Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1880
Esta semana
RSS
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73653] Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Br…
Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, takeScreenshot, screenshotMatcher, stopChunkTrace, deleteTracing, and annotateTraces accept browser-supplied file paths without enforcing the allowWrite permission gate or confining paths to the project root. A client that can reach the Browser Mode API…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73644] OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identi…
OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org/opends/server/extensions/PlainSASLMechanismHandler.java checked the PROXIED_AUTH privilege but did not evaluate the mayProxy proxy ACI scope when an authzid resolved to a different user. Both dn: and u: or bare authzid forms could therefore let an au…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73649] Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, t…
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constructor, __proto__, and prototype only in the #set assignment handler in src/compile/set.ts, while property-read expressions in src/compile/references.ts remained unfiltered. The getReferences() flow called getAttributes(), whose property access allowed…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73567] sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and …
sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.generateKeyPairHex() path in Node.js uses the module-wide SecureRandom instance in src/sm2/utils.js, supplied by jsbn@1.1.0, which seeds an ARC4 stream from Math.random() and new Date().getTime() because window.crypto.getRandomValues is unavailable ev…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-67614] CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SS…
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote attackers to forge valid authentication tokens and obtain an interactive root shell via WebSocket on port 8888. Attackers can craft a forged JWT signed with the hardcoded secret value, specifying ssh_user=root, to authenticate to the terminal service with…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73532] Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered p…
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploa…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-73533] Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered …
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administ…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-53791] rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated …
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed source IP in the PROXY protocol header to circumvent hosts allow/deny rules, gaining unauthorized a…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66691] Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.
Unauthenticated Broken Access Control in Nokri
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66472] Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.
Unauthenticated SQL Injection in Everest Backup
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66478] Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.
Unauthenticated SQL Injection in Church Admin
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66465] Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.
Unauthenticated Broken Authentication in Cartify
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66453] Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.
Unauthenticated Broken Authentication in Salon booking system
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66458] Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.
Unauthenticated SQL Injection in RealPress
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66436] Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.
Unauthenticated SQL Injection in Active Products Tables for WooCommerce

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66446] Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.
Subscriber SQL Injection in If-So Dynamic Content Personalization
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-66424] Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.
Unauthenticated Privilege Escalation in SMS Alert Order Notifications
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-61969] Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.
Unauthenticated SQL Injection in Listdom
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-61962] Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.
Unauthenticated Arbitrary Code Execution in WP BASE Booking
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-61966] Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.
Subscriber SQL Injection in WPJAM Basic