Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1778
Esta semana
RSS
N Alto vulnerabilidad
02/06/2026
[CVE-2026-8036] Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system …
Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL 26.3.0 and prior versions on Windows and Linux.
M Alto vulnerabilidad
02/06/2026
[CVE-2026-5073] The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter o…
The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This is due to insufficient escaping on the user-supplied 'order' and 'orderby' parameters and the lack of sufficient preparation on the existing SQL query in the `arm_get_directory_members()` function. This…
M Crítico vulnerabilidad
02/06/2026
[CVE-2026-5076] The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in a…
The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset key in the `arm_reset_password_key` user meta field when a user requests a password reset. This is in addition to the hashed key that WordPress core stores securely in `wp_users.user_activation_key`. Th…
M Alto vulnerabilidad
02/06/2026
[CVE-2026-49120] Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worke…
Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authenticated users to perform unauthorized internal network requests by creating FHIR Subscription resources with arbitrary endpoint URLs. Attackers can point subscription endpoints at internal addresses such as cloud instance metadata services, internal databases, or container orches…
A Alto vulnerabilidad
02/06/2026
[CVE-2026-47265] AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.1…
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If…
G Alto vulnerabilidad
02/06/2026
[CVE-2026-41577] authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML so…
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on assertions. NotBefore, NotOnOrAfter, and AudienceRestriction are all ignored. This allows replay of expired assertions and acceptance of assertions intended for other service providers. This issue has bee…
S Alto vulnerabilidad
02/06/2026
[CVE-2026-42211] React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a c…
React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (RCE) through external requests. This attack requires the application code to have an existing prototype pollution vulnerability, which can then be leveraged in a 2-step attack where the second step triggers unauthorized …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
S Alto vulnerabilidad
02/06/2026
[CVE-2026-42342] React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.…
React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can consume disproportionate server resources via unbounded path expansion in the __manifest endpoint, resulting in response time degradation and/or service unavailability for end users. This affects React Router Framework Mo…
M Crítico vulnerabilidad
02/06/2026
[CVE-2026-38967] CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response…
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
S Alto vulnerabilidad
02/06/2026
[CVE-2026-33245] React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unst…
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in ver…
S Alto vulnerabilidad
02/06/2026
[CVE-2026-34077] React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unst…
React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scripting (XSS) vulnerability in the RSC redirect handling if redirects come from untrusted sources. This does not impact applications that are not using the unstable RSC APIs in React Router. This is patched in ver…
M Alto vulnerabilidad
02/06/2026
[CVE-2026-10701] Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firef…
Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3.
M Alto vulnerabilidad
02/06/2026
[CVE-2026-1829] The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution …
The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the 'et_pb_text' shortcode 'cvdb_content_visibility_check' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server.
S Alto vulnerabilidad
02/06/2026
[CVE-2026-28299] SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when ex…
SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory.
M Alto vulnerabilidad
02/06/2026
[CVE-2026-10607] A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspec…
A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/06/2026
[CVE-2026-10608] A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the fi…
A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
02/06/2026
[CVE-2026-10617] A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the…
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/auth.go of the component Webhook Verification Handler. The manipulation leads to missing authentication. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bu…
M Alto vulnerabilidad
02/06/2026
[CVE-2025-64390] A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. …
A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Disc Java) sandbox can be escaped through a malformed JAR file.
M Alto vulnerabilidad
02/06/2026
[CVE-2021-4478] Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-boun…
Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A crafted .gdt file can trigger a buffer overflow during file parsing, allowing an attacker to crash the application or execute malicious code on the underlying system.
M Alto vulnerabilidad
02/06/2026
[CVE-2019-25722] Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded…
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denial-of-service vulnerability that allows local and remote attackers to compromise device integrity across all software versions. A local attacker with direct device access can use the hard-coded credentials to access service and clinical accounts and al…