Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 3074 resultados ✕ Limpiar búsqueda
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1880
Esta semana
RSS
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28158] Unauthenticated Cross Site Scripting (XSS) in Do Lasso <= 358 versions.
Unauthenticated Cross Site Scripting (XSS) in Do Lasso
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28003] Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist <= 2.9.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Maspik – Spam blacklist
M Alto vulnerabilidad
13/08/2026
[CVE-2026-28004] Unauthenticated Cross Site Scripting (XSS) in Business Directory <= 6.4.25 versions.
Unauthenticated Cross Site Scripting (XSS) in Business Directory
M Alto vulnerabilidad
13/08/2026
[CVE-2026-27535] Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
Subscriber Broken Access Control in Solace Extra
M Alto vulnerabilidad
13/08/2026
[CVE-2026-27536] Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms <= 4.3.3 versions.
Unauthenticated Cross Site Scripting (XSS) in MailChimp Subscribe Forms
M Alto vulnerabilidad
13/08/2026
[CVE-2026-27539] Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce <= 2.11.31 versions.
Unauthenticated Cross Site Scripting (XSS) in Welcart e-Commerce
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-27544] Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.
Unauthenticated Remote Code Execution (RCE) in QA Analytics

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-27345] Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce <= 2.0.3 versions.
Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce
M Alto vulnerabilidad
13/08/2026
[CVE-2026-6464] Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit executio…
Untrusted data inclusion in PostgreSQL psql COPY may allow a server administrator to elicit execution of data lines as psql commands, via error injection. If the "COPY FROM STDIN" or "\copy FROM STDIN" command fails before the server indicates that it awaits input rows, psql processes the in-line data rows as psql commands. "COPY FROM" with a filename is unaffected. The server administrator has…
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-49827] WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1…
WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to upload arbitrary PHP files through the HR Expense scan_file parameter, leading to Remote Code Execution. Combined with open registration (no invite required) and broken role middleware (CheckUserRole silently swallows RouteNotFoundException), this chai…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-49478] Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC)…
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind SSRF, substitute and cache malicious JWKS keys, or disclose ServiceAccount tokens to external hosts.…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-18408] Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server …
Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary code for restore-time execution as the client operating system account running psql to restore the dump, via psql \restrict meta-command input expansion. The fix for CVE-2025-8714 introduced \restrict and \unrestrict to block this attack, but \unrestrict itself was sufficient fo…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-19385] Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator…
Heap buffer overflow in PostgreSQL pg_dump of long function transform lists allows an object creator to execute arbitrary code as the operating system user running pg_dump, via a crafted transform list. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-15742] Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of add…
Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct writes to a huge range of addresses, executing arbitrary code as the operating system user running the database, via extreme inputs to SQL function levenshtein() or levenshtein_less_equal(). Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-16238] Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitr…
Type confusion in PostgreSQL pg_restore_attribute_stats() allows an object creator to execute arbitrary code as the operating system user running the database, via conflation of range and multirange values. Within major version 18, minor versions before PostgreSQL 18.5 are affected. Versions before PostgreSQL 18 are unaffected.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-16239] Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as th…
Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user to execute arbitrary code as the operating system user running the database, via re-creation of a cursor or other portal with different types. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-14677] Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause…
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-14679] Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unkno…
Stack buffer overflow in PostgreSQL argument name matching allows an object creator to achieve unknown impacts via OUT parameter count. The attack can write only 0x0 and 0x1 bytes. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-14680] Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary c…
Type confusion with PostgreSQL "internal" data type arguments allows any user to execute arbitrary code as the operating system user running the database, via calls to functions with that argument type. Type "internal" represents a class of mutually-incompatible data structures not intended for access from SQL. The system intended to prevent such function calls, but this prevention had gaps. Ve…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-15741] SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a s…
SQL injection in PostgreSQL EXTRACT() deparse allows an object owner to execute arbitrary SQL as a superuser via a hostile object definition. Attacks affect expression deparse consumers broadly, including pg_dump, psql commands like \sf, and any similar usage in non-core tools. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.