Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Google" — 916 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78950] Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to pote…
Integer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78915] Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjace…
Race condition in Enterprise in Google Chrome on on Windows prior to 152.0.7977.65 allowed an adjacent attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Low)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78934] Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker levera…
Race condition in ReadAloud in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78938] Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute ar…
Type confusion in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78906] Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potenti…
Race condition in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78910] Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute a…
Buffer overflow in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78911] Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who…
Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78913] Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to po…
Use after free in Chromoting in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: Medium)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78899] Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute ar…
Use after free in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78901] Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute ar…
Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78905] Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potenti…
Type confusion in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
25/08/2026
[CVE-2026-78891] Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execu…
Buffer overflow in WebRTC in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
M Alto vulnerabilidad
21/08/2026
[CVE-2026-63135] YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS …
YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get_referrer(), yourls_sanitize_url_safe(), and yourls_log_redirect(), then aggregates the value in yourls-infos.php and passes the derived domain through yourls_get_domain(), yourls_stats_pie(), and yourls_google_array_to_data_table(). The chart builder…
M Alto vulnerabilidad
19/08/2026
Vulnerabilidad XSS en WP Statistics afecta sitios WordPress hasta versión 14.16.8
El plugin WP Statistics para WordPress contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado en el parámetro 'utm_campaign' que permite a atacantes no autenticados inyectar scripts maliciosos. La falla afecta todas las versiones hasta 14.16.8 y se ejecuta cuando visitantes acceden a páginas comprometidas, poniendo en riesgo datos de usuarios y credenciales en sitios empresariales, de comercio electrónico y portales informativos comunes en LATAM.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-53958] 4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an au…
4gaBoards is a boards system for realtime project management. Prior to 3.3.9, 4gaBoards allows an authenticated user to modify ssoGoogleId, ssoGoogleEmail, ssoGithubId, ssoGithubUsername, ssoGithubEmail, ssoMicrosoftId, ssoMicrosoftEmail, ssoOidcId, and ssoOidcEmail through PATCH /api/users/:id. The whitelist in server/api/controllers/users/update.js mass assigns these backend-managed identity att…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/08/2026
[CVE-2026-50191] 4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerabl…
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards is vulnerable to pre-account takeover when registrationEnabled, localRegistrationEnabled, and ssoRegistrationEnabled are enabled and Google, GitHub, Microsoft, or OIDC SSO is configured. The POST /api/register endpoint permits creation of an unverified local account with a victim's email address, and POST /api/…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-73367] Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
Unauthenticated Remote File Inclusion in Easy Google Maps < 1.14.2 versions.
M Alto vulnerabilidad
18/08/2026
Vulnerabilidad SSRF alta en ArcadeDB anterior a v26.8.1 permite acceso a servicios internos
ArcadeDB versiones anteriores a 26.8.1 contienen una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) en el comando IMPORT DATABASE. Atacantes autenticados pueden eludir validadores de seguridad mediante redirección DNS o HTTP para acceder a endpoints de metadatos en la nube, servicios internos y bases de datos. Esta vulnerabilidad impacta directamente infraestructuras en AWS, Azure y Google Cloud ampliamente desplegadas en México y LATAM.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-73655] Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to…
Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in apps/webapp/app/services/googleAuth.server.ts passes a Google profile email to findOrCreateGoogleUser() in apps/webapp/app/models/user.server.ts without requiring Google's email_verified assertion. When existingEmailUser && !existingUser is true, the flow writes the ne…
M Alto vulnerabilidad
11/08/2026
[CVE-2026-48767] TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a …
TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth access token for that workspace by calling the Google Sheets helper `getAccessToken`. The vulnerable path checks only whether the caller has read access to the workspace, decrypts the stored Google OAuth credential, refreshes or retrieves the access tok…