multicurrency

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-67261] Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a…
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI component. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying operating system with root privileges. Exploitation may lead to a complete sys…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66702] Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO <= 1.0.274.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Rank Math SEO
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66705] Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress <= 5.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WordPress
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66707] Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce <= 3.7.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Facebook for WooCommerce
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-66709] Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.
Shop manager Remote Code Execution (RCE) in CTX Feed
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66690] Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.5 versions.
Unauthenticated Cross Site Scripting (XSS) in GiveWP
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66694] Unauthenticated Cross Site Scripting (XSS) in Thrive Architect <= 10.9.3.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Thrive Architect
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66664] Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66440] Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions.
Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66457] Unauthenticated Cross Site Scripting (XSS) in Events Manager <= 7.4.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Events Manager
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66663] Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Data Access
M Alto vulnerabilidad
06/08/2026
[CVE-2026-66439] Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters <= 3.2.0.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Advanced AJAX Product Filters
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65560] Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed <= 2.5.48 versions.
Unauthenticated Cross Site Scripting (XSS) in Houzez Property Feed