Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 9165 resultados ✕ Limpiar búsqueda
14,138
Total alertas
3230
Críticas
10635
Altas
8
Ransomware
1081
Esta semana
RSS
M Alto vulnerabilidad
27/07/2026
[CVE-2026-65446] Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions.
Unauthenticated Cross Site Scripting (XSS) in Kali Forms
M Alto vulnerabilidad
27/07/2026
[CVE-2026-65447] Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Contest Gallery
M Alto vulnerabilidad
27/07/2026
[CVE-2026-66473] Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.
Unauthenticated Broken Access Control in Xendit Payment
M Alto vulnerabilidad
27/07/2026
[CVE-2026-61953] Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro <= 15.0.6 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Simple Link Directory Pro
M Alto vulnerabilidad
27/07/2026
[CVE-2026-61957] Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification <= 5.5.1 versions.
Unauthenticated Cross Site Scripting (XSS) in miniorange otp verification
M Alto vulnerabilidad
27/07/2026
[CVE-2026-65437] Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.…
Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk
M Alto vulnerabilidad
27/07/2026
[CVE-2026-65438] Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions.
Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/07/2026
[CVE-2026-65439] Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions.
Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7
M Alto vulnerabilidad
27/07/2026
[CVE-2026-65440] Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions.
Unauthenticated Cross Site Scripting (XSS) in GetGenie
M Alto vulnerabilidad
27/07/2026
[CVE-2025-63913] An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted r…
An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-51077] SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive infor…
SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_query.php component
M Alto vulnerabilidad
27/07/2026
[CVE-2026-51078] An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str …
An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component
M Alto vulnerabilidad
27/07/2026
[CVE-2021-32085] An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with …
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases. Sensitive information is stored in the database, such as privileged credentials for o…
M Crítico vulnerabilidad
27/07/2026
[CVE-2021-32086] An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcod…
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain pri…
M Alto vulnerabilidad
27/07/2026
[CVE-2021-32087] An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with …
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups. Sensitive information is stored in the database, such as privileg…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
27/07/2026
[CVE-2021-32088] An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpo…
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.
M Crítico vulnerabilidad
27/07/2026
[CVE-2021-32084] An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer res…
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-64551] In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cau…
In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cause length before reading staleness When an ERROR chunk with a STALE_COOKIE cause is received in the COOKIE_ECHOED state, sctp_sf_do_5_2_6_stale() reads the 4-byte Measure of Staleness that follows the cause header: err = (struct sctp_errhdr *)(chunk->skb->data); stale = ntohl(*(__be32 *)((u8 *…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-64552] In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in re…
In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in receive_big() receive_big() bounds the device-announced length by (big_packets_num_skbfrags + 1) * PAGE_SIZE. That is still too loose: add_recvbuf_big() sets sg[1] to start at offset sizeof(struct padded_vnet_hdr) into the first page, so the chain actually carries hdr_len + (PAGE_SIZE - sizeof(padde…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-64554] In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: fix stale pr…
In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() br_ip6_fragment() gets prevhdr, a pointer into the skb head, from ip6_find_1stfragopt(), then calls skb_checksum_help(). For a cloned skb skb_checksum_help() reallocates the head via pskb_expand_head(), leaving prevhdr dangling. It is later dereferenced in ip6_f…