Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 25 min
Buscando: "Quest" — 2122 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
S Crítico vulnerabilidad
23/07/2026
[CVE-2026-65689] Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full…
S Crítico vulnerabilidad
23/07/2026
[CVE-2026-65687] Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attackers to read arbitrary files from the server filesystem by supplying a crafted request. Attackers can exploit this path traversal weakness to disclose sensitive server files, including authentication credentials, enabling full un…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65540] Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 version…
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65539] Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65516] Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65488] Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 ve…
Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-65471] Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-57784] Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 v…
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57785] Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57626] Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This…
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65757] Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules An…
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-64874] Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN creden…
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-64876] Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP ext…
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65430] Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credent…
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-64799] Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users …
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible fold…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
F Alto vulnerabilidad
23/07/2026
[CVE-2026-15074] @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request …
@fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This is a bypass of the earlier fix for CVE-2026-6414, which only covered encoded forward slashes. Because the underlying send library normalizes dot segments before applying its own path-traversal guard, an unauthenticated attacker can bypass any route-sc…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63684] Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various ad…
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and i…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63685] Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator r…
Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causing major data corruption or site compromise.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-64829] Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers wi…
Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by exploiting the forgot-password reset flow's failure to clear the sessioncode field in qa-include/app/users-edit.php. While the normal password-change flow in qa-include/pages/account.php explicitly clears the sessioncode t…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13189] In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language para…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.