Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 1677 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19723] The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properl…
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPr…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-12526] The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the reques…
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a publicly reachable front-end form whose user-update action targets an existing ad…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-12865] The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters be…
The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one on the Galleries/Albums list page), so an unauthenticated attacker can craft a link that, when opened by a logged-in administrator (or, for the first sink, a contributor), executes arbitrary JavaScrip…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84715] FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSu…
FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84700] PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the cl…
PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates …
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84482] WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_d…
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration changes.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84476] WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers…
WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84366] Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/co…
Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta["is_secure"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A n…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-73780] A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a …
A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-8712] Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticat…
Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious `uri` query parameter to the HTTP API. Attackers can pass arbitrary `tcp://` or `unix://` URIs to affected endpoints including /api/info, /api/speech-to-text, and /api/text-to-speech to overr…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84268] A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious …
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrup…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-18780] Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft…
Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84218] A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-co…
A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only reje…
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad alta en Kyverno anterior a 1.16.4 expone tokens de servicio en solicitudes HTTP
Kyverno versiones anteriores a 1.16.4 adjunta automáticamente el token de la ServiceAccount del controlador de admisión a solicitudes HTTP salientes en modo apiCall sin validación explícita de autorización. Un atacante puede exfiltrar este token dirigiendo solicitudes apiCall a servidores externos o controlados, comprometiendo completamente las políticas de Kyverno y los recursos del cluster Kubernetes.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad SSRF alta en Kyverno anterior a 1.18.0 permite inyección de solicitudes HTTP
Kyverno antes de la versión 1.18.0 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en apiCall.service.url que permite a usuarios autenticados enviar peticiones HTTP arbitrarias mediante inyección de entrada controlada por el usuario a través de sustitución de variables. Los atacantes pueden comprometer servicios internos, endpoints de metadatos en la nube y direcciones loopback, con datos de respuesta reflejados en mensajes de error de admisión. Esta vulnerabilidad afecta directamente a plataformas Kubernetes en producción en LATAM.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad SSRF alta en Kyverno anterior a 1.16.2 expone recursos internos
Kyverno antes de versión 1.16.2 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en la funcionalidad APICall. Un atacante con permisos de creación de políticas a nivel de namespace puede manipular el campo URL en la configuración ServiceCall para dirigir solicitudes HTTP hacia recursos internos arbitrarios, incluyendo endpoints de metadatos en la nube (169.254.169.254) o infraestructura de otros tenants. Esta vulnerabilidad afecta principalmente a empresas con Kubernetes en entornos cloud públicos (AWS, Azure, GCP) donde Kyverno gestiona políticas de seguridad.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad de autenticación faltante en AVideo permite modificar transmisiones programadas
AVideo presenta una vulnerabilidad alta (CVSS 8.2) en el módulo de transmisión en vivo que permite a atacantes no autenticados modificar el estado de transmisiones programadas mediante solicitudes POST manipuladas. Esta vulnerabilidad afecta principalmente a plataformas de streaming y educativas en LATAM que utilizan este software de código abierto. Los atacantes pueden deshabilitar o sabotear retransmisiones sin acceso previo al sistema.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad CSRF alta en AVideo permite manipulación de contenido sin consentimiento
AVideo contiene una vulnerabilidad de falsificación de solicitud entre sitios (CSRF) en plugin/API/set.json.php que permite a atacantes realizar acciones que modifican el estado del sistema mediante solicitudes GET manipuladas. Los atacantes pueden redirigir navegadores de usuarios a URLs maliciosas para eliminar videos, desactivar cuentas o modificar listas de reproducción sin interacción del usuario. Esta vulnerabilidad afecta especialmente a plataformas de contenido y educación en línea operadas en LATAM.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82957] A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the fu…
A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a manipulation of the argument url results in server-side request forgery. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The …
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82397] Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parse…
Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. RequestHandler._execute in tornado/web.py parses the body before handler dispatch through HTTPServerRequest._parse_body and parse_body_arguments in tornado/httputil.py, …