Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1772
Esta semana
RSS
M Alto vulnerabilidad
15/06/2026
[CVE-2026-52719] An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad.…
An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential informa…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-52720] A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle…
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that c…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-52722] A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream…
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50881] Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor priv…
Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and configuration changes.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50882] An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Den…
An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50883] An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows a…
An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50884] Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administr…
Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50885] Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unaut…
Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints via a crafted request.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50886] Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows at…
Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50887] A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink…
A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50888] An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Ben…
An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL.
L Alto vulnerabilidad
15/06/2026
[CVE-2026-50889] An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a…
An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a crafted refresh-token header.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50873] An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allo…
An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50874] An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Remi…
An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50875] Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows aut…
Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or delete another tenant's webhook via a crafted request.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50877] An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying f…
An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50878] An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to ca…
An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50879] An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to c…
An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50880] An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to e…
An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-49952] Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that…
Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter integration and the database backup API exposed by dbbak.php. Attackers can inject a crafted payload through the username paramet…