Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,598
Total alertas
3086
Críticas
10240
Altas
8
Ransomware
1808
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-75917] SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-t…
SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (app/src/util/pathName.ts, getLeaf()/movePathTo()) used by the 'move/link to' path-selection dialogs, where document metadata fields (bookmark, alias, memo, and an alternate name field) are concatenated into the aria-label HTML attribute without escaping. A document crafted with a …
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-70421] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulne…
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-70422] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-54794] Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) v…
Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-54795] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-54796] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-56088] Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special …
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-43961] A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expressio…
A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the privileges of the user running Vim.
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-16019] Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability i…
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows SQL Injection. This issue affects FAYDAM Datalogger: from 2.7.1 before 2.8.0.
M Alto vulnerabilidad
Hace 5 días
[CVE-2020-37267] Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authori…
Renovate versions >=19.180.0 and
M Alto vulnerabilidad
Hace 5 días
[CVE-2024-58376] Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 m…
Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed during helm repo add operations, gaining full access to Renovate's execution environm…
M Alto vulnerabilidad
Hace 5 días
[CVE-2019-25766] Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comme…
Renovate versions >= 13.87.0 and
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-76235] A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every …
A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73387] Unauthenticated Local File Inclusion in Resido <= 1.5 versions.
Unauthenticated Local File Inclusion in Resido
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73388] Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.
Unauthenticated SQL Injection in Nikstore Core

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73389] Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.
Unauthenticated PHP Object Injection in Kalles Addons
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73390] Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.
Unauthenticated Privilege Escalation in Total Donations
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73391] Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.
Unauthenticated SQL Injection in Total Donations
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-73394] Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.
Unauthenticated Broken Access Control in Stitch Express
M Crítico vulnerabilidad
Hace 5 días
[CVE-2026-73347] Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.
Unauthenticated Privilege Escalation in TrueBooker