Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 9 horas
Buscando: "Multiple Vendors" — 6766 resultados ✕ Limpiar búsqueda
13,736
Total alertas
3106
Críticas
10358
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
04/07/2026
[CVE-2025-71367] picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, all…
picklescan before 0.0.34 fails to detect _operator.attrgetter function calls in pickle payloads, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle files using _operator.attrgetter in reduce methods to execute arbitrary code when pickle.load() processes the file.
M Alto vulnerabilidad
04/07/2026
[CVE-2025-71369] picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.…
picklescan before 0.0.28 fails to detect malicious pickle files that use torch.utils.data.datapipes.utils.decoder.basichandlers in reduce methods, allowing attackers to bypass safety checks. Remote attackers can embed undetected malicious code in pickle files that executes during deserialization, enabling remote code execution.
M Alto vulnerabilidad
04/07/2026
[CVE-2025-71342] picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode …
picklescan before 0.0.30 fails to detect malicious pickle files using idlelib.run.Executive.runcode in reduce methods. Attackers can embed undetected code in pickle files that executes during pickle.load, enabling remote code execution in PyTorch models and supply chain attacks.
M Alto vulnerabilidad
04/07/2026
[CVE-2025-71343] picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.Pars…
picklescan before 0.0.30 fails to detect malicious pickle files that exploit lib2to3.pgen2.pgen.ParserGenerator.make_label function in the reduce method. Attackers can craft malicious pickle files with embedded code that evades detection but executes arbitrary commands when pickle.load() is called.
M Alto vulnerabilidad
04/07/2026
[CVE-2025-71345] picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck._…
picklescan before 0.0.30 fails to detect malicious pickle files that invoke torch.utils.bottleneck.__main__.run_autograd_prof function. Attackers can embed undetected code in pickle files that executes during deserialization, enabling remote code execution.
M Alto vulnerabilidad
04/07/2026
[CVE-2025-71347] picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_…
picklescan before 0.0.33 fails to detect malicious pickle files using numpy.f2py.crackfortran.param_eval function in reduce methods, allowing attackers to bypass security checks. Remote attackers can embed undetected code in pickle files that executes during deserialization, enabling arbitrary code execution in applications loading untrusted pickle data.
M Alto vulnerabilidad
04/07/2026
[CVE-2025-71353] picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.Gu…
picklescan before 0.0.28 fails to detect malicious pickle files that exploit torch._dynamo.guards.GuardBuilder.get function in reduce methods. Attackers can craft pickle files with embedded code that evades picklescan detection and executes arbitrary commands when loaded.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
04/07/2026
[CVE-2026-54424] An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potent…
An Incorrect Use of Privileged APIs vulnerability in Unity Parsec on Windows hosts leads to a potential Elevation of Privilege. This issue affects Parsec through v2026-05-04.0. The patched version is Parsec for Windows version 150-104a. A user can generate a situation where there is an instance of parsecd.exe running as NT AUTHORITY\SYSTEM with a user-controlled value of the AppData environment va…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58419] Notification API leaks private issue metadata after access revocation
Notification API leaks private issue metadata after access revocation
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58421] Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58423] LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repo…
LFS authentication bypass via malformed SSH sub-verb allows unauthorized read access to private repositories
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58424] Permanent Fork PR Workflow Approval Gate Bypass
Permanent Fork PR Workflow Approval Gate Bypass
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28744] Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer to…
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27771] Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package s…
Gitea versions up to and including 1.26.1 have insufficient permission checks for Composer package source links, which can expose private or internal package source information.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27775] Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receiv…
Gitea 1.25.5 caches a branch-specific write-permission result across multiple refs in one pre-receive hook session, allowing a per-branch maintainer-edit grant to be reused for other refs and escalate to full repository write access.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27779] Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting publ…
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28699] Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed…
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28737] Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsReq…
Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28740] Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source obj…
Gitea versions up to and including 1.26.2 allow Git LFS object reuse to authorize private source objects for users who have repository access but lack Code-unit access.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-26231] Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to …
Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.