Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 44 min
Buscando: "Quest" — 1671 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-87971] The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a requ…
The If-So Dynamic Content WordPress plugin before 1.10.2 does not validate the URL scheme of a request-supplied value before reflecting it into a link on an admin page, allowing attackers to execute arbitrary JavaScript in the browser of a logged-in user who opens a crafted link.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106492] Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @back…
Backstage is an open framework for building developer portals. Prior to 0.16.1 and 0.17.8, the @backstage/backend-defaults package is affected by improper preservation of access restrictions during service credential delegation. An external service credential configured with access restrictions (e.g., read-only) could bypass those restrictions by routing requests through plugin delegation paths. T…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106486] Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-…
Backstage is an open framework for building developer portals. Prior to 0.3.10 in @backstage/plugin-scaffolder-backend-module-bitbucket-cloud and 0.2.25 in @backstage/plugin-scaffolder-backend-module-bitbucket-server, the Bitbucket pull-request Scaffolder actions did not sufficiently validate filesystem paths. An authenticated user who can execute an eligible template and influence an allowed Bitb…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-103009] Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information …
Authorization Bypass Through User-Controlled Key (CWE-639) in Elasticsearch can lead to Information Disclosure via a specially crafted cross-cluster search request that references an unauthorized shard identifier. Elasticsearch contains an authorization bypass weakness in its handling of cross-cluster search requests made through the Remote Cluster Security (RCS) 2.0 model. An authorization check …
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102160] An operating system (OS) command injection vulnerability in CloudVision CUE backup management may al…
An operating system (OS) command injection vulnerability in CloudVision CUE backup management may allow an authenticated Super User to submit a crafted backup request and execute arbitrary commands with the privileges of the affected service.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-102155] An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application all…
An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-101154] An authenticated remote attacker with specific permissions can read or write files on the platform f…
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104073] NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allow…
NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom links" permission to steal session cookies and API tokens of other users by exposing the raw Django HttpRequest object to the Jinja2 template context. Attackers can craft a custom link template embedding request.COOKIES['sessionid'] or a user's API to…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105858] Payload is a free and open source headless content management system. In versions before 3.90.0 and …
Payload is a free and open source headless content management system. In versions before 3.90.0 and canary versions before 4.0.0-canary.34, a crafted request to the public first-register operation can execute code remotely when local authentication is enabled and no initial user has been created. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-104069] HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() wh…
HortusFox before 6.2 contains a remote code execution vulnerability in ThemeModule::startImport() where an uploaded ZIP archive is extracted directly into the public web root before any validation of file names, extensions, or content is performed. An authenticated administrator can upload a crafted theme archive containing a PHP file and an .htaccess file to re-enable execution, then request it u…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106038] Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allo…
Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object via Remove, RemoveByRegex, RemoveAll and BatchRemove on the coro_rpc port. Attackers can send forged requests with the force flag set to bypass lease checks, wipe keys matching any regex, or clear the entire store, causing cache loss and reques…
M Alto vulnerabilidad
Hace 3 días
Ejecución remota de código autenticada en Craft CMS 5.10.13.2
Craft CMS 5.10.13.2 contiene una vulnerabilidad de ejecución remota de código (RCE) en el panel de control que afecta a usuarios autenticados. Un atacante con acceso básico al panel puede manipular propiedades de componentes y tipos de entrada para ejecutar código arbitrario. Esta vulnerabilidad impacta principalmente a agencias web, desarrolladores y empresas en LATAM que utilizan Craft CMS como gestor de contenidos.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39728] Unauthenticated Server Side Request Forgery (SSRF) in Instapage Plugin <= 3.7.2 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Instapage Plugin
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39719] Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versio…
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39724] Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions.
Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-57559] Memory corruption while processing service requests.
Memory corruption while processing service requests.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105762] Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/…
Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105761] Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/&lt;…
Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/&lt;app_id&gt;/server endpoint in api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to retrieve an AppMCPServer by the client-supplied server ID without verifying that the server belonged to the requested application and tenant. An authenticated workspace member could therefore…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105634] Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_up…
Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrat…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105628] Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronizatio…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by default. An attacker can provide an avatar URL that redirects to an internal-only resource, such as a metadata endpoint, and Plane uploads the fetched response…