Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 984 resultados ✕ Limpiar búsqueda
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1782
Esta semana
RSS
M Alto vulnerabilidad
23/07/2026
[CVE-2026-63313] 9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fet…
9Router before 0.4.72 contains a server-side request forgery (SSRF) vulnerability in the /v1/web/fetch endpoint. The endpoint accepts a user-controlled url parameter and passes it to a configured external scraping provider (Firecrawl, Jina Reader, Tavily, or Exa) to fetch content. The URL is only validated as syntactically valid via new URL() with no blocklist for private IP ranges, cloud metadata…
M Alto vulnerabilidad
23/07/2026
[CVE-2024-58353] Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting (XSS…
Cal.com (repository calcom/cal.diy) in versions
M Alto vulnerabilidad
23/07/2026
[CVE-2024-58355] Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability…
Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting vulnerability. The single booking view (e.g., https://app.cal.com/booking/) renders booking-question field labels via React's dangerouslySetInnerHTML without sanitizing or escaping user input. An attacker who can create an event type with a malicious booking-question label can inject arbitrary HTML/JavaScrip…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-49035] The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate reques…
The affected product is vulnerable to a heap-based buffer overflow via a crafted MMS Initiate request. Remote code execution (RCE) has been demonstrated when ASLR is disabled; memory corruption or denial of service may occur in configurations where ASLR is enabled.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-50032] A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network a…
A NULL pointer dereference in the MMS Write Named Variable List handler, which may allow a network adjacent attacker to crash the server by sending a WriteRequest with an empty listOfData field.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-50039] The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to …
The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to cause a memory corruption via a Read Request.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-15212] The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up t…
The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' array and therefore evaluates to false via get_global_boolean_var(); as a result, …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-16756] Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the de…
Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-server might allow remote attackers to cause a denial of service by opening many connections and sending partial requests that are never completed, exhausting server sockets and tasks. To mitigate this issue, users should upgrade to aws-smithy-http-ser…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-44909] Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A re…
Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams requesting large r…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65916] CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in…
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status…
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65540] Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 version…
Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65539] Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65516] Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice <= 2.2.6 versions.
Unauthenticated Server Side Request Forgery (SSRF) in PeproDev Ultimate Invoice
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65488] Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor <= 1.6.2 ve…
Unauthenticated Cross Site Request Forgery (CSRF) in LA-Studio Element Kit for Elementor
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57785] Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing <= 1.2.63 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in ApusListing

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/07/2026
[CVE-2026-57626] Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This…
Cross-Site Request Forgery (CSRF) vulnerability in MailPoet allows Cross Site Request Forgery. This issue affects MailPoet: from 5.30.0 through 5.33.0.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65757] Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules An…
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose restricted module data to authenticated users without the required module permissions or valid request tokens.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-64876] Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP ext…
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-65430] Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credent…
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.
M Alto vulnerabilidad
23/07/2026
[CVE-2026-64799] Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users …
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible fold…