Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 51 min
14,928
Total alertas
3375
Críticas
11165
Altas
8
Ransomware
885
Esta semana
RSS
M Alto vulnerabilidad
25/08/2026
[CVE-2026-72696] Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile()…
Grav CMS before 2.0.16 contains a symlink following vulnerability in Scheduler Job::createLockFile() that allows local attackers to overwrite arbitrary files by pre-creating symlinks at predictable lock file paths in the world-writable temp directory. Attackers can place a symlink at the predictable lock path pointing to any file the web server process can write to, and the next scheduled job run …
M Alto vulnerabilidad
25/08/2026
[CVE-2026-72700] The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset an…
The getgrav/grav-plugin-login Composer plugin before 3.9.1 (used by Grav) compares password reset and account activation tokens using a non-constant-time === string comparison instead of hash_equals() in classes/Controller.php (taskReset()) and login.php (activation handler). Because the token-submission endpoint (taskReset) also lacks rate limiting, an attacker could in principle send repeated to…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-56703] Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where V…
Adminer before 5.4.3 contains a remote code execution vulnerability in SQLite query handling where VACUUM INTO is not blocked despite ATTACH restrictions. Authenticated attackers can execute VACUUM INTO to write PHP code to arbitrary file paths and execute commands on the server.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-56707] Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability …
Grav Flex Objects plugin versions 1.4.0 through 1.4.7 contain an authorization bypass vulnerability in the flex-objects shortcode that allows users with page-edit access to render any registered Flex collection without permission checks. Attackers can place the shortcode in published pages to expose sensitive directory contents including user account information, bypassing the authorize ACL enforc…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-56709] Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function whe…
Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-56702] Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUp…
Adminer versions before 5.4.3 contain an unrestricted file upload vulnerability in the AdminerFileUpload plugin that allows authenticated users to upload PHP files by exploiting a permissive default extension allowlist. Attackers can upload PHP webshells to columns ending in _path and execute arbitrary code as the web-server user when uploadPath is web-served.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-34968] Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the data…
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths in the db[] parameter to delete any files writable by the PHP process.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-66766] SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial o…
SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An unauthenticated attacker could supply specially crafted input that triggers excessive processing within the affected functionality. Successful exploitation could exhaust system resources and make the service unavailable, resulting in a high impact on availability.…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78284] Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.
Unauthenticated Arbitrary File Deletion in MasterStudy LMS
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78263] Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78264] Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78268] Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat But…
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78282] Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments
M Alto vulnerabilidad
24/08/2026
[CVE-2026-77384] libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the re…
libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE requests for the same reservation, causing unbounded listener and closure growth in @lib…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78259] Unauthenticated Broken Authentication in WPLegalPages <= 3.7.0 versions.
Unauthenticated Broken Authentication in WPLegalPages

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-32560] Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Gen…
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator
M Alto vulnerabilidad
24/08/2026
[CVE-2026-32561] Subscriber Privilege Escalation in Booking Hub <= 1.3.0 versions.
Subscriber Privilege Escalation in Booking Hub
M Alto vulnerabilidad
24/08/2026
[CVE-2026-32556] Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Boost
M Alto vulnerabilidad
24/08/2026
[CVE-2026-7455] A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Wri…
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-77567] Filament is a collection of full-stack components for accelerated Laravel development. Prior to vers…
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0.