Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 10 horas
Buscando: "Ni" — 4254 resultados ✕ Limpiar búsqueda
13,736
Total alertas
3106
Críticas
10358
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
24/07/2026
[CVE-2026-49744] Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmwa…
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Out of bounds accesses triggered by malware introduced to a Guest KMD could allow privilege escalation which escapes virtualization boundaries.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-49745] Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmwa…
Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's virtualised GPU memory. Software installed and run under a Guest VM can send commands to the GPU which result in out of bounds memory accesses. These can be used to escalate privileges.
M Crítico vulnerabilidad
24/07/2026
[CVE-2026-12877] The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not saniti…
The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection attacks. This is exploitable in the Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0's standard front-end issue-tracker configuration.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-12981] The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation wh…
The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-66138] In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can ach…
In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.
M Alto vulnerabilidad
24/07/2026
[CVE-2026-12736] The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and incl…
The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save_option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to update_option() without any option-name allowlist or value sanitization, while the permission_callback only verifies the…
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-42933] Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerabilit…
Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active proxy, which would bypass OT segmentation.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-16765] A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unk…
A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected by this issue is some unknown functionality of the file /OnlineClassroom/loginlinkadmin.php. Executing a manipulation of the argument aid can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
23/07/2026
[CVE-2024-58353] Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS…
Cal.com (repository calcom/cal.diy) in versions
M Alto vulnerabilidad
23/07/2026
[CVE-2024-58355] Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability…
Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/) renders booking-question field labels via React's dangerouslySetInnerHTML without sanitizing or escaping user input. An attacker who can create an event type with a malicious booking-question label can inject arbitrary HTML/JavaScrip…
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-52439] An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.ne…
An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism
M Alto vulnerabilidad
23/07/2026
[CVE-2026-38764] An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate priv…
An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys
M Alto vulnerabilidad
23/07/2026
[CVE-2026-49035] The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate reques…
The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-16002] The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash th…
The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service.
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-15630] A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or mod…
A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a mismatch between authorization (based on ?id=) and action (based on request body).

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65705] FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill v…
FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processe…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-60122] gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the…
gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to t…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-16756] Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the de…
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. To mitigate this issue, users should upgrade to aws-smithy-http-ser…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65918] PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vul…
PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor callback that passes unclamped length to memcpy. Attackers can supply malicious or truncated GIF files to cause denial of service via segmentation fault or disclose adjacent heap memory contents.
M Crítico vulnerabilidad
23/07/2026
[CVE-2026-65700] h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that…
h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to the server process by supplying traversal sequences in the bearer token. The get_user_dir function in openai_server/backend_utils.py uses the bearer token string unsanitized as a path component via os.p…