Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "X" — 10687 resultados ✕ Limpiar búsqueda
14,391
Total alertas
3276
Críticas
10807
Altas
8
Ransomware
1043
Esta semana
RSS
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63685] Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator r…
Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causing major data corruption or site compromise.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-64791] Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular La…
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-64792] Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Re…
Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors.
M Crítico vulnerabilidad
22/07/2026
[CVE-2026-64793] Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and …
Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access.
M Crítico vulnerabilidad
22/07/2026
[CVE-2026-64796] Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free di…
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured inc…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-64797] Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trus…
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
M Crítico vulnerabilidad
22/07/2026
[CVE-2026-64798] Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL …
Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63265] Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Re…
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations out…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63280] Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular La…
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63683] Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions man…
Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.
M Alto vulnerabilidad
22/07/2026
[CVE-2025-60835] An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
M Alto vulnerabilidad
22/07/2026
[CVE-2025-44090] An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and…
An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
M Alto vulnerabilidad
22/07/2026
[CVE-2025-50324] An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary co…
An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.
M Alto vulnerabilidad
22/07/2026
[CVE-2025-50327] An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privile…
An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism
M Crítico vulnerabilidad
22/07/2026
[CVE-2025-50329] An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate…
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/07/2026
[CVE-2025-50330] An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate pr…
An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.
M Alto vulnerabilidad
22/07/2026
[CVE-2025-44089] An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloadin…
An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-64829] Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers wi…
Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php. While the normal password-change flow in qa-include/pages/account.php explicitly clears the sessioncode t…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-14899] The code to parse MIME headers for display when forwarding a message (if the setting to view all hea…
The code to parse MIME headers for display when forwarding a message (if the setting to view all headers was enabled) had an off-by-one error, allowing a single byte to be read from the memory after the buffer for the headers, and potentially crashing Thunderbird. This vulnerability was fixed in Thunderbird 153 and Thunderbird 140.13.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13077] A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out…
A missing bounds check in the BSON CodeWScope element accessors allows an attacker to trigger an out-of-bounds heap read via a crafted aggregation pipeline. The vulnerability can be exploited by an authenticated user by generating a malformed BSONColumn data containing a CodeWScope element, bypassing wire-level BSON validation. When the forged element is decompressed, the unchecked size value is u…