Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 1677 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
10/09/2026
[CVE-2026-87933] A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJS…
A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87996] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 unt…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then let the Playwright browser resolve it again in the sync and async request interceptors. An authenticated user controlling authoritative DNS could return a public ad…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87011] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 unt…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, the unauthenticated POST /oauth/backchannel-logout handler in backend/open_webui/utils/oauth.py fetched the OIDC discovery document and signing keys before validating a submitted logout token. Each request repeated uncached network fetches, and the signing-key lookup blocked the async eve…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79324] Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/mo…
Missing authorization in the Address Delete controller in Mageplaza GDPR for Magento 2 (mageplaza/module-gdpr) through 4.2.9 allows remote unauthenticated attackers to delete any customer's saved address, and to erase all stored addresses by iterating the address id, via a GET request to /customer/address/delete/id/{id}. The controller extends the legacy Action class instead of AbstractAccount, so…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79323] Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (mage…
Information disclosure in the blogComments GraphQL query in Magefan Blog GraphQL for Magento 2 (magefan/module-blog-graph-ql) through 2.2.1 allows remote unauthenticated attackers to obtain blog commenter email addresses and internal customer and admin identifiers via a POST request to /graphql.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-82563] An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emula…
An attacker could impersonate the camera and place themselves in a man-in-the-middle or device-emulation position. This permits manipulation of device status responses, observation of application requests, and potential triggering of firmware-update behavior.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86771] Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF gene…
Snipe-IT versions before 8.7.0 fail to HTML-escape the employee_num field in the acceptance PDF generator, allowing attackers with users.edit permission to inject img tags into TCPDF's writeHTML() function. Attackers can craft a malicious employee_num value containing an img tag with an arbitrary HTTP(S) URL to trigger server-side requests to internal services, cloud metadata endpoints, or externa…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86750] Snipe-IT versions <= 8.6.3 (fixed in 8.7.0) do not validate company assignment authorization before …
Snipe-IT versions
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86751] Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing auth…
Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkout acceptance notes that survive HTML escaping, are expanded by CommonMark parser, and resolved by laravel-mail-auto-embed via file_get_contents or curl, exfiltrati…
M Alto vulnerabilidad
09/09/2026
[CVE-2024-58382] league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdo…
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs designed to trigger worst-case performance, and sending multiple requests in parallel exhausts CPU resources and PHP-FPM processes.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad SSRF alta en Lara Dashboard 1.3.1 permite lectura de credenciales IAM
Lara Dashboard versiones hasta 1.3.1 contiene una vulnerabilidad de falsificación de solicitudes del lado del servidor (SSRF) en el endpoint POST /api/admin/builder/markdown/fetch. Usuarios autenticados pueden obtener URLs arbitrarias y acceder a servicios HTTP internos, metadatos en la nube e incluso credenciales IAM sin validación de host ni restricciones de redirección. En entornos de AWS, Azure o Google Cloud utilizados por empresas LATAM, esta vulnerabilidad expone acceso directo a tokens de identidad y secretos almacenados en servicios internos.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad XSS almacenado en SiYuan anterior a v3.8.2 afecta búsqueda de activos
SiYuan versiones anteriores a v3.8.2 contienen una vulnerabilidad de cross-site scripting (XSS) almacenado en la función de búsqueda de activos. Atacantes autenticados pueden inyectar código malicioso en nombres de archivos que se ejecuta en el navegador de usuarios legítimos, permitiendo manipulación de estado de aplicación y ejecución de solicitudes API no autorizadas. El riesgo es moderado-alto en entornos colaborativos donde múltiples usuarios acceden a repositorios compartidos.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad XSS almacenado alta en SiYuan anterior a v3.8.2 afecta vista previa de activos
SiYuan antes de la versión 3.8.2 contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en la función de vista previa de activos de búsqueda. Los atacantes pueden insertar contenido malicioso en activos de texto dentro de espacios de trabajo para ejecutar código JavaScript con privilegios autenticados. Esto permite acceso no autorizado a APIs internas y manipulación de datos en la instancia SiYuan, representando riesgo significativo para organizaciones que almacenan información sensible en esta plataforma de gestión de conocimiento.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad alta en PasswordPusher: condición de carrera permite eludir límites de visualización
PasswordPusher anterior a versión 2.11.1 contiene una vulnerabilidad de time-of-check-to-time-of-use que permite a atacantes no autenticados acceder múltiples veces a secretos de un solo uso enviando solicitudes concurrentes al endpoint de visualización, antes de que se incremente el contador de vistas y expire el contenido. Afecta sistemas de gestión de credenciales en empresas de México y LATAM que dependen de esta herramienta para compartir contraseñas temporales.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad de XSS en SiYuan anterior a v3.8.2 permite ejecución de código JavaScript
SiYuan versiones anteriores a v3.8.2 no codifica correctamente las rutas de plantillas de cuadernos persistidas en atributos HTML, permitiendo ataques de cross-site scripting (XSS). Un atacante puede crear rutas de plantilla maliciosas que se ejecutan cuando un usuario abre la configuración del cuaderno, comprometiendo datos sensibles y manipulando el estado de la aplicación mediante solicitudes API del mismo origen. Afecta principalmente a organizaciones que utilizan SiYuan para gestión de notas y documentación en entornos colaborativos.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
09/09/2026
[CVE-2026-78490] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Restriction of Excessive Authentication Attempts vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to client-side request forgery.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-79635] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-80099] Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because th…
Several Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request — performs an HMAC-style Bearer token comparison that degenerates when `HiiveConnection::g…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-80123] Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5…
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-84068] The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before u…
The Quentn WP WordPress plugin before 1.2.15 does not adequately escape a request parameter before using it in an unprepared SQL query, allowing unauthenticated attackers to extract arbitrary data from the database via SQL injection.