Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Quest" — 2122 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Alto vulnerabilidad
27/08/2026
[CVE-2026-80208] APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in Interna…
APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gateway shipped with the product proxies every /api request to the backend server, so both endpoints are reachable by any unauthenticated cli…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-75871] GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of t…
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration that overrides the HTTP Host header, r…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30046] A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to…
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30047] A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7…
A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30050] An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5g…
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30057] An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Deni…
An issue in the CreateUEContext handler component of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted request.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-19889] GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of t…
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.9.0 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect model requests to an externally-controlled endpoint via crafted model metadata, resulting in the disclosure of Google Vertex AI or AWS Bed…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/08/2026
Vulnerabilidad de desbordamiento de búfer en CodeMeter Runtime versiones anteriores a 8.41a y 9.10
CodeMeter Runtime, cuando se configura como servidor, es vulnerable a un ataque de lectura fuera de límites (out-of-bounds read) mediante el opcode 0x5e debido a validación insuficiente de longitud de datos. Esta falla causa fallo de segmentación que interrumpe el servicio. Afecta sistemas de licenciamiento de software en empresas manufactureras, de ingeniería y financieras en LATAM que dependen de esta plataforma para protección de activos digitales.
M Alto vulnerabilidad
27/08/2026
Vulnerabilidad CSRF sin autenticación en FluentBooking Pro versiones ≤ 2.2.4
FluentBooking Pro versiones 2.2.4 e inferiores presentan una vulnerabilidad de falsificación de solicitud entre sitios (CSRF) sin requerir autenticación previa. Esta falla permite a atacantes ejecutar acciones no autorizadas en plataformas de reserva utilizadas por hoteles, agencias de viajes y servicios de turismo en LATAM. El score CVSS 8.1 indica alto riesgo de compromiso de integridad y disponibilidad de sistemas altas de reservación.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81271] Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory <= 2.8.176 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in GeoDirectory
M Alto vulnerabilidad
27/08/2026
[CVE-2026-47849] Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation …
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring Data REST 4.0.0 - 4.4.15 Spring Data REST 3.7.20 and earlier
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81421] A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element i…
A security flaw has been discovered in ddfourtwo sentry-selfhosted-mcp 0.4.0. The affected element is an unknown function of the component raw_sentry_api. The manipulation of the argument endpoint results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem earl…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-77611] SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authent…
SeaweedFS is a distributed storage system for files and blobs. In versions prior to 4.40, an authenticated S3 principal with permissions scoped to a nested object key can overwrite a different object outside that scope by calling PutObjectAcl on the key it is allowed to access. The handler authorizes the request against the requested nested key but then writes the updated entry back to the bucket …
M Alto vulnerabilidad
26/08/2026
[CVE-2026-55228] Weblate is a web-based continuous localization platform used to manage software translations. In ver…
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via these unvalidated requests, a user could grant access to projects they were not au…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-81027] one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a r…
one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a specific channel either through a suffix on the API key or through a URL path parameter. The suffix path is reached only after model.IsAdmin succeeds and otherwise rejects the caller, while the path-parameter branch sets the selected-channel value from c.Param("channelid") with no r…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-81029] OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued to…
OpenMetadata accepts a caller-supplied post-authentication redirect target and appends the issued token to it. SamlLoginServlet reads the callback request parameter and stores it in the HTTP session without comparing it against any configured or registered destination, and the assertion consumer servlet later formats that stored value into a URL carrying the freshly issued JWT together with the ac…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-81031] IDURAR ERP CRM changes the password of whichever account a request names rather than the account mak…
IDURAR ERP CRM changes the password of whichever account a request names rather than the account making the request. The update handler in backend/src/controllers/middlewaresControllers/createUserController/updatePassword.js resolves the authenticated user from the request that the token middleware populated, then issues its update against a filter built from the identifier in the URL path, and ne…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-54569] SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.…
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many,…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80570] In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - zero re…
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - zero report size on F54 work error In rmi_f54_work(), if an error occurs during report request or command verification, the code jumped directly to the 'error' label, bypassing the 'abort' label where f54->report_size was normally zeroed out. This left f54->report_size containing its previous successful …
M Alto vulnerabilidad
26/08/2026
[CVE-2026-80553] In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Cancel existing …
In the Linux kernel, the following vulnerability has been resolved: s390/vfio_ccw: Cancel existing workqueues The initialization of the io_work and crw_work workqueues begs the question of whether they should be un-initialized. Add the corresponding cleanup tags in _release_dev to ensure work isn't dispatched after the private struct is free'd.