Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,928
Total alertas
3375
Críticas
11165
Altas
8
Ransomware
890
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-18983] The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site S…
The One User Avatar | User Profile Picture plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4 via the wpua_action_process_option_update function. This is due to insufficient file type validation in wp_handle_upload() called without a MIME allow-list, with post-write validation relying on the attacker-controlled client-supplied Content-Type…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-18324] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Rich-Text Textarea Field in all versions up to, and including, 1.57.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a use…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-18978] The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Co…
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 7.8.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. A comment payload crafted exclusive…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-38820] openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injec…
openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-38821] A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenti…
A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-38822] In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the au…
In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-61800] Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints an…
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. In versions 4.4.0 through 4.14.6, a party holding the cluster key can write, overwrite, or delete arbitrary files under /var/ossec on worker nodes, leading to remote code execution as root. During cluster file synchronization, the non-merged branch of update_master_files_in_worker…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-82072] Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execut…
Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-78037] Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. A…
Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated attacker may be able to execute arbitrary operating system commands with elevated privileges, potentially resulting in unauthorized access to sensitive information or complete device compromise.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-78239] Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, …
Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote attacker to enable administrative services that should be restricted. Successful exploitation may permit unauthorized access to the device.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-76940] The affected Ebyte device does not restrict repeated authentication attempts through rate limiting …
The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-76943] Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allo…
Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to bypass intended access controls and obtain command execution capabilities. Successful exploitation could allow unauthorized interaction with privileged functionality and may lead to complete device compromise.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-76945] The affected Ebyte device relies on client-managed authentication tokens without sufficient server-…
The affected Ebyte device relies on client-managed authentication tokens without sufficient server-side validation. An attacker may replay or manipulate authentication tokens to gain unauthorized access to administrative functionality.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-77977] Ebyte gateway product's vendor configuration utility does not require authentication before allowin…
Ebyte gateway product's vendor configuration utility does not require authentication before allowing certain disruptive administrative actions when default credentials remain configured. An unauthenticated attacker on the adjacent network could reboot the device or restore factory settings, resulting in a loss of configuration and service availability.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75813] Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthor…
Certain configuration endpoints may lack proper server-side authorization checks, allowing unauthorized users to access or modify sensitive device settings. This could result in full compromise of device functionality.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75814] The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the…
The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a disruption of device availability.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-76060] An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionalit…
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-76179] An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway produ…
An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication tokens used by the web management interface are insufficiently protected during client-side session handling, which may allow an attacker with access to exposed session information to obtain and reuse a valid token. Successful exploitation could allow an attacker to impersona…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75418] A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.…
A path traversal vulnerability exists in the built-in preview/development web server of Lektor
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-75419] go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() fun…
go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz middleware always allows requests. Any authenticated user (regardless of role or tenant) can invoke administrative APIs such as deleting users,…