Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 1481 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1790
Esta semana
RSS
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-73338] Unauthenticated Cross Site Scripting (XSS) in Autopay <= 5.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Autopay
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-73342] Unauthenticated Cross Site Scripting (XSS) in WP Multilang <= 2.4.31 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Multilang
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-73343] Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-73181] Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 ver…
Unauthenticated Arbitrary File Download in Extra Product Options & Add-Ons for WooCommerce < 7.6 versions.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-66793] A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Man…
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with cluster-admin privileges on the managed cluster, leading to arbitrary code execution and …
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-68567] Unauthenticated Cross Site Scripting (XSS) in Convert Pro <= 1.0.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Convert Pro
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-69189] Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.use…
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history ide…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-66667] Unauthenticated Cross Site Scripting (XSS) in Templately <= 3.7.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Templately
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-66046] Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic compl…
Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes …
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-66621] Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-66629] Unauthenticated Cross Site Scripting (XSS) in Kirki <= 6.2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Kirki
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-66633] Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
Unauthenticated Cross Site Scripting (XSS) in Fluent Forms Pro Add On Pack < 6.2.12 versions.
M Crítico vulnerabilidad
Hace 6 días
[CVE-2026-59940] Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap…
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() allows attacker-controlled JSON Promise control nodes to operate on values from the general deserialization reference table without verifying genuine internal Promise resolver records, causing deserialization side effects with plugins enabled and potenti…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-61407] Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Acce…
Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-56684] Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey…
Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pending_list while an authenticated client can trigger CLIENT KILL, causing connTLSClose to delete the iterator's cached next node and producing a use-after-free that can crash the server or potentially allow remote code execution when TLS is enabled. This …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-59825] Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from…
Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concerns/user/ldap_authenticable.rb mutates OpenSSL::SSL::SSLContext::DEFAULT_PARAMS when LDAP authentication uses LDAP_TLS_NO_VERIFY=true, disabling SSL and TLS certificate verification globally for requests made by puma web processes while sidekiq backgro…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-45733] Trilium Notes is a cross-platform, hierarchical note taking application focused on building large pe…
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute …
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-50138] goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with Web…
goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `--read-only`, `--upload-only`, and `--no-delete` are enforced only on the primary HTTP port. The WebDAV port is wired straight to `golang.org/x/net/webdav.Handler` with no equivalent guard, so an authenticated WebDAV client can `PUT`, `DELETE`, `MKCOL`…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-50187] Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the d…
Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh passes ZSH_DOTENV_FILE to source after a directory change into a folder containing a .env file, allowing syntactically valid shell commands in the file to execute with the current account's privileges, including without a prompt when ZSH_DOTENV_PROMPT…
M Alto vulnerabilidad
Hace 6 días
[CVE-2026-32547] Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.
Unauthenticated Cross Site Scripting (XSS) in BP Better Messages