Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2119 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93749] source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source ma…
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81179] SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that e…
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password reset link. An unauthenticated attacker can request a reset email whose link points to an attacker-controlled system, and a victim who follows that link …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-32641] Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.…
Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/http/middleware.rs uses unwrap() while parsing the x-amz-firehose-common-attributes header before authentication. A remote unauthenticated attacker can supply non-UTF-8 header data, malformed JSON, or invalid derived header values that trigger a Rust panic and interrupt request han…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93758] An insecure direct object reference in the nested attributes handling of the Mongoid object-document…
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping restrictions, then updated and linked to the requesting user's own record. This ma…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61833] zot is a container image and artifact registry based on the Open Container Initiative Distribution S…
zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to the push action, so DELETE requests are not checked for the distinct delete permission. Bearer-authenticated requests also bypass the fine-grained DistSpecAuthzHandl…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-46655] virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Vi…
virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits a low-privilege local process to submit an IOCTL_SELECT request with attacker-controlled VIRTIO_VSOCK_SELECT.Fdss[*].fd_count values that overflow the 32-bit sum used by VIOSockSelect for bounds checking. The wrapped sum can pass the FD_SETSIZE check even though an individual de…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-75031] In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was fou…
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-61682] kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and containe…
kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior to 0.31.4 and 0.32.2, the kcp front-proxy does not remove inbound X-Remote-User, X-Remote-Group, or X-Remote-Extra-* identity headers before forwarding requests to shards. Any authenticated tenant can inject X-Remote-Group: system:masters, authorization.kcp.io/warrant, authenticat…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-54148] http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0…
http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.50.0.0, DigestAuthProvider.verify in http4k-security-digest does not compare the uri parameter in an Authorization: Digest response with the actual request URL. An attacker who captures a valid Digest authentication response can replay it against another URL served by the same realm, bypassing the per-r…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-10744] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denia…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially escalate privileges due to an integer overflow in MQINQ request validation.
M Alto vulnerabilidad
18/09/2026
[CVE-2025-14753] IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An…
IBM Cloud Pak for Data 5.1.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
M Crítico vulnerabilidad
18/09/2026
[CVE-2025-15399] IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 …
IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93565] ### Summary `RtspMethods.valueOf()` silently strips trailing control bytes (any character with code…
### Summary `RtspMethods.valueOf()` silently strips trailing control bytes (any character with code point
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93568] HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
HTTP/2 and HTTP/3 Extended CONNECT requests are downgraded as regular CONNECT requests
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93569] HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target…
HTTP/1 absolute-form Host mismatch is translated to HTTP/2 :authority, overriding the request-target authority

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93592] vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and …
vLLM versions before 0.28.0 fail to validate the lower bound of token IDs in the /v1/embeddings and /pooling endpoints, allowing unauthenticated attackers to crash the engine by submitting negative token IDs. A single request with a negative token ID triggers a CUDA device-side assertion that poisons the GPU context, causing all subsequent requests to fail until the process restarts.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93491] A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vul…
A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap memory consumption and a denial of service due to memory exhaustion.
M Alto vulnerabilidad
18/09/2026
Vulnerabilidad de bypass de autenticación en Quarkus HTTP (CVE-2026-87743)
Se identificó una falla alta en el módulo de seguridad HTTP de Quarkus que permite a atacantes no autenticados eludir controles de autorización mediante manipulación de rutas. Un adversario puede crafted URLs que el validador de seguridad interpreta como públicas, pero que se enrutan a endpoints protegidos, comprometiendo acceso a datos sensibles. Afecta especialmente a aplicaciones empresariales en LATAM que usan Quarkus en producción sin actualizar.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-89058] A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflec…
A flaw was found in RESTEasy's CorsFilter, which, when configured to allow all origins ("*"), reflects the request's Origin header back in the Access-Control-Allow-Origin response together with Access-Control-Allow-Credentials: true. This permissive cross-origin policy allows a malicious website to make credentialed cross-origin requests and read authenticated responses from a victim's session, re…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-89059] A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodie…
A flaw was found in RESTEasy's IIOImageProvider, which decodes attacker-supplied image request bodies without enforcing any limit on the declared image dimensions or pixel count. A remote, unauthenticated attacker can send a small crafted image declaring enormous dimensions to trigger a very large memory allocation, exhausting the JVM heap and resulting in a denial of service.