Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1807
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 21 horas
Vulnerabilidad XSS sin autenticación en WPComplete versiones <= 2.9.5.6
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación en el plugin WPComplete que afecta versiones hasta la 2.9.5.6. Esta falla permite a atacantes inyectar código malicioso en sitios WordPress expuestos, comprometiendo la integridad de datos y robando sesiones de administradores. Es especialmente alta para empresas LATAM con presencia digital en WordPress, plataforma dominante en la región.
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-28190] Subscriber Broken Access Control in ProLancer Element <= 1.4.8 versions.
Subscriber Broken Access Control in ProLancer Element
M Alto vulnerabilidad Nuevo
Hace 21 horas
Inyección SQL alta en ProLancer Element versiones ≤ 1.4.8
Se ha identificado una vulnerabilidad de inyección SQL en ProLancer Element que afecta todas las versiones hasta la 1.4.8, con puntuación CVSS de 8.5 (alta). Esta falla permite a atacantes ejecutar consultas SQL arbitrarias a través del módulo de suscriptores, comprometiendo la integridad y confidencialidad de bases de datos. Empresas en LATAM que utilizan esta plataforma para gestión de proyectos o freelancing están expuestas a robo de datos sensibles y acceso no autorizado.
M Alto vulnerabilidad Nuevo
Hace 21 horas
XSS no autenticado alta en Brave Conversion Engine (PRO) versiones ≤ 0.8.6
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación en Brave Conversion Engine (PRO) versiones 0.8.6 y anteriores, con CVSS 7.1. Esta falla permite a atacantes inyectar código malicioso que se ejecuta en navegadores de usuarios finales, comprometiendo sesiones y datos sensibles. Empresas en México y LATAM que utilizan esta herramienta para conversión de contenido o procesamiento de documentos están expuestas a ataques dirigidos y robo de credenciales.
M Alto vulnerabilidad Nuevo
Hace 21 horas
Eliminación arbitraria de archivos sin autenticación en ShopBuilder Pro ≤ 2.2.0
ShopBuilder Pro, extensión de Elementor para WooCommerce, presenta una vulnerabilidad alta (CVSS 8.6) que permite a atacantes no autenticados eliminar archivos arbitrarios del servidor. Afecta directamente a tiendas en línea y sitios de comercio electrónico en México y LATAM que utilizan versiones anteriores a 2.2.1. El riesgo es severo: pérdida de datos altas, degradación de servicios y potencial exposición de información sensible.
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-32478] Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.
Subscriber SQL Injection in WP Project Manager Pro
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-28151] Unauthenticated Local File Inclusion in Tonda < 2.6 versions.
Unauthenticated Local File Inclusion in Tonda < 2.6 versions.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-28152] Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
Unauthenticated Local File Inclusion in Tonda Core < 2.6 versions.
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-28153] Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notificatio…
Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-28162] Unauthenticated Cross Site Scripting (XSS) in Events Made Easy <= 3.2.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Events Made Easy
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-28166] Unauthenticated Cross Site Scripting (XSS) in Tourmaster <= 5.4.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Tourmaster
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-28167] Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
Unauthenticated Arbitrary File Download in Super Forms
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-28171] Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.
Unauthenticated Arbitrary File Deletion in WooCommerce File Approval
M Alto vulnerabilidad Nuevo
Hace 22 horas
[CVE-2026-78245] A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_upl…
A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.
M Alto vulnerabilidad Nuevo
Hace 22 horas
[CVE-2026-76172] fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme …
fast-uri is a URI parser for Node.js. During parsing it runs a legacy decoding pass over the scheme component and never re-escapes the result, and serialization writes the scheme back out verbatim, unlike the host component which is re-escaped. As a result an input whose scheme carries percent-encoded slashes parses as a scheme with no authority, so the parsed host and error are both undefined, ye…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 22 horas
[CVE-2026-78244] A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this iss…
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.
M Alto vulnerabilidad Nuevo
Hace 22 horas
[CVE-2026-10582] Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRem…
Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actua…
M Alto vulnerabilidad Nuevo
Hace 23 horas
[CVE-2026-75931] fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input …
fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree with each other: parse, resolve, normalize, and equal can yield different hosts for the same input d…
M Alto vulnerabilidad Nuevo
Hace 23 horas
[CVE-2026-75975] fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validat…
fast-uri is a URI parser for Node.js. Its custom parser for bracketed IPv6 literals does not validate the complete IPv6 grammar, so invalid trailing text in an authority can be silently discarded and a malformed attacker-controlled host is turned into a different valid IPv6 destination. For example, a bracketed literal with invalid trailing characters is normalized to the unspecified address, whic…
M Alto vulnerabilidad Nuevo
Hace 23 horas
[CVE-2026-78314] SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.
SQL Injection in Delta DIAEnergie v1.11.00.002 allows attacker to remote code execution.