Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
24/06/2026
[CVE-2026-56231] Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST …
Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:jobId endpoints. The handlers authorize the request based only on the attacker-controlled app_id supplied in the request body and never verify that the jobId in the URL belongs to that app_id (or the same tenant/org) before issuing privileged builder comma…
O Alto vulnerabilidad
23/06/2026
[CVE-2026-54012] Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. P…
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can create, update, or import workspace models store arbitrary meta.knowledge entries on their model without checking whether they own or can read the referenced files. Open WebUI then treats meta.knowledge entries of type file as an authorization source in …
M Alto vulnerabilidad
19/06/2026
[CVE-2026-49338] gonic is a music streaming server / free-software subsonic server API implementation. Prior to versi…
gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subsonic API endpoints `/rest/deletePlaylist.view` and `/rest/getPlaylist.view` perform no per-resource authorization. Once authenticated as any user (admin or not), an attacker can delete any playlist owned by any other user (including admin) by passing its `id` and read the full con…
C Alto vulnerabilidad
17/06/2026
[CVE-2026-20190] A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sen…
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitiv…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-12204] A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderC…
A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the file app/api/controller/Crontab.php of the component Scheduled Task Endpoint. Executing a manipulation can lead to authorization bypass. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The v…
A Alto vulnerabilidad
10/06/2026
[CVE-2026-47342] A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to o…
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges This issue affects Apache OFBiz: before 24.09.07. Users are recommended to upgrade to version 24.09.07, which fixes the issue.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-47298] Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code …
Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/06/2026
[CVE-2026-45503] Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose inform…
Improper authorization in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-45490] Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
09/06/2026
[CVE-2026-42902] Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges lo…
Improper authorization in Microsoft PowerToys allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/06/2026
[CVE-2026-46484] Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Head…
Headplane is a feature-complete Web UI for Headscale. Prior to versions 0.6.3 and 0.7.0-beta.3, Headplane was vulnerable to a path traversal / authorization bypass in the Headscale API client used by node and user rename operations. This issue has been patched in versions 0.6.3 and 0.7.0-beta.3.
M Alto vulnerabilidad
08/06/2026
[CVE-2026-46656] Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw wh…
Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically deleted from the database. This "Ghost Session" allows revoked users to maintain full unauthorized access to the system. Version 3.22.0 fixes the issue.
M Alto vulnerabilidad
07/06/2026
[CVE-2026-11462] A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This imp…
A vulnerability was found in Chengdu Everbrite Network Technology BeikeShop up to 1.6.0.22. This impacts the function callback of the file plugins/Stripe/Controllers/StripeController.php of the component Stripe Plugin. Performing a manipulation of the argument Request results in improper authorization. The attack can be initiated remotely. The exploit has been made public and could be used. The pa…
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-10580] The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass le…
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both administrators and unauthenticated visitors — a value that HippooPermissions::has_role_acce…