Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,928
Total alertas
3375
Críticas
11165
Altas
8
Ransomware
890
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82239] Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/que…
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-82222] Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injec…
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73208] An attacker that holds a token intended for a different purpose can authenticate, because when an OA…
An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim does not describe what a token is allowed to do. A token that grants no relevant permissions can be acc…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-42007] An attacker that has valid credentials can use a Sieve script with the editheader extension to trigg…
An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail. This causes memory leak and opportunity to do memory corruption during mail delivery, which can crash the delivery process and may allow execution of arbitrary code in the c…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-42391] An unauthenticated attacker can send an IMAP ID command with a very large number of parameters befor…
An unauthenticated attacker can send an IMAP ID command with a very large number of parameters before logging in, which causes memory and CPU usage to grow disproportionately. The login process can be terminated by the out-of-memory handling, which also terminates all other connections handled by the same process. This can cause degradation or denial of service for IMAP logins. Limit the number of…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-40018] None None None No publicly available exploits are known.
None None None No publicly available exploits are known.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-27852] An attacker that can send mail to a user can craft a message whose headers contain a very large numb…
An attacker that can send mail to a user can craft a message whose headers contain a very large number of email addresses or MIME parameters, which causes excessive memory usage when the message is later parsed. The message is still delivered, but reading it over IMAP can exhaust the memory limit of the process and terminate it, causing denial of service for the affected user. Update to non-vulner…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-33605] An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed com…
An unauthenticated attacker can crash the ManageSieve login process by sending a small malformed command before authenticating. If running in high-security mode (default for community releases), only the attacker's own connection is terminated. If running in high-performance mode (default for Pro releases), all connections handled by the same managesieve-login process are terminated. Repeating the…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-79996] The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability chec…
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-5097] The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in …
The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the 'referer' parameter in all versions up to, and including, 2.4.17. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-6286] The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stor…
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Stored Cross-Site Scripting via customer name fields in versions up to and including 2.2. This is due to an authentication bypass where the AddBookingCommand explicitly skips nonce verification (Command.php line 186), allowing unauthenticated users to submit booking data. While the plugin applies saniti…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-76581] The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions u…
The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.1. This is due to inconsistent and ambiguous HMAC message construction between the unauthenticated `wdpsso_step1` and `wdpsso_step2` AJAX actions, where step 1 signs and discloses an unseparated concatenation of the token, state, redirect, and domain values, while step 2 ver…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-78032] SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed…
SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with the web server privilege.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-40541] An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit…
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-14558] The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions …
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-19084] The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when cr…
The shared-files-pro WordPress plugin before 1.7.70 does not validate the file path supplied when creating a featured image, allowing unauthenticated attackers to read arbitrary files from the server and republish their contents at a public URL.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-19423] The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection whe…
The Ultimate Member WordPress plugin before 2.13.0 does not validate a submitted role selection when it cannot resolve the set of roles a profile form permits, and screens the value against the site's registered role names rather than against the form's own allow-list, allowing unauthenticated users who register through the Ultimate Member WordPress plugin before 2.13.0's own form to grant thems…
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-82082] NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remot…
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-76053] The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulner…
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Noise-Key Injection into HTML Parser in all versions up to, and including, 3.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-77365] The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin f…
The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'a' (above_fold_images) parameter in all versions up to, and including, 4.2.10 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t…