Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 531 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
XSS no autenticado en Video Background Block (≤2.0.3) – CVSS 7.1
Vulnerabilidad de Cross-Site Scripting (XSS) sin autenticación en el plugin Video Background Block permite a atacantes inyectar código malicioso a través de la funcionalidad de video de fondo en secciones. Afecta versiones 2.0.3 y anteriores. El riesgo es alto para sitios WordPress en México y LATAM que usen este componente sin actualizar, exponiendo a robo de sesiones y datos de usuarios.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-42635] XSS sin autenticación en WooCommerce Simple Auctions <= 3.0.10
Vulnerabilidad de Cross Site Scripting (XSS) sin autenticación requerida en WooCommerce Simple Auctions afecta versiones hasta 3.0.10. Permite a atacantes inyectar código malicioso en tiendas de comercio electrónico, comprometiendo sesiones de clientes y administradores. Riesgo alta para plataformas de subastas basadas en WordPress en LATAM.
M Alto vulnerabilidad
Hace 4 días
XSS sin autenticación en WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.4.6
Una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación afecta el plugin WP Cookie Notice en versiones hasta 4.4.6, permitiendo a atacantes inyectar código malicioso que se ejecuta en navegadores de visitantes. El riesgo es alta para sitios WordPress en México y LATAM que dependen de este plugin para cumplir normativas de privacidad (GDPR, CCPA, ePrivacy), pudiendo comprometer datos de usuarios y credibilidad organizacional.
M Alto vulnerabilidad
Hace 4 días
Control de acceso roto sin autenticación en Easy Digital Downloads versiones ≤ 3.7.1
Easy Digital Downloads, plugin de WordPress ampliamente usado en LATAM para venta de contenido digital, presenta una vulnerabilidad alta de control de acceso que permite a atacantes no autenticados acceder a funcionalidades restringidas. Esta falla afecta principalmente a tiendas digitales y plataformas de distribución de contenido en México y Latinoamérica que dependen de este plugin para gestionar transacciones y datos sensibles.
M Alto vulnerabilidad
Hace 4 días
Escalada de privilegios en PublishPress Capabilities permite asignación incorrecta de permisos
Una vulnerabilidad de asignación incorrecta de privilegios (CVE-2026-48197, CVSS 7.2) afecta PublishPress Capabilities hasta la versión 2.45.0, permitiendo que usuarios no autorizados escalen sus permisos dentro de sitios WordPress. Este riesgo es alta para empresas en LATAM que dependen de WordPress para gestión de contenidos y requieren control granular de accesos. La explotación podría comprometer la integridad editorial y el acceso a datos sensibles.
M Alto vulnerabilidad
Hace 4 días
Exposición de datos sensibles sin autenticación en Norvis Backup versiones ≤ 1.1.0
Norvis Backup en versiones 1.1.0 y anteriores permite acceso no autenticado a datos sensibles, exponiendo información alta de respaldos sin requerir credenciales de acceso. Esta vulnerabilidad afecta directamente a empresas en México y LATAM que dependen de esta solución para proteger datos corporativos, comprometiendo la confidencialidad de información de clientes y operaciones.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105071] Unauthenticated Sensitive Data Exposure in SiteVault – Backup, Restore, Migration &amp; Cloning <= 1…
Unauthenticated Sensitive Data Exposure in SiteVault – Backup, Restore, Migration &amp; Cloning

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105807] A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an u…
A vulnerability was found in SourceCodester Simple Student Information System 1.0. This affects an unknown part of the file searchquery.php. Performing a manipulation results in sql injection. The attack can be initiated remotely.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-94293] An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH req…
An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-57537] Memory Corruption when accessing and modifying geographic mapping data concurrently without proper s…
Memory Corruption when accessing and modifying geographic mapping data concurrently without proper synchronization.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-25291] Memory corruption when performing concurrent operations on shared memory page lists due to lack of p…
Memory corruption when performing concurrent operations on shared memory page lists due to lack of proper synchronization mechanisms.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105776] A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to…
A flaw has been found in bhagya3929 Employee-Movement-Tracking-and-Monitoring-Website-for-IOCL up to ae783195ba7e0390d3b3bfaddd99944b7e9735a4. Affected by this vulnerability is an unknown functionality of the file /admin_transaction.php. This manipulation of the argument Username causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. T…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105778] A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unkno…
A vulnerability has been found in Tenda AC5 02.03.01.111_multi. Affected by this issue is some unknown functionality of the file /goform/setWifi of the component Wifi Handler. Such manipulation of the argument wifiPwd leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-25267] Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
Memory corruption when non-secure loader rewrites page tables before secure memory initialization.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-75962] The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP…
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-39723] Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.
Unauthenticated Broken Access Control in Morning for WooCommerce
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105704] A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unk…
A vulnerability was identified in SourceCodester Drug Recommendation System 1.0. This affects an unknown function of the component Auth Guard. Such manipulation of the argument user_id leads to improper authentication. The attack can be executed remotely. The exploit is publicly available and might be used.
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105484] A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted el…
A security vulnerability has been detected in TOTOLINK X6000R 9.4.0cu.652_B20230116. The impacted element is the function firmware_check of the file /cgi-bin/cstecgi.cgi of the component UploadFirmwareFile Handler. Such manipulation of the argument file_name leads to os command injection. The attack may be performed from remote.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105486] A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of t…
A vulnerability was detected in OSSRS srs up to 7.0-a1. This affects the function systemAPI.Run of the file internal/proxy/api.go of the component System API. Performing a manipulation results in missing authentication. It is possible to initiate the attack remotely. The exploit is now public and may be used. Upgrading to version 8.0-d0 mitigates this issue. The patch is named bb5fde228f4ca5bd26d9…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105571] A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function …
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early throu…