Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 6907 resultados ✕ Limpiar búsqueda
13,970
Total alertas
3187
Críticas
10511
Altas
8
Ransomware
1126
Esta semana
RSS
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47480] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an unc…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause an uncaught exception. A successful exploit of this vulnerability might lead to denial of service.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47482] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missin…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory after effective lifetime. A successful exploit of this vulnerability might lead to denial of service.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47736] Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY p…
Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, when PROXY protocol v1 support is enabled, Puma reads incoming bytes into an internal buffer while waiting for CRLF to determine whether a PROXY v1 line is present, allowing an attacker that continuously sends bytes without CRLF to cause unbounded in-process memory growth and additional CPU cost from repeatedly…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47737] Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vuln…
Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until 7.2.1 and 8.0.2, Puma is vulnerable to source IP spoofing when set_remote_address proxy_protocol: :v1 is enabled and persistent connections are used because Puma incorrectly re-parses PROXY protocol headers after each keep-alive request on the same connection, allowing an attacker to inject a second PROXY header and overwrite R…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47476] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncont…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47477] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stac…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a stack-based buffer overflow. A successful exploit of this vulnerability might lead to denial of service.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-47478] NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the us…
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause the use of an expired file descriptor. A successful exploit of this vulnerability might lead to denial of service.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15709] A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. …
A flaw was found in libsoup's WebSocket implementation when using the permessage-deflate extension. The extension's decompression loop (inflate()) processes data in chunks without enforcing an upper boundary limit on the output buffer size. While libsoup limits the incoming compressed frame size via max_incoming_payload_size, it fails to track or limit memory allocation during decompression. A sep…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15711] A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to …
A vulnerability was found in libsoup's WebSocket frame parsing implementation. The library fails to validate length rules specified in RFC 6455 §5.5, which mandates that all WebSocket control frames (e.g., PING, PONG, CLOSE) contain a payload of 125 bytes or less. A remote, unauthenticated attacker can exploit this by sending a non-compliant, oversized control frame. Because the parser handles thi…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15720] In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mob…
In Open5GS through version 2.7.7 a pre-authentication heap out-of-bounds read in the AMF NAS 5GS mobile-identity handler may result in subscriber-wide denial of service.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-4017] Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with lo…
Buffer Overflow in the entry handler of the TraceEvent() system call could allow an attacker with local access to cause information disclosure, data tampering or a crash of the QNX Neutrino kernel.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-55002] External control of file name or path in SQL Server allows an authorized attacker to elevate privile…
External control of file name or path in SQL Server allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15703] A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulner…
A vulnerability was detected in SourceCodester Simple and Nice Shopping Cart Script 1.0. This vulnerability affects unknown code of the file /admin/userproductdeletequery.php. Performing a manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-60081] DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column …
DBI::ProfileData versions before 1.651 for Perl do not limit the path index. The path index column of profile dump files is used to allocate an array of data for the parser. An unbounded value allows an attacker to specify a large index and consume available memory.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-55651] Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposu…
Easy!Appointments is a self hosted appointment scheduler. In version 1.5.2, an Excessive Data Exposure vulnerability in the customers search endpoint allows an authenticated user to obtain appointment hashes belonging to other users. Using these hashes, an attacker can modify or delete appointments of other providers, resulting in an Appointments Takeover. Version 1.6.0 fixes the issue.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/07/2026
[CVE-2026-12523] Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (…
Summary Cloudflare quiche's HTTP/3 layer was discovered to be vulnerable to resource exhaustion (i.e., memory) by means of specially crafted HTTP/3 frames. Impact HTTP/3 defines multiple frame types to support HTTP message exchanges and connection management. Each frame has a length and a payload whose length depends on the frame type. quiche was found to be vulnerable when parsing some …
M Alto vulnerabilidad
14/07/2026
[CVE-2026-12707] Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to un…
Summary Cloudflare quiche was discovered to be vulnerable to memory resource exhaustion due to unbounded queuing of post-handshake client migration events. Impact quiche supports the connection migration features described in Section 9 of RFC 9000, which allows a single QUIC connection to survive changes in the network path. Although quiche implements the protections described in Section …
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15392] DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrust…
DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location. The complete_table_name method builds the absolute table file path without checking whether the file is a symbolic link. A link inside the data directory can point to a table file at any path outside of the configured f_dir and f_dir_search directories. Callers of file-based drivers c…
M Alto vulnerabilidad
14/07/2026
[CVE-2026-51105] Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a den…
Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via the OP_SERVERMESSAGE Handler.
M Alto vulnerabilidad
14/07/2026
[CVE-2026-15736] Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: I…
Snowflake SQLAlchemy versions prior to 1.11.0 contain several security vulnerabilities, including: Improper handling of user-supplied column identifiers in merge operations could allow SQL injection through attacker-controlled input keys. An attacker may be able to exploit this through request field names in a dynamic upsert endpoint, potentially enabling read access to data visible to the applica…