Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1841
Esta semana
RSS
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38062] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38063] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radi…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38064] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38065] Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_…
Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.
R Crítico vulnerabilidad
15/06/2026
[CVE-2026-30120] remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability…
remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.
R Crítico vulnerabilidad
15/06/2026
[CVE-2026-30121] remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-36213] An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges v…
An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-36537] ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code e…
ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of the /login/oauth2/code/ endpoint. By manipulating the email address in this JSON object, a remote attacker can bypass authentication and gain full access to any existing user account on the platform w…
M Alto vulnerabilidad
15/06/2026
[CVE-2025-56814] A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to ex…
A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell metacharacters.
M Alto vulnerabilidad
15/06/2026
[CVE-2025-68713] An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sen…
An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's scoped storage. The resulting files appear in the application's trusted Received interface. These conditions establish a vector for arbitrary code execution if th…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-8357] LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed w…
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-6040] A heap use-after-free existed when importing the blank-width characters of an ODF number format. A p…
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-47777] Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a m…
Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented to be featured in a remote Collection could lead to attackers bypassing the check and faking consent. An attacker could forge the FeatureAuthorization object that is used to verify consent to be featured in a Collection and thus make it appe…
F Crítico vulnerabilidad
15/06/2026
[CVE-2026-9862] Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in th…
Fortra's  Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd service. A remote attacker with network access to the service may be able to cause commands to be executed with the privileges of the service during the autoregistration processing.
F Alto vulnerabilidad
15/06/2026
[CVE-2026-9863] Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch t…
Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy tar-based client installations. A malicious or compromised legacy tar-installed client selected for upgrade or patching may be able to cause commands to be executed on the BoKS Master during client version handling.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
E Alto vulnerabilidad
15/06/2026
[CVE-2026-5079] Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service …
Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multi…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-5230] Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library al…
Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-5233] Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows …
Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-5242] Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy…
Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code Injection. This issue affects Pizzy Library: from 1.0.0.26250 before 1.3.9.26250.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-52704] Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce P…
Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code Inclusion. This issue affects WooCommerce PDF Invoice Builder: from n/a through 2.0.8.