Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39533] Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.4 versions.
Unauthenticated Broken Access Control in AWP Classifieds
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39534] Unauthenticated Broken Access Control in WP Directory Kit <= 1.5.0 versions.
Unauthenticated Broken Access Control in WP Directory Kit
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39524] Unauthenticated Broken Access Control in Masteriyo - LMS <= 2.1.5 versions.
Unauthenticated Broken Access Control in Masteriyo - LMS
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39503] Unauthenticated Broken Access Control in Easy Digital Downloads <= 3.6.5 versions.
Unauthenticated Broken Access Control in Easy Digital Downloads
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39513] Unauthenticated Broken Access Control in Easy Appointments <= 3.12.21 versions.
Unauthenticated Broken Access Control in Easy Appointments
M Alto vulnerabilidad
15/06/2026
[CVE-2026-34886] Unauthenticated Broken Access Control in Simple Membership <= 4.7.1 versions.
Unauthenticated Broken Access Control in Simple Membership
M Alto vulnerabilidad
15/06/2026
[CVE-2026-34898] Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce <= 1.5.3 versions.
Unauthenticated Broken Access Control in Event Tickets Manager for WooCommerce

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-25425] Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.
Unauthenticated Broken Access Control in User Registration
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38329] Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /ap…
Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks file extension validation. An attacker with a valid API token can upload a malicious PHP script and execute arbitrary code on the server.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-5230] Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library al…
Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
O Alto vulnerabilidad
12/06/2026
[CVE-2026-53821] OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server…
OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pairing or trusted-proxy authorization baseline. Unpaired or restricted trusted-proxy Control UI clients can obtain cached operator.admin authority on live WebSocket connections to execute admin-gated Gateway RPCs.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-47120] Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From…
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check). This issue has been patched in version 2.0.8.
M Alto vulnerabilidad
12/06/2026
[CVE-2026-48119] Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From…
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authenticated agents can forge service-monitor results for other users' services. This issue has been patched in version 2.0.12.
M Crítico vulnerabilidad
12/06/2026
[CVE-2026-46716] Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From…
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to before version 2.0.8, a RoleMember user can create a scheduled cron task with Cover=CronCoverAll, Servers=[] and an arbitrary Command. At every tick of the scheduler, the dashboard pushes that command to every server in the global ServerShared map — including servers that belong to…
K Alto vulnerabilidad
12/06/2026
[CVE-2026-42851] Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write b…
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat`, a log line, an email body rendered in `less`, an issue body in a TUI, etc. — can cause kitty to execute attacker-supplied Python inside the running kitty process, with the user's full privileges. There is no approval …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/06/2026
[CVE-2026-50108] The Naxclow platform API that returns device relay registration details exposes a persistent credent…
The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifying that the requester is the legitimate device or owner. An actor able to present a platform-valid request signature can retrieve credentials for arbitrary devices and register on the relay as that device, enabling interception and disruption of its communications.
A Crítico vulnerabilidad
12/06/2026
[CVE-2026-50084] The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer…
The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to any account. This is an instance of "CWE-862: Missing Authorization" with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N (9.6 Critical). When combined with CVE-2026-50082, CVE-50083, and CVE-50085, this can lead to a fully unauthenticated, remote takeover of a…
M Alto vulnerabilidad
12/06/2026
[CVE-2026-7368] The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid c…
The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether the shared hard-coded credentials or legitimate per-user credentials, can subscribe to wildcard topics covering all robots globally, and can publish to any robot's command topic using only the robot's serial number (disclosed in the telemetry stream). Even after removal of hard-c…
O Alto vulnerabilidad
11/06/2026
[CVE-2026-53816] OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event…
OpenClaw before 2026.5.18 contains an insufficient provenance validation vulnerability in node event handling that allows paired nodes to forge exec lifecycle events without system.run authorization. A malicious or compromised paired node can send crafted node.event messages to the gateway, steering target sessions into exec-event paths that expose capabilities the reduced node surface should not …
P Alto vulnerabilidad
10/06/2026
[CVE-2026-0272] A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated …
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with root privileges. The security risk posed by this issue is significantly minimized when CLI access is restricted to a limited group of administrators and by restricting access to the management inte…