Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 7967 resultados ✕ Limpiar búsqueda
14,165
Total alertas
3233
Críticas
10659
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
16/07/2026
[CVE-2026-59861] Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedd…
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs into Ruby double-quoted literals without escaping #, allowing attacker-controlled #{expr}, #$var, or #@var interpolation markers to in…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-59862] Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let …
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and PythonConventionService.RemoveInvalidDescriptionCharacters without newline sanitization, allowing generated inline comments to split and…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-5674] A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape s…
A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploiting PipeWire's PulseAudio compatibility layer. An attacker with minimal permissions within a sandboxed environment can load a malicious library, leading to arbitrary code execution outside the sandbox and potential compromise of the user's system.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-63304] AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/function…
AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers who can craft a valid encrypted codeToExec payload can break out of the single-quoted grep context and execute arbitrary OS commands as the web-server user.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-63305] AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint w…
AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Attackers who can craft a valid encrypted payload can inject arbitrary shell metacharacters into these fields to execute OS commands as the web-server user.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-63306] stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the…
stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint applications, and reach instance metadata endpoints by supplying malicious URLs or leveraging redirect chains to access inte…
H Alto vulnerabilidad
16/07/2026
[CVE-2026-35147] HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The applic…
HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access. The application fails to verify the user's authentication status when accessing specific API endpoints, allowing an unauthenticated attacker to interact with the APIs and perform unauthorized actions without valid credentials.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
H Alto vulnerabilidad
16/07/2026
[CVE-2026-35149] HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation…
HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's authentication responses, allowing them to gain unauthorized access to the application without verification.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-7543] The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' pa…
The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-15005] The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions …
The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on the execTemplate function. This makes it possible for unauthenticated attackers to execute arbitrary PHP code on the server by supplying a php://filter stream wrapper URI as the 'template' parameter, which bypasses …
M Alto vulnerabilidad
16/07/2026
[CVE-2026-15008] The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for …
The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the fr_token function in all versions up to, and including, 7.3.1.4. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execu…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12978] The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before ref…
The FunnelKit WordPress plugin before 3.15.0.6 does not escape a user-supplied parameter before reflecting it into the HTML response of one of its page-builder AJAX actions, allowing unauthenticated attackers to perform Reflected Cross-Site Scripting against logged-in users who open a crafted page. The affected action is only registered when the Divi /builder is active.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12525] The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be wri…
The Redux Framework WordPress plugin before 4.5.13 does not restrict which user meta keys can be written when saving custom profile fields, allowing users with at least the Subscriber role to escalate their privileges to Administrator by submitting a crafted value while updating their own profile, on sites where the Redux Framework WordPress plugin before 4.5.13's user-profile (Users extension) fe…
L Alto vulnerabilidad
16/07/2026
[CVE-2026-53366] In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on th…
In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap, but the fraggap bytes carried over from the previous skb ar…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-13042] The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Con…
The RPB Chessboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 8.1.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. WordPress's save-time kses sanitizat…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
16/07/2026
[CVE-2026-12753] The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable t…
The Advance Product Search- Voice & Ajax Search for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 's' and 'match' parameter in all versions up to, and including, 1.4.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQ…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-1609] A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is e…
A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provide…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-23538] A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote …
A vulnerability was identified in the Feast Feature Server's `/ws/chat` endpoint that allows remote attackers to establish persistent WebSocket connections without any authentication. By opening a large number of simultaneous connections, an attacker can exhaust server resources—such as memory, CPU, and file descriptors—leading to a complete denial of service for legitimate users.
M Alto vulnerabilidad
16/07/2026
[CVE-2026-3842] A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine …
A flaw was found in QEMU. This vulnerability allows a local attacker within a guest virtual machine to write data beyond its allocated memory. This occurs when cpu_physical_memory_map() returns a shorter length than expected, leading to an out-of-bounds write. Successful exploitation could result in unauthorized access to guest memory or corruption of heap-allocated objects, potentially causing in…
M Alto vulnerabilidad
16/07/2026
[CVE-2026-48863] A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verificat…
A flaw was found in libsolv. A stack-based buffer overflow vulnerability exists in the PGP verification component due to incorrect length handling when copying EdDSA 's' MPI into a stack buffer. A remote attacker could craft a malicious Ed25519 PGP signature with mismatched MPI lengths. Processing this crafted signature could lead to a denial of service in automated package or repository processin…