Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Encode" — 180 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XSS almacenado alta en AVideo plugin Bookmark (CVE-2026-89256)
AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en el plugin Bookmark que permite a propietarios de videos inyectar código malicioso a través del parámetro de nombre de capítulo. Los nombres de capítulos no se codifican antes de insertarse en el HTML de la página pública, causando que todo visitante ejecute el payload en el origen de AVideo. Con CVSS 8.7, afecta plataformas de streaming y repositorios de video frecuentes en empresas e instituciones educativas de LATAM.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XSS almacenado alta en AVideo afecta sesiones de administradores
AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en el plugin LoginControl que no codifica correctamente las claves PGP públicas. Un atacante autenticado puede inyectar código JavaScript malicioso mediante una clave PGP fraudulenta, el cual se ejecuta en la sesión del administrador al visualizar la pestaña de perfil de usuario. Con CVSS 8.7, afecta principalmente plataformas de video on-demand y educación en línea en LATAM que usan AVideo sin actualizar.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XSS almacenada alta en plugin YPTWallet de AVideo (CVSS 8.7)
AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenada en el plugin YPTWallet que afecta el manejo de valores de CryptoWallet. Los datos no se escapan HTML antes de guardarse en wallet_log.information, permitiendo que administradores ejecuten código malicioso al revisar solicitudes de retiro pendientes en pendingRequests.php. Empresas de streaming y plataformas de monetización en LATAM usando esta versión enfrentan riesgo de compromisos administrativos.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88899] knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in t…
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88866] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scr…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any valid login account can inject malicious scripts in the User-Agent header that execute in administrator browsers when viewing the Login History page, allo…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87927] MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxs…
MaxSite CMS through 109.6 contains a local file inclusion vulnerability in the ajax and require-maxsite dispatchers that allows unauthenticated attackers to execute privileged handler files by supplying base64-encoded path traversal sequences. Attackers can bypass path validation checks and execute admin-gated handler actions without authentication to access sensitive functionality.
M Alto vulnerabilidad
05/09/2026
[CVE-2026-18406] The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is …
The SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Text Field Entity-Encoded Payload in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
05/09/2026
[CVE-2026-52771] YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::…
YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' query without escaping. The page tag is attacker-controlled — the POST /api/pages/{tag} API accepts arbitrary URL-encoded values, including single quotes, and stores them. A low-privileg…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85671] QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_ba…
QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can enumerate file identifiers through unauthenticated endpoints and retrieve base64-encoded files or parsed document chunks without ownership verification to disclos…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85437] MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string dec…
MOOS-IvP through 24.8.1 contains multiple buffer overflow vulnerabilities in IvP function string decoders that trust attacker-controlled length fields without validation. Attackers can craft malicious encoded strings with mismatched declared and actual field lengths to overflow heap and stack buffers, potentially achieving remote code execution through MOOS variables or alog files.
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85438] MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dime…
MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validation. Attackers can supply crafted payloads with mismatched dimension values to write attacker-controlled doubles past the end of the IvPBox weight array, causing memory corruptio…
M Crítico vulnerabilidad
03/09/2026
[CVE-2026-85394] python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepti…
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verification when algorithms are not explicitly restricted. This is an incomplete fix for CVE-2024-33663.
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-84479] WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely o…
WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. An attacker who submits valid credentials and sets User-Agent: AVideoEncoder bypasses two…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-71981] Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attacker…
Cypht before 2.12.2 contains a PHP object injection vulnerability that allows authenticated attackers to execute arbitrary operating system commands by supplying a crafted PHP object graph in the back_query GET parameter of the logout handler. Attackers can pass a base64-encoded serialized payload through this parameter, which is decoded and passed directly to unserialize() without an allow-list, …
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82397] Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parse…
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._execute in tornado/web.py parses the body before handler dispatch through HTTPServerRequest._parse_body and parse_body_arguments in tornado/httputil.py, …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82648] WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL …
WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fe to reach cloud metadata services and loopback interfaces.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-59316] Spring Authorization Server's default consent page renders user-controlled values without HTML entit…
Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page presented to the end user. Spring Authorization Server 1.5.0 - 1.5.8 Spring Authorizat…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80576] In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IB…
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: reject oversized IBs with per-ring packet limits On GFX rings, amdgpu_cs_p2_ib() passed user-supplied ib_bytes through to ib->length_dw without a limit, while ring_emit_ib() encodes length into packet fields. Oversized values can corrupt adjacent control bits and destabilize command submission. Add a per-ring IB pac…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-73108] RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability i…
RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receiving the payload. A crafted header can request up to 1,073,741,823 bytes of capacity, allowing unauthenticated attackers to use concurrent TCP connectio…
M Alto vulnerabilidad
25/08/2026
[CVE-2021-47996] Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundl…
Nokogiri before 1.11.4 (CRuby implementation only, when the packaged/vendored libxml2 is used) bundles libxml2 2.9.10, which is affected by multiple vulnerabilities addressed in libxml2 2.9.12, including a memory leak in xmlSchemaValidateStream (CVE-2019-20388), a global buffer over-read in xmlEncodeEntitiesInternal (CVE-2020-24977), a heap-based buffer overflow (CVE-2021-3517), and an out-of-boun…