Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 2923 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1790
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-78263] Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Event Tickets
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-78264] Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.
Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-78268] Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat But…
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-78282] Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Stripe Payments
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-32560] Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Gen…
Subscriber Local File Inclusion in MagicAI for WordPress - AI Text, Image, Chat, Code, and Voice Generator
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-32556] Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.
Unauthenticated Cross Site Scripting (XSS) in Boost
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-7455] A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Wri…
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-77567] Filament is a collection of full-stack components for accelerated Laravel development. Prior to vers…
Filament is a collection of full-stack components for accelerated Laravel development. Prior to versions 4.12.0 and 5.7.0, incorrect challenge-form required-field handling allows app-based multi-factor authentication to be bypassed when recovery codes are enabled. Email-based multi-factor authentication is not affected. This issue is fixed in versions 4.12.0 and 5.7.0.
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-16783] A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Wri…
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-19568] A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption …
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
M Alto vulnerabilidad Nuevo
Hace 57 min
[CVE-2026-76098] Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vul…
Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, and recursive rendering in HTMLRenderer.render_token() can exceed Python's recursion limit and raise RecursionError, allowing crafted Markdown to crash a parsing pr…
M Alto vulnerabilidad Nuevo
Hace 57 min
[CVE-2026-61419] Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A …
Dell ThinOS 10, versions prior to 2605_10.2518, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
M Alto vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-71506] Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API del…
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check. Attackers can exploit this misconfigured permission check to zero paid amounts on invoices and remove entries from accountin…
M Alto vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-40877] Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP ob…
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to PHP object injection in the user preference functionality, which can lead to remote code execution. This issue has been fixed in version 3.2.3.
M Alto vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-30864] Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflec…
Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-76072] The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands wh…
The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattended. In headless mode and auto mode the default policy in extensions/cli/src/permissions/defaultPolicies.ts grants the Bash tool the allow permission, and permissionChecker.ts hard-blocks a command only when the terminal-security evaluator returns a disabled verdict, so isCriticalC…
M Crítico vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-76835] OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may sk…
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns true, and isAllowedPath in oauthproxy.go matches the s…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-76836] AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not requi…
AzuraCast exposes the Liquidsoap custom configuration fields through an endpoint that does not require the permission guarding them. The backend_config property in backend/src/Entity/Station.php is annotated with GROUP_GENERAL, and PUT /api/station/{station_id}/profile/edit in backend/src/Controller/Api/Stations/ProfileEditController.php deserializes with that group while requiring only StationPer…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-71943] Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet funct…
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerability is caused by insufficient filtering of the username and password fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for t…
M Alto vulnerabilidad Nuevo
Hace 2 horas
[CVE-2026-71938] Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp f…
Multiple DrayTek VigorSwitch models contain a buffer overflow vulnerability in the switch_lan_gvrp function. The vulnerability is caused by unsafe copying of the portList field into an undersized buffer. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires valid administrative credentials …