Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 7570 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1810
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-13212] The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device write…
The Zephyr virtio driver does not validate the descriptor-chain head id that the virtio device writes into the used ring. In virtio_isr() (drivers/virtio/virtio_common.c), the device-written vq->used->ring[idx].id is used directly as an index into vq->recv_cbs[] and vq->desc[], which are both allocated with exactly vq->num entries. recv_cbs[] holds {cb, opaque} callback entries, and the indexed ca…
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-21752] HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker una…
HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented security flaws.
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-78414] Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before vers…
Cross-site scripting in the Web Administration interface of Network Optix Nx Witness VMS before version 6.1.3 on Linux, Windows and MacOS allows an adjacent-network attacker to execute arbitrary JavaScript in the browser of an authenticated administrator and steal the administrator's session token, resulting in Administrator Account Takeover. An attacker who controls an Nx server on the same netwo…
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-39915] TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to injec…
TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized carriage return and line feed sequences in the rt URL parameter, which is reflected into Set-Cookie response headers. Attackers can craft malicious requests to induce authenticated users to execute arbitrary JavaScript in th…
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-78248] A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is…
A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-78367] A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source arc…
A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execu…
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-76848] TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression …
TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family drivers, createSelectDistinctExpression in src/query-builder/SelectQueryBuilder.ts joins that array and interpolates the result into the generated statement as SELECT DISTINCT ON (values), with no escaping, quoting, identifier validation or allowlist, an…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-76843] The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose Clus…
The official Flair wheels for 0.15.0 and 0.15.1 still contain flair/models/clustering.py, whose ClusteringModel.load static method returns pickle.loads(joblib.load(str(model_file))) and so executes arbitrary Python while loading a model file. Loading a model supplied by an attacker therefore runs that attacker's code with the privileges of the loading process. This is the same sink and the same fi…
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-76844] webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the reque…
webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset. The guard, UP_PATH_REGEXP applied to path.normalize(`./${pathname}`), only matches ".." that stands as a whole path segment, while the containment test is the string comparison pathname.startsWith(publicPathPathna…
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-76841] Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before …
Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional default: RerankModel._get_tokenizer in xinference/model/rerank/core.py, SentenceTransformerRerankModel.load in xinference/model/rerank/sentence_transformers/core.py,…
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-59567] Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege esca…
Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context.
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-59565] A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on …
A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-59566] A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected ver…
A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.
M Alto vulnerabilidad Nuevo
Hace 18 min
[CVE-2026-78247] A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affec…
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad Nuevo
Hace 1 hora
Inyección SQL alta en FluentCRM Pro versiones <= 3.1.12
Se ha identificado una vulnerabilidad de inyección SQL en FluentCRM Pro que afecta versiones hasta la 3.1.12, permitiendo a atacantes ejecutar comandos SQL arbitrarios a través del módulo de autoría. Esta vulnerabilidad impacta directamente a empresas en México y Latinoamérica que utilizan esta plataforma de automatización de marketing para gestionar datos de contactos y campañas sensibles.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 1 hora
Inyección SQL alta en itsourcecode Online Clinic Management System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en el módulo de login administrativo (success/login.php) de itsourcecode Online Clinic Management System versión 1.0, permitiendo ejecución remota no autenticada mediante manipulación del parámetro Username. La vulnerabilidad ha sido divulgada públicamente (CVSS 7.3) y afecta directamente a clínicas y centros médicos en LATAM que utilizan este sistema para gestionar datos sensibles de pacientes.
M Alto vulnerabilidad Nuevo
Hace 1 hora
Vulnerabilidad XSS sin autenticación en Urna versiones ≤2.6.2 (CVSS 7.1)
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación en Urna versiones 2.6.2 e inferiores que permite a atacantes inyectar código malicioso y comprometer sesiones de usuarios. Esta vulnerabilidad afecta especialmente a plataformas de votación y gestión electoral en organismos públicos y privados de LATAM. El riesgo es alto dado que no requiere credenciales previas para explotarse.
M Alto vulnerabilidad Nuevo
Hace 1 hora
XSS no autenticado en Social Media & Share Icons versión 2.9.9 y anteriores
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) no autenticado en el plugin Social Media & Share Icons en versiones hasta la 2.9.9, afectando principalmente a sitios WordPress en México y Latinoamérica. Un atacante podría inyectar código malicioso que se ejecute en navegadores de usuarios legítimos, comprometiendo sesiones y datos sensibles. Con puntuación CVSS 7.1, representa un riesgo medio-alto para plataformas e-commerce, instituciones financieras y sitios corporativos.
M Alto vulnerabilidad Nuevo
Hace 1 hora
Vulnerabilidad alta de Inclusión de Archivos Local sin autenticación en Verdure Core <= 1.2
Se ha identificado una vulnerabilidad de Inclusión de Archivos Local (LFI) sin autenticación en Verdure Core versiones 1.2 y anteriores (CVSS 8.1). Esta falla permite a atacantes acceder a archivos sensibles del servidor sin necesidad de credenciales, comprometiendo datos confidenciales y configuraciones altas. Empresas en LATAM que utilizan esta plataforma en producción están expuestas a exposición de información y potencial ejecución remota de código.
M Alto vulnerabilidad Nuevo
Hace 1 hora
[CVE-2026-66584] XSS sin autenticación en 12 Step Meeting List <= 3.19.16
Se identificó una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación en el plugin 12 Step Meeting List en versiones hasta la 3.19.16, permitiendo a atacantes inyectar código malicioso que afecta a usuarios visitantes. Empresas en LATAM que administren sitios comunitarios, grupos de apoyo o directorios de reuniones con este plugin están expuestas a robo de sesiones, credenciales y datos sensibles. Con CVSS 7.1, representa un riesgo significativo si el sitio maneja información personal o transacciones.