Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
14,926
Total alertas
3375
Críticas
11163
Altas
8
Ransomware
891
Esta semana
RSS
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-18431] The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and inclu…
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is due to a chain of authorization and input validation weaknesses across the two components that makes it possible for unauthenticated attackers to write attacker-controlled files to the s…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77693] The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the use…
The Order Tip for WooCommerce WordPress plugin before 1.6.0 does not check the capability of the user requesting a file deletion, nor does it restrict which path may be deleted, allowing users with the Shop Manager role and above to delete arbitrary files on the server, which could lead to the site being taken over.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-75797] The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it …
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-19760] The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Sit…
The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTTP Host Header in all versions up to, and including, 1.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This req…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-58095] mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for…
mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root.
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-58096] LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the…
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-74851] The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its …
The Pods WordPress plugin before 3.3.9.1 does not correctly compare a display callback against its list of blocked functions, allowing users with the author role and above to execute arbitrary code on the server. Only sites using the restricted display-callback mode are affected, which is the automatic default on installations whose first Pods version predates 3.1.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-74928] The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its impo…
The Project Manager WordPress plugin before 4.0.7 does not have any authorisation check on its import routes, allowing unauthenticated users to create WordPress accounts with a password the attacker already knows, bypassing the site's own registration setting.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58093] The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After rea…
The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the process tree lock. After reacquiring the tty lock, the handler did not revalidate the state of the terminal, and could proceed to link a terminal that was concurrently being destroyed to the calling process' session. An unprivileged local user can exploit this race condition to escalate privileges.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58094] The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. …
The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a largepage shared memory object. This is intended to be used immediately after creating the object, before any memory is allocated for the object. The handler checked whether a page size had already been configured without holding the rangelock. Two concurrent callers could both observe an unconfigured object and set conflicting…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58097] mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buff…
mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-19718] The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin Word…
The BlogVault Backup & Staging WordPress plugin before 6.65, MalCare WordPress Security Plugin WordPress plugin before 6.65, The WP Remote WordPress Plugin WordPress plugin before 6.65 do not prevent unauthenticated users from obtaining data derived from the secret that binds a site to its remote management service, and generate that secret with a weak pseudo-random number generator, allowing att…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80196] Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remai…
Kimai before 2.58.0 contains an authentication bypass vulnerability where password reset links remain valid after password changes because the LoginLink signature covers only the user id, not the password hash. Attackers who intercept or cache a password reset link can use it up to 2 additional times within a 1-hour window to log in as the user even after the legitimate user has changed their pass…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80198] Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and ex…
Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allowing administrators to access arbitrary configuration keys. Attackers with admin privileges can upload malicious templates to exfiltrate server-wide secrets including LDAP bind passwords and SAML private keys into invoice or export documents accessible to lower-privileged users.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80202] Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), wh…
Kimai before 2.56.0 does not enforce team-membership checks in TimesheetVoter::voteOnAttribute(), which maps permissions only to own_timesheet or other_timesheet. As a result, any authenticated user with ROLE_TEAMLEAD (or a role holding edit_other_timesheet/delete_other_timesheet) can read, modify, and permanently delete timesheets belonging to any user system-wide via the API, regardless of team …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80191] GROWI applies its page-viewer permission check to attachment requests only when the request carries …
GROWI applies its page-viewer permission check to attachment requests only when the request carries an authenticated user. retrieveAttachmentFromIdParam in apps/app/src/server/routes/attachment/get.ts guards the check with a condition requiring the user to be non-null, so a request that carries no session skips the check entirely and the handler returns the file. The routes reached this way, /atta…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80192] @better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 …
@better-auth/sso before 1.6.27 (and before 1.4.8 in the 1.4.x line and before 1.7.0-rc.5 in the 1.7 prerelease line) contains two domain-ownership flaws. When domain verification is disabled, automatic organization assignment accepts unverified provider domains, allowing an authenticated organization owner/administrator to register an SSO provider for an arbitrary domain and have users with matchi…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80193] Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller…
Kimai before 2.62.0 fails to validate create_other_timesheet permission in the QuickEntry controller when creating new timesheets. Authenticated users with view_other_timesheet and edit_other_timesheet permissions can create timesheet records for team members by submitting the QuickEntry form, bypassing authorization checks enforced elsewhere.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-76148] CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the…
CorvusSKK contains a code injection vulnerability, which may lead to arbitrary code execution on the affected product.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58089] When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach P…
When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs to a process can continue monitoring it after the process executes a setuid or setgid binary, contrary to the intended policy.