Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1856
Esta semana
RSS
M Alto vulnerabilidad
06/08/2026
[CVE-2026-61982] Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.
Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65504] Unauthenticated Broken Access Control in BOX NOW Delivery Croatia <= 3.3.0 versions.
Unauthenticated Broken Access Control in BOX NOW Delivery Croatia
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-65507] Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions.
Unauthenticated Privilege Escalation in AIWU
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-65508] Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.
Unauthenticated SQL Injection in Simply Schedule Appointments
M Alto vulnerabilidad
06/08/2026
[CVE-2026-61961] Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.
Unauthenticated Cross Site Scripting (XSS) in EmbedPress
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-54489] Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a…
Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure and session hijacking. This vulnerability is considered critical as it allows an unauthenticated attacker to obtain active session crede…
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-53975] OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remot…
OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands by sending crafted POST requests to the /api/fs/exec endpoint, which passes commands verbatim to Node.js spawn() without any allowlist, blocklist, or argument validation. The authentication middleware becomes a no-op when UI_PASSWORD is not configured,…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-53976] OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/rea…
OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unauthenticated remote attackers to read arbitrary files by supplying the allowOutsideWorkspace=true query parameter alongside an absolute path, bypassing the workspace boundary check in resolveReadPathFromContext. Attackers can exploit the vacuous isPath…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28183] Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
Editor Privilege Escalation in PublishPress Capabilities
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-32327] A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library co…
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-34191] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
M Alto vulnerabilidad
06/08/2026
[CVE-2026-34501] Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issu…
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-34502] Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This i…
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28172] Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28177] Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Popup Maker

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28111] Contributor Privilege Escalation in Forminator <= 1.56.0 versions.
Contributor Privilege Escalation in Forminator
M Crítico vulnerabilidad
06/08/2026
[CVE-2026-28139] Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
Unauthenticated PHP Object Injection in Ajax Search Lite
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28140] Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.
Unauthenticated Broken Access Control in JetFormBuilder
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28141] Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery
M Alto vulnerabilidad
06/08/2026
[CVE-2026-28143] Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Forminator