Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 1677 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84761] Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache <= 7.9 versions.
Unauthenticated Server Side Request Forgery (SSRF) in LiteSpeed Cache
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85212] CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServic…
CRMEB contains an authentication bypass vulnerability in the verifyAuth() method of SystemRoleServices.php that returns true from both conditional branches. Sub-administrators and accounts with no roles can access restricted admin endpoints by exploiting the inert role check that always permits requests.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85214] vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users …
vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, and disable accounts including administrators to cause denial of service.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85179] Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch…
Label Studio through 1.23.0 fails to validate webhook URLs, allowing authenticated users to dispatch requests to internal services including RFC 1918 addresses and cloud metadata endpoints. Attackers can create webhooks targeting private networks and exfiltrate annotation data by enabling payload transmission in outbound requests.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85180] Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenti…
Ollama fails to validate redirect destinations when pulling tensor-layer models, allowing unauthenticated attackers to redirect blob downloads to arbitrary hosts. An attacker can control a registry, serve a malicious tensor-layer manifest, and cause the server to issue GET requests to internal hosts including cloud metadata endpoints.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85182] vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to t…
vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account's current password in the request body.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85178] Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKey…
Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can retrieve decrypted upstream provider credentials for other tenants, including plaintext OpenAI, Anthropic, and Bedrock API key…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85174] SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file wh…
SiYuan before v3.8.2 logs API tokens from query parameters in plaintext to an accessible log file when full-text search requests exceed timing thresholds. Authenticated attackers can read the log file via the getFile endpoint to recover admin API tokens and gain permanent administrative access.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85164] WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set…
WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before fetching them. Authenticated API clients can supply internal URLs to fetch cloud metadata or internal services, with responses written to publicly accessible web paths for retrieval.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85160] AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerabili…
AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visit…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85124] @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash …
@fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP request handler skips the destination validation that the WebSocket path performs, and the underlying reply-from library only rejects forward-slash traversal, so a request containing backslash dot-segments can escap…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84645] In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their conf…
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84649] In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c…
In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (both inclusive), an HTTP endpoint serving dynamically generated JavaScript resources embeds the user's cross-site request forgery (CSRF) token (crumb) as a string literal, allowing attackers with contr…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-66842] BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrat…
BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). Impact: This vulnerability may allow an authenticated attacker with network access to the BIG-IP management interface to escalate privileges by creating administrative accounts on the BIG-IP system. Th…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-18329] Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access …
Description NGINX JavaScript (njs) and QuickJS (qjs) engines have a vulnerability when a js_access handler performs asynchronous request body processing and an exception is thrown during asynchronous access-control evaluation before an explicit access denial is returned. An unauthenticated attacker can exploit this vulnerability by sending a crafted HTTP request that triggers an error condition i…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad de autorización en Craft CMS 5.0.0-RC1 a 5.10.10 permite reemplazo no autorizado de activos
Craft CMS versiones 5.0.0-RC1 hasta 5.10.10 contienen un fallo de autorización en AssetsController::actionReplaceFile que permite a usuarios autenticados con permisos limitados reemplazar archivos sin validación de permisos. El defecto ocurre cuando se omite el parámetro assetId, resolviendo el activo destino por carpeta y nombre de archivo después de las verificaciones de permisos. Empresas en LATAM con portales de contenido, sitios de agencias digitales o plataformas de gestión de medios basadas en Craft CMS están potencialmente expuestas.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad CSRF sin autenticación en Activity Log <= 2.13.1
Se ha identificado una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) sin requerimiento de autenticación en Activity Log versiones 2.13.1 y anteriores, con puntuación CVSS de 7.1. Esta falla permite a atacantes ejecutar acciones no autorizadas en sistemas vulnerables mediante solicitudes manipuladas. Organizaciones en LATAM que utilicen este componente deben evaluar su exposición inmediatamente.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad CSRF en Simply Schedule Appointments <= 1.6.12.23 permite acciones no autorizadas
Se ha identificado una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) sin autenticación en Simply Schedule Appointments en versiones hasta 1.6.12.23. Esta vulnerabilidad permite a atacantes realizar acciones no autorizadas en nombre de usuarios legítimos, afectando principalmente a empresas de servicios, clínicas y consultorías en LATAM que utilizan este plugin para gestionar citas. Con un CVSS de 8.8, representa un riesgo alto para la integridad de datos y la continuidad operativa.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad CSRF alta en Mang Board WP versiones ≤2.3.8 permite ataques no autenticados
Se ha identificado una vulnerabilidad de Falsificación de Solicitud entre Sitios (CSRF) no autenticada en el plugin Mang Board WP hasta la versión 2.3.8, con puntuación CVSS 8.8. Esta falla permite a atacantes realizar acciones maliciosas en sitios WordPress afectados sin requerir credenciales, poniendo en riesgo la integridad de contenido, datos de usuarios y configuraciones administrativas en empresas de México y Latinoamérica que dependen de este plugin.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19219] In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog …
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.