Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 5290 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-84819] Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in WPAdverts
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81796] Unauthenticated Broken Authentication in WP Travel <= 12.0.3 versions.
Unauthenticated Broken Authentication in WP Travel
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81799] Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce <= 4.6.4 version…
Unauthenticated Broken Access Control in Return Refund and Exchange For WooCommerce
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-81800] Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés) <= 2.4.6 versions.
Unauthenticated SQL Injection in Verified Reviews (Avis Vérifiés)
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81801] Subscriber Settings Change in WP-Stateless <= 4.4.1 versions.
Subscriber Settings Change in WP-Stateless
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81803] Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
Subscriber Remote Code Execution (RCE) in RepairBuddy
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81804] Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration <= 2.4.2 versi…
Unauthenticated Sensitive Data Exposure in ZHBackup – Backup, Restore &amp; Migration

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81805] Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.
Unauthenticated Privilege Escalation in SiteSkite
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81794] Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
Unauthenticated Broken Access Control in Shirt Product Designer for WooCommerce 1.0.4 versions.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81795] Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite <= 1.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Page Visits Counter &#8211; Lite
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81786] Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce <= 1.2.2 versions…
Unauthenticated Broken Access Control in Thank You Page Customizer for WooCommerce
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81789] Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce <= 3.1.6…
Unauthenticated Arbitrary File Deletion in Advanced Product Fields Extended for WooCommerce
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81783] Subscriber Broken Authentication in MailMunch – Grow your Email List <= 3.2.5 versions.
Subscriber Broken Authentication in MailMunch – Grow your Email List
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81784] Unauthenticated PHP Object Injection in Wise Chat <= 3.4 versions.
Unauthenticated PHP Object Injection in Wise Chat
M Alto vulnerabilidad
10/09/2026
[CVE-2026-46387] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 7.0.16 and 8.0.5, Suricata's HTTP/2 decompression path could grow the decompressed response-body buffer without an effective upper bound. A crafted HTTP/2 DATA payload using a high compression ratio, such as gzip, deflate, or brotli compressed data, could cause Su…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45747] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88889] Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that…
Renovate before 44.14.7 contains a command injection vulnerability in the Maven Wrapper manager that allows attackers to execute arbitrary commands by specifying a malicious distributionType parameter in maven-wrapper.properties. Attackers can inject shell commands through unescaped distributionType values to achieve remote code execution when Renovate processes Maven Wrapper updates in binarySour…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88890] OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter bui…
OpenPanel through commit cd24bb8 contains an SQL injection vulnerability in the analytics filter builder that fails to validate profile.* filter column identifiers before interpolating them into ClickHouse WHERE clauses. An authenticated attacker with project-scoped read or root export credentials can inject arbitrary ClickHouse SQL to bypass project isolation and read other organizations' analyti…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88891] OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing …
OpenPanel fails to enforce read-only project access level on 26 of 29 mutating procedures, allowing read-level members to modify, delete, and publish project data. Attackers with explicit read-only access can delete reports and dashboards, schedule entire projects for deletion, publish private analytics to public share links, and modify alerting rules by exploiting missing access level validation …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88893] OpenPanel share lookup procedures fail to validate access controls and return password hashes and pr…
OpenPanel share lookup procedures fail to validate access controls and return password hashes and protected report definitions to unauthenticated callers. Attackers with a share link can retrieve argon2id password hashes and full report configurations including event names, filters, and breakdown dimensions for offline password cracking and business intelligence theft.