Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2119 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
17/09/2026
[CVE-2025-15697] The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in …
The Dictionary WordPress plugin through 1.0 does not escape user input before reflecting it back in the responses of several directly accessible scripts, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting attacks against anyone they can induce to submit a crafted request.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85128] The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role reques…
The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation requires the Choose User Role at Registration WordPress plugin before 1.3.3's role selec…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87935] The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to…
The Paid Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.15 via the admin_request_handler function. This is due to missing authorization and file type validation in the admin_request_handler function, which is reachable unauthenticated via is_admin() returning true for /wp-admin/admin-post.php. This makes it possible for unauthenticated…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-25281] Transient DOS when processing large or numerous request buffers without sufficient memory allocation…
Transient DOS when processing large or numerous request buffers without sufficient memory allocation validation.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-24075] Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handle…
Memory Corruption when multiple threads issue concurrent IOCTL requests to the device control handler due to improper synchronization and race conditions.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-25278] Memory Corruption when processing I2C transfer requests due to a race condition between memory alloc…
Memory Corruption when processing I2C transfer requests due to a race condition between memory allocation and data copying.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92592] Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-contr…
Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bound to its purpose (Yii's cookieValidationKey is derived from the same Craft securityKey used for signed request parameters). An authenticated, non-administrator us…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92578] WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password h…
WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by submitting the hash directly to login endpoints, completely bypassing password v…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92582] AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. ob…
AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameDomainCheck']) merely because 'user' and 'pass' parameters are present in the request; the values are never validated and are read from $_REQUEST, so a…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92576] HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool …
HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the _validate_url() function fails to block internal IP ranges and private addresses. Attackers can send messages instructing the bot to fetch cloud metadata endpoints, localhost services, and RFC 1918 addresses to extract IAM credentials and internal service data.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92804] Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated …
Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests at internal addresses or cloud metadata endpoints, potentially exfiltrating provider credentials.
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-92805] UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wiza…
UVdesk Community Skeleton through 1.1.8 fails to authenticate or validate installation state on wizard endpoints in ConfigureHelpdesk controller actions. Unauthenticated attackers can repoint the database and create super administrator accounts by submitting crafted requests to wizard endpoints, gaining full control of the instance.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92806] phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscr…
phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form handler. Attackers can induce logged-in administrators to visit crafted pages that silently delete and blacklist arbitrary subscriber addresses without authentication verification.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92796] Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in mu…
Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements after the first statement to read credential tables and obtain password hashes that authenticate as administrators without plaintext recovery.
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92782] Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allo…
Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-92751] CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to per…
CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing actions on behalf of authenticated operators. Attackers can craft hidden forms that submit to destructive endpoints like topic deletion and cluster configuration changes, leveraging the operator's HTTP Basic authentication credentials or play-basic-authentication cookie without S…
M Crítico vulnerabilidad
16/09/2026
[CVE-2026-76460] A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, re…
A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized ac…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-76425] A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQ…
A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements to an affected endp…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-63506] Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15…
Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized accepts a request-controlled clientID and asks isUserAuthorized to validate the bearer token against that selected TinaCloud app instead of the self-hosted site's configured app. An attacker with any TinaCloud account can submit the attacker's own app ID and valid token to a victi…
M Alto vulnerabilidad
16/09/2026
[CVE-2026-20352] A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthe…
A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful ex…