Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
14,928
Total alertas
3375
Críticas
11165
Altas
8
Ransomware
865
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-27330] Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
Unauthenticated Broken Access Control in Mobile App for WooCommerce
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-32550] Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.
Subscriber SQL Injection in Kadence Shop Kit
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-32564] Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.
Subscriber SQL Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78137] The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on…
The StoreGrowth WordPress plugin before 2.1.2 does not validate a browser-supplied product price on two of its unauthenticated actions, allowing unauthenticated attackers to add a product to the cart at an arbitrary, attacker-chosen price that carries through to the checkout total when the BOGO offer feature is enabled.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-78333] The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submit…
The 12 Step Meeting List WordPress plugin before 3.19.17 does not sanitise and escape a value submitted by unauthenticated users before storing it in its activity log and outputting it back in an admin area page, leading to a Stored Cross-Site Scripting issue which could be used against high privilege users such as admin.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-77017] The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may s…
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor confine the stored file location to an allowed directory before serving it, allowing users with a role as low as subscriber to read arbitrary files on the server, including its configuration file and authentication secrets.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-77018] The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may s…
The Workeera WordPress plugin before 1.0.6 does not restrict which profile values a candidate may submit, nor validate the type of the file it subsequently writes into a publicly reachable directory, allowing users with a role as low as subscriber to upload arbitrary files and achieve remote code execution.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47886] Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulner…
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47888] A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framewo…
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47889] A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies with…
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47885] The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMe…
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47877] Spring Security Authorization Server's default consent page renders user-controlled values without H…
Spring Security Authorization Server's default consent page renders user-controlled values without HTML entity encoding. Spring Security 7.1.0 Spring Security 7.0.0 - 7.0.6
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47879] Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for d…
Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows arbitrary Spring Resource locations for defining the proto descriptor. Spring Cloud Gateway 5.0.0 - 5.0.2 Spring Cloud Gateway 4.3.0 - 4.3.5 Spring Cloud Gateway 4.0.0 - 4.2.9 Spring Cloud Gateway 3.1.13 and earlier
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47849] Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation …
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier
M Alto vulnerabilidad
27/08/2026
[CVE-2026-19715] The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access …
The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.3.1 does not restrict access to the debug log it writes, which is stored at a fixed and publicly reachable location, allowing unauthenticated users to read the OAuth tokens and authorisation codes it has issued as well as user records including password hashes when debug logging is enabled.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-19223] The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network adminis…
The Smush WordPress plugin before 4.3.2 does not restrict a network-wide setting to network administrators, allowing an administrator of any single site on a multisite network to execute arbitrary code across the entire network.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-13415] The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing se…
The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administra…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81491] A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_…
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has no…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81421] A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element i…
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem earl…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47851] Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in t…
Analyzing a PDF with a deeply nested or cyclic table of contents can cause a StackOverflowError in the ingestion thread. Spring AI 2.0.0 Spring AI 1.1.0 - 1.1.8 Spring AI 1.0.0 - 1.0.9