Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 1677 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
09/09/2026
[CVE-2026-14962] The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and es…
The ELEX WooCommerce Request a Quote WordPress plugin before 2.4.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks and extract arbitrary data from the database.
M Alto vulnerabilidad
09/09/2026
[CVE-2026-87084] Tanium addressed a server-side request forgery vulnerability in Enforce.
Tanium addressed a server-side request forgery vulnerability in Enforce.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86806] A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within…
A weakness has been identified in opengeos GeoLibre up to 2.3.0. Impacted is the function _is_within_roots. This manipulation causes server-side request forgery. The attack can be initiated remotely. Upgrading to version 2.4.0 is recommended to address this issue. Patch name: b745f62e29fa37364686525a21eee5e5c0f8a369. It is recommended to upgrade the affected component.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-66304] Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose…
Server-side request forgery (ssrf) in Skype for Business allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81356] Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Co…
Inconsistent interpretation of http requests ('http request/response smuggling') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81357] Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a…
Server-side request forgery (ssrf) in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-82075] An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sha…
An uncontrolled resource consumption weakness exists in the request-handling path of the MongoDB sharded-cluster router process. A client that has network access to a router port and has not authenticated can supply connection-monitoring parameters that cause the server to expend CPU resources without any rate limiting, degrading or denying service to legitimate clients. No authentication, elevate…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86728] AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php…
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86721] AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cook…
AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86723] AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerabil…
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit an empty request to verifyChallenge.json.php to bypass PGP two-factor authentication and gain full authenticated access.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86718] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request fo…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrator browsers to delete all live transmission history or m…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86600] In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity t…
In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake f…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73314] XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handl…
XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header value. When the algorithm cannot be mapped to a supported hash function, the verification function incorrectly returns true instead of failing, causing…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73315] XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhoo…
XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback…
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en Reyrolle 7SR5 permite denegación de servicio remota
Se identificó una falla en el servidor web de Reyrolle 7SR5 (versiones anteriores a V2.70) que no limita adecuadamente los recursos del sistema al procesar múltiples solicitudes HTTP concurrentes. Un atacante no autenticado puede explotar esta vulnerabilidad para causar el colapso y reinicio del dispositivo, interrumpiendo sistemas altas de protección en subestaciones eléctricas. En LATAM, donde estos relés protegen infraestructura eléctrica esencial, el impacto operacional es severo.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta de escalada de privilegios en Reyrolle 7SR5 (CVSS 8.8)
Se ha identificado un fallo en los controles de autorización del lado del servidor en la interfaz de gestión web de Reyrolle 7SR5 en todas las versiones anteriores a V2.70. Un atacante autenticado con permisos bajos puede eludir las restricciones de control de acceso basado en roles (RBAC) manipulando datos de solicitudes para escalar privilegios a nivel administrativo. Esto afecta directamente a infraestructuras altas de distribución eléctrica y subestaciones en LATAM que dependen de estos dispositivos de protección.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81806] Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side …
Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-66767] SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a…
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the applic…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86539] knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embeddin…
knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86438] Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire a…
Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.