Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 10018 resultados ✕ Limpiar búsqueda
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1781
Esta semana
RSS
C Medio vulnerabilidad
03/06/2026
Cisco Webex Meetings Cross-Site Scripting Vulnerability
Cisco PSIRT publica advisory de seguridad: Cisco Webex Meetings Cross-Site Scripting Vulnerability. Tipo: Cross-Site Scripting (XSS). Producto afectado: Cisco Webex. Security Impact Rating: Medium.
H Crítico vulnerabilidad
03/06/2026
[CVE-2026-5241] A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows…
A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The issue arises because the `trust_remote_code` parameter, intended to prevent remote code execution, is overridden by untrusted serialized configuration data in a nested code path. Specifically, when lo…
S Alto vulnerabilidad
03/06/2026
[CVE-2022-49042] An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in …
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via unspecified vectors.
S Alto vulnerabilidad
03/06/2026
[CVE-2022-49036] An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration i…
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users to execute arbitrary code via unspecified vectors.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35084] A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain…
A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35085] A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to ga…
A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-35083] A remote attacker with user privileges can exploit a stack buffer overflow to gain full system acces…
A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
A Crítico vulnerabilidad
03/06/2026
[CVE-2026-47065] ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Pro…
ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which perform…
A Crítico vulnerabilidad
03/06/2026
[CVE-2025-14771] Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue aff…
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.
L Alto vulnerabilidad
03/06/2026
[CVE-2026-4035] A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment v…
A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environment credentials to an attacker-controlled endpoint. This issue arises because the `api_key` field in gateway secrets can accept `$ENV_VAR` references, which are resolved against the MLflow server's env…
M Alto vulnerabilidad
03/06/2026
[CVE-2025-15654] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This issue affects Prague: from n/a through 2.2.8.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-50031] ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intell…
ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors comma…
M Medio vulnerabilidad
03/06/2026
Condición de carrera en Go Snowflake Driver afecta acceso a configuración de logging
El controlador Go para Snowflake (versiones afectadas) contiene una vulnerabilidad de condición de carrera (race condition) en la validación de acceso al archivo de configuración Easy Logging. Un atacante con acceso local podría explotar esta debilidad para leer o modificar archivos de configuración sensibles en aplicaciones que usan este driver, potencialmente comprometiendo credenciales y conexiones a Snowflake en infraestructuras críticas de LATAM.
P Medio vulnerabilidad
03/06/2026
Vulnerabilidad crítica en módulo de correo de Python hasta v3.11.3 permite eludir validación de dominio
El módulo email de Python versiones 3.11.3 y anteriores contiene un fallo en la función _parseaddr.py que permite a atacantes eludir mecanismos de autenticación basados en validación de dominio de correo electrónico. Un atacante puede fabricar direcciones de correo con caracteres especiales que el parser interpreta incorrectamente, permitiendo registros no autorizados en aplicaciones que restringen el acceso solo a direcciones de dominios específicos (como @empresa.com). Esto afecta directamente servicios web y plataformas SaaS en México y LATAM que utilizan Python para procesar correos.
M Alto vulnerabilidad
03/06/2026
[CVE-2026-10704] A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulne…
A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrative Control Panel. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/06/2026
[CVE-2026-10694] A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this iss…
A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in file inclusion. The attack can be launched remotely. The exploit is now public and may be used.
R Alto vulnerabilidad
03/06/2026
[CVE-2026-9334] Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when d…
Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference under dupkeys_as_arrayref. The branch reached for a duplicate key tests `SvTYPE (old_value) != SVt_RV && SvTYPE (SvRV (old_value)) != SVt_PVAV`, which evaluates SvRV(old_value) before establishing tha…
R Alto vulnerabilidad
03/06/2026
[CVE-2026-9516] Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input …
Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances the input scalar's string pointer past the mark with SvPV_set() and restores it only on the normal return path. When decoding aborts through a Perl exception, for example a filter_json_object callback t…
M Alto vulnerabilidad
03/06/2026
Vulnerabilidad crítica en Mirasvit Full Page Cache Warmer bajo explotación activa
CISA confirma explotación activa de CVE-2026-45247 en extensiones Mirasvit Full Page Cache Warmer para plataformas de e-commerce. La vulnerabilidad afecta directamente a tiendas online en México y LATAM que usan este módulo de optimización de caché. No se ha detectado uso en campañas de ransomware documentadas hasta la fecha.
M Alto vulnerabilidad
02/06/2026
[CVE-2026-35482] alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meet…
alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script engine allows an authenticated administrator to execute arbitrary operating system commands on the server. The extension system is intended to execute restricted JavaScript in a sandboxed Rhino environme…