Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71316] Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:n…
Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for //_payload.json can be returned before route middleware and page guards because import.meta.prerender is not enforced, disclosing another user's SSR data. This issue is fixed in 4.5.1.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-70617] Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any…
Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbitrary group DM channels by sending a PUT request to the channels recipient endpoint without membership verification. Attackers can exploit the unguarded PUT /channels/{channel_id}/recipients/{user_id} handler to join private group DMs, read complete m…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-48168] PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Acti…
PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation. Additionally, the workflow allows any @claude comment to trigger the job regardless of whether the commenter is a trusted collaborat…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-17613] Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowin…
Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files on the target server and subscribe to WebSocket events, enabling full data exfiltration and data poisoning.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-7529] The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthori…
The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to every one of its REST API endpoints being registered with `permission_callback => '__return_true'` in all versions up to, and including, 1.1.16. This makes it possible for unauthenticated attackers to read and modify the plugin's banner, stockbar, and c…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71264] WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson() with no setti…
WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson() with no settings-PIN check, unlike the /edit endpoint which explicitly checks correctPIN, disclosing the device's general configuration (network, hardware, LED setup) to any unauthenticated client on the network. Separately, the settings-PIN unlock state is tracked via a single global boolean `correctPIN` (wled0…
M Alto vulnerabilidad
05/08/2026
Vulnerabilidad alta en toner-management: ejecución de operaciones sin autenticación
Los manejadores de cambio de estado en toner-management (add.php, edit.php, delete.php) ejecutan operaciones de base de datos sin validación de autenticación ni autorización. Un atacante remoto no autenticado puede invocar directamente estos handlers para modificar, eliminar o crear registros de tóners, marcas y impresoras, comprometiendo la integridad de sistemas de gestión de suministros en empresas latinoamericanas. El CVSS 8.2 refleja el alto riesgo de manipulación de datos altas.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-7520] The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of …
The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `sign_in()` and `sign_up()` AJAX handlers in all versions up to, and including, 3.2.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to relink the site's MailMunch integration to an attacker-controlled MailMu…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-6627] The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unautho…
The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment credentials in all versions up to, and including, 1.1.1. This is due to missing capability checks and nonce verification on the `wpf_stripe_callback_success()` and `wpf_stripe_disconnect()` functions, both hooked to `admin_init`. The `admin_init` hoo…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-6639] The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Informa…
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without authentication or authorization checks. The method is not included in the workspace controller's `getNoncedMethods()` array, t…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-6079] The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of…
The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd_ajax_target_task_manager() function in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to enumerate all scheduled tasks (potentially exposing PII), execute arbitrary tasks, and delete any task via the p…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-5581] The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary me…
The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including, 1.1.8. This is due to missing capability checks in the `plupload_ajax_delete_file()` function, which is registered via `wp_ajax_nopriv_gfmu_delete_file`. The nonce intended for CSRF protection is exposed on any public-facing page containing a multi-…
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-4431] The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due…
The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_post()` function in all versions up to, and including, 2.3.0. This is due to the `rbsm_submit_post` AJAX action being registered for unauthenticated users via `wp_ajax_nopriv_rbsm_submit_post` without any authorization checks when a `postId` parameter is…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-54418] Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecre…
Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with no ownership check, session pinning, or permission-attribute gate (unlike other RPC-exposed methods in the same dispatcher). Any authenticated user can invoke getSetupData with an arbitrary userId to read that u…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-12000] The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure i…
The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the WordPress core REST endpoints /wp-json/wp/v2/pages, /wp-json/wp/v2/pages/, /wp-json/wp/v2/posts, and /wp-json/wp/v2/posts/. This is due to the plugin's REST guards — papr_restrict_page_post_rest_api() and the the_posts filter registered by papr_fi…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-16605] The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its…
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-16561] The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in on…
The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated users to retrieve the comments of images belonging to private, password-protected or otherwise access-restricted galleries.
M Alto vulnerabilidad
05/08/2026
[CVE-2026-8761] The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl…
The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `CustomersController` REST controller (`includes/REST/CustomersController.php`), which re-registers WooCommerce's customer CRUD routes under the `/dokan/v1/customers/` namespace and replaces WooCommerce's native `manage_woocommerce` c…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-70619] Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authentica…
Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint management routes that verify session authentication but omit the admin authorization guard. Attackers can supply an attacker-controlled URL to overwrite the embedding backend persisted in the endpoint con…
M Alto vulnerabilidad
04/08/2026
[CVE-2026-70494] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 un…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted write access to a shared chat folder to permanently delete chats and messages belonging to the folder owner. The cascade following the authorization check is bound to the folder owner'…