Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-32468] Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway
M Alto vulnerabilidad
16/08/2026
[CVE-2024-58375] OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when u…
OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-66462] Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments
M Crítico vulnerabilidad
05/08/2026
[CVE-2026-44945] A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests…
A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user with the default user global role can gain full administrative access to the Rancher control plane and transitively to all downstream clusters it manages. This issue affects Rancher: from 2.11.0 before 2.11.16, from 2.12.0 before 2.12.12, from 2.13.…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59548] Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking <= 1.0.0 versions.
Unauthenticated Sensitive Data Exposure in Byteflows Travel &amp; Hotel Booking
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59528] Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates <= 1.1.1 versions.
Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Rates
M Alto vulnerabilidad
23/07/2026
[CVE-2026-28698] Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to a…
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which could expose the underlying host/share filesystem.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
H Alto vulnerabilidad
21/07/2026
[CVE-2023-37507] HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus thei…
HCL DevOps Plan is susceptible to an information disclosure that can allow an attacker to focus their attacks based upon the information revealed.
M Crítico vulnerabilidad
06/07/2026
[CVE-2026-14808] Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerabili…
Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password.
M Alto vulnerabilidad
29/06/2026
[CVE-2026-56124] phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allow…
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the application. The index model executes an unbounded SELECT query and embeds the complete JSON-encoded result set in an inline script block, exposing uploader IP addresses, Argon2ID key hash…
M Alto vulnerabilidad
26/06/2026
[CVE-2026-56060] Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce <= 7.1.1 v…
Unauthenticated Sensitive Data Exposure in Print Invoice & Delivery Notes for WooCommerce
M Alto vulnerabilidad
26/06/2026
[CVE-2026-54824] Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions.
Unauthenticated Sensitive Data Exposure in Ads by WPQuads
M Alto vulnerabilidad
15/06/2026
[CVE-2026-52694] Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.
Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce
M Alto vulnerabilidad
15/06/2026
[CVE-2026-49066] Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway <= 6.0.0 versions.
Unauthenticated Sensitive Data Exposure in Conekta Payment Gateway
M Alto vulnerabilidad
15/06/2026
[CVE-2026-49068] Subscriber Sensitive Data Exposure in Coupon Affiliates <= 7.8.1 versions.
Subscriber Sensitive Data Exposure in Coupon Affiliates

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-49056] Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes a…
Unauthenticated Sensitive Data Exposure in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels
M Alto vulnerabilidad
15/06/2026
[CVE-2026-34891] Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce <= 2.2.5 versions.
Unauthenticated Sensitive Data Exposure in IDPay Payment Gateway for Woocommerce