Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 50 min
Buscando: "Quest" — 1674 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
11/09/2026
Fuga de memoria en middleware compression de Node.js y Express (CVE-2026-87776)
El middleware compression para Node.js y Express en versiones anteriores a 1.8.2 presenta una vulnerabilidad que causa fuga de memoria nativa de zlib cuando clientes abortan conexiones durante respuestas comprimidas. Un atacante remoto puede agotar recursos del servidor mediante desconexiones repetidas y prematuras, impactando la disponibilidad de aplicaciones web y API REST en entornos de producción de LATAM.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-87908] multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1…
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An unauthenticated attacker can send a single request whose part carries a very large volume of header bytes, forcing the parser to buffer all of them and …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-82097] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-80380] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized ac…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88045] rclone is a command-line program to sync files and directories to and from different cloud storage p…
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to multipart.NewRW().Reserve before reading request-body bytes. waitForTurn admits the current part and one oversized part when the buffer is empty despite -…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45747] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88887] Renovate is a dependency update automation tool. When listing tags/digests for a container image, Re…
Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the same origin as the original registry. A malicious or compromised container registry can therefore s…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88880] Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagi…
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88872] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sending a GET request. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, sets or clears any user's channel password without C…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88873] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request fo…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrators' browsers to request the endpoint, copying sensitive application log…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88876] AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vu…
AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() without password validation. Attackers can request the seo.php endpoint with a video ID to obtain the direct MP4 URL and read protected media bytes witho…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88870] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request fo…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation. Attackers can craft malicious pages with image tags pointing to savePublicKey.json.php to replace a logged-in victim's PGP 2FA public key, causing lockout or enabling account takeover if the attacker kn…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88863] capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank aga…
capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /private/invite_new_user_to_org endpoint only requires the org.update_user_roles permission for org_super_admin invitations, so an authenticated user holding only the o…
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.14 permite denial of service remoto
GeoVision GV-LPC2211 versión 1.14 (260903) contiene un fallo de validación en campos de longitud variable en múltiples manejadores de solicitudes VLSVR, permitiendo que atacantes no autenticados causen el colapso del servicio. Esta vulnerabilidad afecta principalmente a sistemas de vigilancia y control de acceso implementados en infraestructuras altas de México y Latinoamérica, generando riesgo de indisponibilidad operativa.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite denegación de servicio remota
La cámara IP GeoVision GV-LPC2211 versión 1.13 presenta una falla en la validación de tokens ONVIF WS-Discovery que permite a atacantes remotos sin autenticación corromper el estado de control de pila y crashear el proceso de descubrimiento. Esta vulnerabilidad afecta directamente la disponibilidad de sistemas de videovigilancia altas en infraestructuras de seguridad física de empresas, data centers y operaciones en LATAM.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-82925] The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized…
The Site Reviews WordPress plugin before 8.3.0 does not prevent request data from being deserialized, and derives the key protecting that data by padding out the site's WordPress nonce key, which makes the key publicly computable on installs where that key is absent, left at its sample value, or too short to be secret. This allows unauthenticated users to inject arbitrary PHP objects on such insta…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-49363] An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node detai…
An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-87933] A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJS…
A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87996] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 unt…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwright browser resolve it again in the sync and async request interceptors. An authenticated user controlling authoritative DNS could return a public ad…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87011] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 unt…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and signing keys before validating a submitted logout token. Each request repeated uncached network fetches, and the signing-key lookup blocked the async eve…