Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Google" — 844 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1785
Esta semana
RSS
G Alto vulnerabilidad
08/07/2026
[CVE-2026-15112] Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potent…
Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
G Crítico vulnerabilidad
08/07/2026
[CVE-2026-15113] Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote atta…
Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
08/07/2026
[CVE-2026-15114] Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote att…
Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High)
G Alto vulnerabilidad
08/07/2026
[CVE-2026-15116] Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execut…
Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
08/07/2026
[CVE-2026-15117] Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who co…
Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
08/07/2026
[CVE-2026-15118] Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execut…
Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
08/07/2026
[CVE-2026-15107] Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to ex…
Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
A Alto vulnerabilidad
06/07/2026
[CVE-2026-49297] Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator…
Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with write access to the source GCS bucket (typically a different trust principal than the DAG author — partner uploads, ingest-only service accou…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58296] Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allo…
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58297] Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allo…
Exposure of private personal information to an unauthorized actor in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58299] Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthoriz…
Time-of-check time-of-use (toctou) race condition in Microsoft Edge for Android allows an unauthorized attacker to execute code over a network.
M Alto vulnerabilidad
02/07/2026
[CVE-2026-57670] Unauthenticated Cross Site Scripting (XSS) in Google Maps CP <= 1.2.5 versions.
Unauthenticated Cross Site Scripting (XSS) in Google Maps CP
M Alto vulnerabilidad
02/07/2026
[CVE-2026-13251] The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and…
The Perfmatters plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.6.4 via the 's' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires the Local Google Fonts feature to be enabled (disabled by default), pretty permalinks to…
G Crítico vulnerabilidad
01/07/2026
[CVE-2026-14425] Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potenti…
Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14426] Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced…
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14427] Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who h…
Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14428] Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.4…
Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14429] Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a…
Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14430] Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute …
Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14431] Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute ar…
Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)