Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1790
Esta semana
RSS
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17665] Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ar…
Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17653] Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had com…
Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17654] Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform O…
Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17657] Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who h…
Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17658] Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute ar…
Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17660] Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowe…
Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
30/07/2026
[CVE-2026-17650] Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who …
Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/07/2026
[CVE-2025-69945] kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php…
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
M Alto vulnerabilidad
29/07/2026
[CVE-2025-69949] kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php v…
kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-67595] VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in t…
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, install…
M Alto vulnerabilidad
29/07/2026
[CVE-2025-67405] Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_passwo…
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.
M Alto vulnerabilidad
29/07/2026
[CVE-2025-67406] https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. …
https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the activate_case.php in parameter id endpoint of Advocate office management system. Unsanitized user input in the specified parameter is i…
M Alto vulnerabilidad
29/07/2026
[CVE-2025-67407] Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_studen…
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.
M Alto vulnerabilidad
29/07/2026
[CVE-2025-67408] Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.ph…
Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-50782] Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.Hrm…
Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML payload to read arbitrary files from the server via an out-of-band attack.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/07/2026
[CVE-2026-67437] OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17…
OliveTin gives access to predefined shell commands from a web interface. From 3000.0.0 until 3000.17.0, the service/internal/auth/otoauth2/restapi_auth_oauth2.go OAuth2 login handler stores per-login state in the registeredStates map on every /oauth/login request without expiring, deleting, or bounding entries, allowing an unauthenticated attacker to exhaust memory and cause a denial of service. T…
M Alto vulnerabilidad
29/07/2026
[CVE-2026-13308] Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. Th…
Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Home EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of WebSocket messages related to the OCPP service. …
M Alto vulnerabilidad
29/07/2026
[CVE-2026-6267] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.…
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to insufficient access controls on internal request handling.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-67432] MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.…
MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to 0.23.0, MCP::Server::Transports::StreamableHTTPTransport in the mcp gem reads and parses an entire JSON-RPC POST body without a size limit, allowing an unauthenticated remote attacker to exhaust process memory. This issue is fixed in version 0.23.0.
M Alto vulnerabilidad
29/07/2026
[CVE-2026-6102] MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulner…
MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MSI Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the NTIOLib_X64.sys driver. The issue …