Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 2131 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad en plugin Modula Image Gallery para WordPress expone galerías privadas
El plugin Modula Image Gallery (versiones hasta 3.0.1) para WordPress contiene una falla de control de acceso que permite a atacantes acceder a galerías privadas sin autorización. La función Modula_Meta::add_metas() no valida el estado de publicación de las galerías, permitiendo divulgación no autorizada de contenido mediante parámetros GET. Afecta sitios WordPress en empresas y medios de LATAM que almacenan contenido sensible en galerías privadas.
M Alto vulnerabilidad
25/09/2026
Vulnerabilidad alta de escalada de privilegios en plugin Knit Pay para WordPress (CVE-2026-89426)
El plugin Knit Pay para WordPress, utilizado para procesar pagos con Cashfree, Instamojo, Razorpay y PayPal, contiene una vulnerabilidad de escalada de privilegios (CVSS 8.8) en versiones hasta 9.6.1.0. La falla permite a atacantes modificar roles de usuario a través de campos de entrada de Gravity Forms, comprometiendo el acceso administrativo. Afecta directamente a tiendas en línea, plataformas de suscripción y negocios digitales en LATAM que dependen de estos gateways de pago.
M Medio vulnerabilidad
25/09/2026
CVE-2026-69304 ASP.NET Core Denial of Service Vulnerability
Microsoft publica advisory de seguridad: CVE-2026-69304 ASP.NET Core Denial of Service Vulnerability. Tipo: Denegación de Servicio (DoS).
M Crítico vulnerabilidad
25/09/2026
Vulnerabilidad crítica en plugin Bookly para WordPress permite acceso no autorizado a datos de reservas
El plugin Bookly para WordPress (versiones hasta 28.2) contiene una vulnerabilidad de Referencia Directa a Objetos (IDOR) en acciones AJAX que permite a atacantes acceder y manipular datos de reservas, sesiones y órdenes sin autenticación. Afecta directamente a negocios de servicios en LATAM que usan este plugin para gestionar citas y pagos online, exponiendo información de clientes y transacciones.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-96039] The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_n…
The BA Book Everything plugin for WordPress is vulnerable to Stored Cross-Site Scripting via first_name Parameter in all versions up to, and including, 1.8.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. An unauthenticated attacke…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-84281] The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pr…
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'productTitle' in '_fpd_data' Order Item Meta in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page…
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-89055] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in a…
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete arbitrary attachments from the Media Library — including administrator-owned product …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-93303] The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to S…
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via 'form_data' Rich Text Field via Draft Save/Resume in all versions up to, and including, 2.10.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will …
M Alto vulnerabilidad
25/09/2026
[CVE-2026-83591] The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Sc…
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Regex Transformation in all versions up to, and including, 1.1.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an in…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-84279] The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the…
The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'output_format' parameter in all versions up to, and including, 6.5.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires …
M Crítico vulnerabilidad
25/09/2026
[CVE-2026-14281] The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin fo…
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement on the publicly accessible REST route `POST /wp-json/wawp/v1/signup/` and the absence of a key allowlist in the `finish_registration_logic` function, which…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97737] In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lo…
In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leading to account takeover.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97731] MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in…
MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied X-Amz-SignedHeaders list. extractSignedHeaders() in cmd/signature-v4-utils.go iterates only the claimed list and never enumerates the headers that actually arrived, and thus a header that arrives unsigned is neither hashed into the canonical request nor rejected. Because cmd/api…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-97646] A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca5…
A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. This affects an unknown function of the file admin/fun/getStudent.php. This manipulation of the argument sid causes authorization bypass. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The project…
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-95699] Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users acce…
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked exposing user profile information and potential scalding due to unintended device activation.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97324] A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the …
A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoOrderPaid of the file yudao-module-pay/src/main/java/cn/iocoder/yudao/module/pay/controller/admin/demo/PayDemoOrderController.java of the component Demo-order Payment Callback Handler. The manipulation of the argument ID leads to improper authorization. The attack can be initiated…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-97326] A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d…
A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this issue is some unknown functionality of the file chat-server/src/main/java/cn/sinjinsong/chat/server/ChatServer.java of the component chat-server. This manipulation causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to the …
M Crítico vulnerabilidad
24/09/2026
[CVE-2026-93291] Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-m…
Omni C20 lacks proper certificate validation which could allow an attacker to perform a man-in-the-middle attack which could allow them to execute arbitrary code.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-93354] Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthe…
Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers to register arbitrary OAuth clients and take over user accounts by exploiting the OAuth 2.0 Dynamic Client Registration endpoint, which is enabled by default and requires no authentication. Attackers can send a POST request to the registration endpoint to obtain a client_id and cl…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-82566] The Botslab G980H dash camera firmware contains a session management vulnerability in which authenti…
The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can remain valid after the associated client connection has been terminated or replaced. Under certain connection conditions, a newly established connection can displace an existing client while previously established session state remains active until a separate expiration mechanism in…