Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,928
Total alertas
3375
Críticas
11165
Altas
8
Ransomware
890
Esta semana
RSS
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-55247] plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iC…
plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in editor can make the server request internal network resources or local calendar fil…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-55108] KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until…
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones a repository supplied through a core.oam.dev/v1beta1 ComponentDefinition and follows repository-controlled variables.tf …
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-55065] Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api…
Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only against an attacker-controlled project identifier. ProjectView.CanDelete in pkg/models/project_view_permissions.go does not establish that the view belongs to the p…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-55066] Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/project…
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket.go authorizes only the project, view, and bucket from the URL. updateTaskBucket then calls Task.ReadOne without a separate task permission check, returns the vict…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-54745] Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. …
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function accepts an arbitrary attacker-controlled HTTP or HTTPS target and passes its o…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-54754] Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace s…
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, marketplace settlement in core/kapp/market/market.go reads MarketOrderData.ReferralPercentage from the listing while reading asset.Royalties.MarketPercentage live at purchase time. An asset owner can create a valid listing and then use AssetTrigger UpdateRoyalties to make the combined referral and royalty percen…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-54755] Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty…
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those values in uint32 accumulators. Crafted values such as two 0x80000000 entries wrap the validation sum to zero and pass CheckVa…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-54788] dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, da…
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in the Datadog dd=... vendor entry into a HashMap without enforcing a pair count or entry size limit. Because tracecontext extraction is enabled by default, …
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82227] Contributor SQL Injection in WPBulky <= 1.2.2 versions.
Contributor SQL Injection in WPBulky
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81757] Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Author Remote Code Execution (RCE) in Rank Math SEO
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81760] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81767] Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
Unauthenticated Broken Access Control in Simple Payment
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81285] Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versio…
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81019] wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is…
wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known reco…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81020] wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is s…
wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known record…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-6176] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti…
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review submissions from unauthenticated users through the 'cr_local_forms_submit' AJAX act…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-5934] The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a…
The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected p…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-56854] The source-address critical option in the Permissions returned by an authentication callback was onl…
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-50979] A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.…
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-38638] An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to caus…
An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.