Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1815
Esta semana
RSS
M Alto vulnerabilidad
08/07/2026
[CVE-2026-56250] Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field…
Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, enabling retargeting to arbitrary R2 bundle objects. Attackers can patch r2_path to point to victim objects, soft-delete the attacker-controlled version, and trigger the on_version_update cleanup function to delete the victim R2 object, causing denial of service and bundle availa…
M Alto vulnerabilidad
08/07/2026
[CVE-2026-5356] The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerab…
The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 5.4.0. This is due to the plugin's Stripe Connect payment processor accepting a client-supplied PaymentIntent ID. This makes it possible for unauthenticated attackers to pay an arbitrary amount by supplying a previously succeeded …
M Crítico vulnerabilidad
08/07/2026
[CVE-2026-12153] The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up t…
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository on the vulnerable site.
M Alto vulnerabilidad
07/07/2026
[CVE-2026-59704] Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning pri…
Cap's GET /api/video/ai endpoint fails to validate user ownership or membership before returning private video AI metadata including titles, summaries, and chapters. Authenticated attackers can supply arbitrary video IDs to read sensitive AI-generated content and trigger unauthorized AI generation that consumes the video owner's credits without consent.
M Crítico vulnerabilidad
07/07/2026
[CVE-2026-58473] Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated at…
Cognee before 1.2.0 contains an improper access control vulnerability that allows unauthenticated attackers to overwrite the global LLM provider configuration by self-registering an account and calling the settings endpoint, which performs no admin or superuser check. Attackers can redirect all LLM operations instance-wide to an attacker-controlled endpoint by exploiting the process-wide singleton…
M Alto vulnerabilidad
07/07/2026
[CVE-2026-59708] The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without…
The GET /api/v1/public/:accessId/portfolio endpoint in ghostfolio accepts private access IDs without validating granteeUserId filtering, allowing unauthenticated access to full portfolio data. Attackers with a private access ID can retrieve sensitive portfolio information including holdings, quantities, buy prices, and performance metrics without authentication.
M Alto vulnerabilidad
07/07/2026
[CVE-2026-11340] Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Pr…
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: before release.Master.1107.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
07/07/2026
[CVE-2026-8377] Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control Syste…
Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue affects Access Control System (GKS): before Version 2.
M Crítico vulnerabilidad
07/07/2026
[CVE-2026-34048] Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. …
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket bootstrap routes only check authentication and do not enforce terminal authorization, allowing a low-privileged team member to connect to terminal routes and execute commands on team servers. This issue is fixed in version 4.0.0-beta.471.
M Alto vulnerabilidad
05/07/2026
[CVE-2026-6509] Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardu…
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Update allows Privilege Escalation. This issue affects Pardus Update: from
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27771] Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package s…
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-25038] Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14460] Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardu…
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57746] Subscriber Broken Access Control in Booked <= 3.0.0 versions.
Subscriber Broken Access Control in Booked
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57688] Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
Unauthenticated Broken Access Control in POS Entegratör

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/07/2026
[CVE-2026-39448] Unauthenticated Broken Access Control in NOWPayments for WooCommerce <= 1.4.0 versions.
Unauthenticated Broken Access Control in NOWPayments for WooCommerce
M Alto vulnerabilidad
02/07/2026
[CVE-2025-69134] Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 version…
Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper
M Crítico vulnerabilidad
01/07/2026
[CVE-2026-23537] A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that all…
A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write arbitrary JSON files to the server's filesystem. Although the system attempts to restrict file locations, these protections can be bypassed, enabling an attacker to overwrite vital application configurations or startup scripts. Because this flaw requir…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-1239] The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to…
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to unauthorized access of data due to a missing authorization check on the 'ninja-forms-views/token/refresh' REST callback in all versions up to, and including, 3.14.1. This makes it possible for unauthenticated attackers to view form submissions, which could potentially contain sensitive information.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-13468] The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerab…
The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to access and export the contents of any visualizer chart on the site — includ…