Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,230
Total alertas
3248
Críticas
10709
Altas
8
Ransomware
985
Esta semana
RSS
M Alto vulnerabilidad
11/07/2026
[CVE-2026-15338] The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion i…
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.1 via the get_type_template function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be us…
M Alto vulnerabilidad
11/07/2026
[CVE-2026-13114] The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Store…
The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content and User Biographical Info in all versions up to, and including, 1.4.112 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a u…
M Alto vulnerabilidad
11/07/2026
[CVE-2026-13353] The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress i…
The WP Ultimate CSV Importer – WordPress Import & Export for CSV, XML & Excel plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.0.1 via the 'MappedFields' parameter. This is due to missing capability checks on the AJAX handlers for install_addon, saveMappedFields, and StartImport, combined with the plugin nonce being exposed to any authenticated us…
M Alto vulnerabilidad
11/07/2026
[CVE-2026-13756] The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to…
The WP Grid Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.3.3. This is due to missing authorization and meta key validation in the `update()` handler for the `/wp-json/wpgb/v2/metadata` REST endpoint. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to Administrator b…
M Alto vulnerabilidad
10/07/2026
[CVE-2026-42952] Previously, there was no throttling on repeated authentication attempts to the charging station bac…
Previously, there was no throttling on repeated authentication attempts to the charging station backend, which could allow an attacker to execute a denial-of-service attack.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-44383] Multiple connections to the backend using the same charging station ID are allowed, which could all…
Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.
L Alto vulnerabilidad
10/07/2026
[CVE-2026-55175] Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2…
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to versions 2026.1.1, 2026.0.3, 2025.4.4, and 2025.3.4 on their respective release lines, Kustomize bake operations allow unsafe YAML tag processing in rosco manifests. This can lead to remote code execution on rosco pods when performing Kustomize bakes. This issue is fixed in versions 2026.1.1, 2026.0.3, 2025.4.4, and 20…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-14480] OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web U…
OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database field and later uses this value as the destination path for an uploaded file without validating or restricting the path. Because Python os.path.join() honors attac…
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-15089] vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest regis…
vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*.
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-20744] The charging station websocket endpoint accepts connections without proper authentication, which co…
The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation.
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-11913] vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*.
F Alto vulnerabilidad
10/07/2026
[CVE-2026-55809] Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drup…
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Flag attendance field allows Object Injection. This issue affects Flag attendance field versions: from 0.0.0 to 1.2.
P Alto vulnerabilidad
10/07/2026
[CVE-2026-55810] Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drup…
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-49213] TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/…
TypeBot is a chatbot builder tool. Prior to 3.17.2, Typebot's shared SSRF validator in packages/lib/src/ssrf/validateHttpReqUrl.ts can be bypassed with the IPv6 unspecified address :: because validateIPAddress blocks local, metadata, and private ranges but does not block :: or its expanded form. A workspace editor or creator can configure a server-side HTTP Request block or guarded script fetch to…
O Alto vulnerabilidad
10/07/2026
[CVE-2026-52747] ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS …
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Prior to 3.0.16, the multipart/form-data request body parser in libmodsecurity silently removes embedded line breaks from non-file form-field values before exporting them to ARGS and ARGS_POST because src/request_body_processor/multipart.cc overwrites reserved bytes in m_reserve instead o…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
L Alto vulnerabilidad
10/07/2026
[CVE-2026-44795] Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, …
Spinnaker is an open source, multi-cloud continuous delivery platform. Prior to 2026.1.0, 2026.0.3, 2025.4.4, and 2025.3.3, unsafe YAML processing bypasses safe deserialization when using CloudFormation deployments or CloudFoundry baking. The use of a non-safe constructor allows arbitrary loading of Java classes, leading to remote code execution. This issue is fixed in versions 2026.1.0, 2026.0.3,…
M Alto vulnerabilidad
10/07/2026
[CVE-2026-13244] Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drup…
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Tealium iQ Tag Management allows Object Injection. This issue affects Tealium iQ Tag Management versions: from 0.0.0 to 2.4.0.
M Alto vulnerabilidad
10/07/2026
[CVE-2026-15081] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal Location Selector allows SQL Injection. This issue affects Location Selector versions: from 0.0.0 to 1.3.0.
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-12535] Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drup…
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.
M Crítico vulnerabilidad
10/07/2026
[CVE-2026-10768] Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issu…
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.