Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 9 horas
Buscando: "Multiple Vendors" — 6766 resultados ✕ Limpiar búsqueda
13,736
Total alertas
3106
Críticas
10358
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
03/07/2026
[CVE-2026-26307] Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searc…
Gitea versions before 1.25.5 do not enforce a timeout on git grep searches, allowing expensive searches to consume server resources.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27657] Gitea versions before 1.25.5 allow a user to change another user's primary email address.
Gitea versions before 1.25.5 allow a user to change another user's primary email address.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-27660] Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the requ…
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-22555] Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first…
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-24451] Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public t…
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-24690] Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull reque…
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-25038] Gitea 1.26.2 allows unauthorized users to access labels of private organizations.
Gitea 1.26.2 allows unauthorized users to access labels of private organizations.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-25712] Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for…
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-20779] Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a vali…
Gitea versions from 1.5.0 before 1.26.3 have a TOTP single-use enforcement defect that allows a valid TOTP code to be accepted more than once across web two-factor authentication flows and the Basic Auth X-Gitea-OTP path.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14605] A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the funct…
A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the library bsp/loongson/ls1cdev/libraries/ls1c_can.h of the component ls1c CAN Handler. Such manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about …
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14606] A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function…
A security flaw has been discovered in RT-Thread up to 5.0.2. Affected by this issue is the function CAN_Receive in the library bsp/synwit/libraries/SWM341_CSL/CMSIS/DeviceSupport/SWM341.h of the component SWM341 CAN Handler. Performing a manipulation results in stack-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be used for a…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-58379] A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulner…
A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitrary code execution or a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file. The vulnerability occurs because the software incorrectly calculates buffer sizes when processing low bit-depth images, leading to an ov…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14459] Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in …
Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from
M Alto vulnerabilidad
03/07/2026
[CVE-2026-14460] Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardu…
Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue affects pardus-software: from
M Alto vulnerabilidad
03/07/2026
[CVE-2026-10055] In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker…
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full response body to the caller. Because the destination URL is neither validated nor allowlisted, a remote attacker with access to the Theia service co…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-13341] A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.…
A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-10054] In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged term…
In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal, /services/terminals/:id) without service-level authentication. WebSocket origin validation in @theia/core is fail-open: connections are accepted when the Origin header is missing or when no THEIA_HOSTS allowlist is configured (the default). The …
M Alto vulnerabilidad
03/07/2026
[CVE-2026-9148] The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the gu…
The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 This is due to insufficient output escaping in the getCommentAuthor() function, which interpolates the stored comment_author_url value directly into single-quoted HTML attributes without applying esc_url() or esc_attr(). This mak…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-4967] In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to rem…
In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-13040] The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cro…
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter in all versions up to, and including, 9.2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injecte…