Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1856
Esta semana
RSS
M Alto vulnerabilidad
31/07/2026
[CVE-2026-18358] A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is …
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP listener. This can accumulate accepted sockets and pending routing-token operations …
M Alto vulnerabilidad
31/07/2026
[CVE-2026-62391] The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server…
The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-side config kyuubi.session.local.dir.allowlist via unprefixed Spark config aliases. This issue affects Apache Kyuubi: from 1.6.0 before 1.12.0. Users are recommended to upgrade to version 1.12.0, which fixes the issue.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-16843] Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insuf…
Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-11770] A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search …
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication …
M Alto vulnerabilidad
31/07/2026
[CVE-2026-15722] A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_fro…
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a repl…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-10079] A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubern…
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the workload as having empty UID, name and labels and namespace "default". This bypas…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-65313] A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations …
A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because the same credential is applied to every workstation provisioned this way, an attacker with adjacent-network access who knows the password can gain VNC access to affected workstations.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
31/07/2026
[CVE-2026-65310] ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes …
ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any authentication and permissive CORS on every response. An unauthenticated attacker with network access can read live process values and server configuration.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-65309] ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords usi…
ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way password hash. This allows an attacker able to read the credential store or capture network traffic to recover all stored passwords.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-15258] The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise a…
The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before using them in a SQL query, allowing users with the Contributor role and above to perform SQL injection attacks.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-16236] The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up …
The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing file extension and content validation in the saveLiveImages() function combined with an insufficient authorization check on the get_keys() AJAX handler and a missing authentication check on the REST API import endpoint. This makes it possible for auth…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-14930] The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or owners…
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-15048] The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its A…
The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to retrieve chat-history session metadata including WordPress usernames, user IDs, and timestamps.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-14830] The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout …
The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the associated order as paid, allowing unauthenticated attackers to complete WooCommerce orders without paying.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-12721] The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from t…
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
31/07/2026
[CVE-2026-13392] The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget d…
The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before 3.10.01 subsequently executes, allowing arbitrary PHP code to run on the server; on a multisite network this lets a non-supe…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-13609] The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted…
The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which restores HTML tags that the sanitizer had neutralized. A double-encoded payload submitted by an unauthenticated visitor is therefore stored as a live tag and later output without escaping on the Frontend Admin by DynamiApps WordPress plugin before 3.29.9'…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-14319] The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint …
The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing unauthenticated users to retrieve information about anonymous recurring donors, including their name and subscription details.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-14333] The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessibl…
The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and without access protection, allowing unauthenticated attackers to download complete backups including the site database and its user password hashes.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-12251] The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities…
The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its registration forms, and its post-registration safeguard against elevated accounts is disabled by default, allowing unauthenticated users to register with a site-defined role that carries administrator capabilities and gain administrative access, when such a…