Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 7953 resultados ✕ Limpiar búsqueda
14,138
Total alertas
3230
Críticas
10635
Altas
8
Ransomware
1073
Esta semana
RSS
M Alto vulnerabilidad
23/07/2026
[CVE-2026-47743] Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewir…
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive data disclosure, and stored XSS. First, several Livewire components in the admin panel exposed Eloquent model identifiers as public properties without the `#[Locked]` attribute. An authenticated user could rewrite the wire payload from the browser to ta…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-44909] Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A re…
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams requesting large r…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65917] CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDO…
CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate other tenants' backup resources by supplying an attacker-controlled globally sequential IncJob integer ID th…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65916] CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in…
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-16584] Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 migh…
Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured security policy and execute AWS API operations that the policy was set to deny or gate. When initialization of the security policy enforcement data fails at server startup, the policy check is skipped for the lifetime of the process. IAM permissions on …
C Alto vulnerabilidad
23/07/2026
[CVE-2026-65898] DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an u…
DOMPurify before 3.4.11 fails to clone the ALLOWED_ATTR allowlist when setConfig() is used with an uponSanitizeAttribute hook, allowing the hook to permanently mutate the shared allowlist. Attackers can register a hook that conditionally allows dangerous attributes like onerror for trusted elements, then submit untrusted content that inherits the polluted allowlist and executes event handlers as s…
S Alto vulnerabilidad
23/07/2026
[CVE-2026-65690] Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulner…
Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its file upload functionality that allows authenticated attackers to traverse outside the intended directory by supplying a crafted filename. Attackers can exploit this path traversal weakness to execute arbitrary commands with high privileges on the server. The vulnerability is specific …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-14257] brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand()…
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps the result count under the limit while making each result progressively longer, so total memory scales with both count …
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65906] In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was po…
In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65908] In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executabl…
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65608] Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory…
Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling call_user_func_array() on attacker-influenced input, validating only that the target is callable (is_callable()) without restricting dangerous functions such as exec, system, passthru, or shell_exec. Because FlexDirectory registe…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65510] Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Cross Site Scripting (XSS) in PeproDev Ultimate Invoice
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65511] Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education Wor…
Unauthenticated Cross Site Scripting (XSS) in Manual - Documentation, Knowledge Base & Education WordPress Theme
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65492] Unauthenticated Cross Site Scripting (XSS) in Dokan Pro <= 5.0.0 versions.
Unauthenticated Cross Site Scripting (XSS) in Dokan Pro
J Alto vulnerabilidad
23/07/2026
[CVE-2026-64806] In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project tr…
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
J Alto vulnerabilidad
23/07/2026
[CVE-2026-64807] In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied lin…
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration
J Alto vulnerabilidad
23/07/2026
[CVE-2026-64808] In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project tr…
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling
J Alto vulnerabilidad
23/07/2026
[CVE-2026-64809] In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project tr…
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter
J Alto vulnerabilidad
23/07/2026
[CVE-2026-64811] In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting proje…
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration
J Alto vulnerabilidad
23/07/2026
[CVE-2026-64802] In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trus…
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration