Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 1674 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
21/09/2026
[CVE-2026-94449] A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strate…
A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices. The issue occurs when using the ApplyGuard or ApplyFaultTolerance annotations, where the library fails to release internal tracking objects after each request. This causes a steady increase in memory usage that eventually leads to the applica…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-80110] A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding…
A flaw was found in pki-core. The v2 REST ACL filter selects a tie-breaking permission for colliding literal and wildcard ACL keys using lexicographic string comparison rather than specificity, causing a wildcard-mapped permission to override a more specific literal-mapped permission when both match. In the CA's profile-management REST API this allows a request to POST /v2/profiles/raw -- intended…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-61629] nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the …
nginx ignition is a user interface for the nginx web server. In versions 2.29.0 through 2.40.0, the gin i18n middleware in nginx-ignition's API server runs in front of every HTTP request and calls `golang.org/x/text/language.ParseAcceptLanguage` on the raw `Accept-Language` header without imposing any size or shape filter. The underlying parser has quadratic-time behaviour on long lists of malform…
M Alto vulnerabilidad
21/09/2026
Vulnerabilidad en verificación de firma de NooBaa-Core permite bypass de autenticación S3
Se identificó un defecto en la lógica de validación de firmas de noobaa-core que afecta la puerta de enlace multicloud de NooBaa. El servicio no rechaza correctamente solicitudes S3 con presigned URLs que contienen headers x-amz- sin firmar, permitiendo a atacantes eludir mecanismos de autenticación Signature Version 4 (SigV4). Empresas en LATAM que usan NooBaa para gestión de almacenamiento multicloud están en riesgo de acceso no autorizado a datos sensibles.
M Alto vulnerabilidad
21/09/2026
Vulnerabilidad de inyección SQL alta en QCMS hasta versión 6.0.6
Se ha detectado una vulnerabilidad de inyección SQL (CVSS 7.3) en QCMS versiones hasta 6.0.6 que afecta la función self_Tmp en el componente Content Detail Page. Un atacante remoto puede manipular el parámetro ID para ejecutar comandos SQL no autorizados, especialmente porque el router procesa REQUEST_URI sin decodificación de URL. Este exploit ha sido divulgado públicamente y representa riesgo inmediato para portales de contenido y aplicaciones web en producción.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-94038] A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textS…
A security vulnerability has been detected in NonceGeek dim-sum-app. This impacts the function textSearchV2Handler of the file deno/main.tsx of the component Deno Backend. Such manipulation of the argument supabase_url leads to server-side request forgery. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 8389032e5d52c28c4855c612…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-94039] A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoic…
A vulnerability was detected in vas3k TaxHacker up to 0.8.5. Affected is the function generateInvoicePDF of the file /apps/invoices/actions.ts of the component Invoice PDF Renderer. Performing a manipulation of the argument businessLogo results in server-side request forgery. The attack is possible to be carried out remotely. The exploit is now public and may be used. The project was informed of t…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
20/09/2026
Vulnerabilidad alta en NivoCart: tokens de restablecimiento predecibles permiten acceso administrativo
NivoCart versiones hasta 2.4.0 contiene una vulnerabilidad de severidad alta (CVSS 8.1) en el endpoint forgotten.php que genera tokens de recuperación predecibles usando substr(md5(mt_rand()), 0, 10). Un atacante que conozca el correo de un administrador puede solicitar un restablecimiento de contraseña, predecir el token y obtener acceso administrativo sin limitaciones de tasa ni expiración. Esta vulnerabilidad afecta directamente a plataformas de e-commerce en México y LATAM que utilizan NivoCart para gestionar tiendas en línea.
M Alto vulnerabilidad
20/09/2026
[CVE-2026-87067] The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instan…
The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which classes may be instantiated when it deserialises a value taken from an XML-RPC request, allowing users who hold its forms-management permission to write a file of their choosing and execute arbitrary code. That permission belongs to an administrator by default, and to any role the site has granted it through the Formina…
M Alto vulnerabilidad
19/09/2026
[CVE-2026-76790] The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several va…
The Estatik Real Estate Plugin WordPress plugin before 4.3.5 does not sanitise and escape several values decoded from a request parameter before reflecting them back in an unauthenticated AJAX response, leading to Reflected Cross-Site Scripting.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84084] IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due …
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery (CSRF) vulnerability.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84077] IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due …
IBM Guardium Data Protection 12.2 could allow a remote attacker to bypass security restrictions due to a cross-site request forgery vulnerability.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11727] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11725] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.
M Alto vulnerabilidad
18/09/2026
[CVE-2017-20284] Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that al…
Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the jndi-appconfig tutorial servlet. Attackers can craft requests with directory traversal sequences to the servlet endpoint to read files outside the intended tutori…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93748] http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when pro…
http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-stale directives, allowing unauthenticated attackers to retrieve cached responses belonging to other users. Attackers can request the same URL with a large max-stale value to obtain another user's Set-Cookie session credentials from shared-cache entries that were deliberately zero…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93749] source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source ma…
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81179] SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that e…
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset by email while configuring ALLOWED_HOSTS with a wildcard accept an attacker-controlled Host header when generating a password reset link. An unauthenticated attacker can request a reset email whose link points to an attacker-controlled system, and a victim who follows that link …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-32641] Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.…
Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/http/middleware.rs uses unwrap() while parsing the x-amz-firehose-common-attributes header before authentication. A remote unauthenticated attacker can supply non-UTF-8 header data, malformed JSON, or invalid derived header values that trigger a Rust panic and interrupt request han…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93758] An insecure direct object reference in the nested attributes handling of the Mongoid object-document…
An insecure direct object reference in the nested attributes handling of the Mongoid object-document mapper may allow a user with basic application privileges to reference a record identifier that is not their own. Processing such a request can cause that record to be looked up without the usual ownership or scoping restrictions, then updated and linked to the requesting user's own record. This ma…