Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-66585] Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
Unauthenticated Sensitive Data Exposure in WP Cafe Pro < 3.0.15 versions.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-73384] Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.
Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-73386] Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 …
Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66463] Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
Unauthenticated Sensitive Data Exposure in iCARRY
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66443] Unauthenticated Sensitive Data Exposure in REST API Log <= 1.7.1 versions.
Unauthenticated Sensitive Data Exposure in REST API Log
M Alto vulnerabilidad
12/08/2026
[CVE-2026-47717] FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3…
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensitive project configuration data to guest-context requests even when secureEnabled is enabled. Version 1.3.1 fixes the issue.
M Alto vulnerabilidad
06/08/2026
[CVE-2026-65543] Subscriber Sensitive Data Exposure in Vimeo <= 1.2.2 versions.
Subscriber Sensitive Data Exposure in Vimeo

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/07/2026
[CVE-2026-6267] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-67425] Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat …
Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and ANTHROPIC_API_KEY from the environment and sends them in the Authorization: Bearer header to caller-controlled base_url, allowing an attacker to receive the operator's key on a public host that passes the SSRF guard. This issue is fixed in version 2.26.…
M Alto vulnerabilidad
29/07/2026
[CVE-2026-54660] swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior t…
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHeaders forwards --authorizationToken to every URL fetched by fetchRemoteSchemaDocument while warmUpRemoteSchemasCache resolves external $ref URLs, allowing an attacker-controlled OpenAPI spec to exfiltrate the developer or CI bearer token to…
M Alto vulnerabilidad
17/07/2026
[CVE-2026-7488] Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce a…
Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This issue affects E-Commerce: through 03062026.
M Alto vulnerabilidad
17/07/2026
[CVE-2026-7189] Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's…
Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-57736] Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded …
Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from n/a through 11.3.51.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-54834] Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone
M Alto vulnerabilidad
25/06/2026
[CVE-2026-54848] Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for …
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data. This issue affects APIExperts Square for WooCommerce: from n/a through 4.7.3.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/06/2026
[CVE-2026-54841] Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
Unauthenticated Sensitive Data Exposure in Vitepos
M Alto vulnerabilidad
25/06/2026
[CVE-2026-54821] Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
Subscriber Sensitive Data Exposure in Visual Link Preview
M Alto vulnerabilidad
17/06/2026
[CVE-2026-52698] Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp…
Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget
M Alto vulnerabilidad
17/06/2026
[CVE-2026-34888] Unauthenticated Sensitive Data Exposure in Bricksforge <= 3.1.8.4 versions.
Unauthenticated Sensitive Data Exposure in Bricksforge
M Alto vulnerabilidad
15/06/2026
[CVE-2026-52695] Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout