Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 6 horas
Buscando: "X" — 7734 resultados ✕ Limpiar búsqueda
13,735
Total alertas
3106
Críticas
10357
Altas
8
Ransomware
1053
Esta semana
RSS
N Alto vulnerabilidad
23/06/2026
[CVE-2026-54314] n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompre…
n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expanded attacker-controlled archives into memory without enforcing limits on decompressed output size. An unauthenticated attacker could send a small compressed archive to a public webhook workflow using this node, causing the n8n process to terminate due to memory exhaustion and disru…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-35019] NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulner…
NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge a valid encrypted session cookie using the shared hardcoded key and bypass authentication checks to …
M Alto vulnerabilidad
23/06/2026
[CVE-2026-35018] NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code ex…
NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands as root by injecting shell metacharacters into the username JSON parameter processed by the dalStorage_addUserAccount function. Attackers can exploit the unsafe concatenation of user-supplied input into a shell c…
I Alto vulnerabilidad
23/06/2026
[CVE-2026-56379] ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG deco…
ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows attackers to inject arbitrary MVG drawing commands. Attackers can craft malicious SVG files with injected Magick Vector Graphics commands that execute during rendering.
F Alto vulnerabilidad
23/06/2026
[CVE-2026-56275] Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node t…
Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate internal services by exploiting the missing secureFetch verification in httpSecurity…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-56322] Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updat…
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel parameter before enforcing privacy restrictions, allowing attackers to enumerate private channels and leak version/config state. Unauthenticated attackers can probe private channel names and distinguish valid channels from nonexistent ones based on respon…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-56243] Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane…
Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enabled. Attackers can bypass org-level hashed-key enforcement by sending plaintext API keys directly to the PostgREST/RLS plane to access protected resources.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/06/2026
[CVE-2026-56248] Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerab…
Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from the audit_logs table's Row-Level Security (RLS) policy when accessed via the Supabase PostgREST API. Because the PostgreSQL query planner executes costly logic before RLS rejection, unfiltered queries to the public.audit_logs endpoint using the public anon key consistently trigger…
K Alto vulnerabilidad
23/06/2026
[CVE-2026-56258] Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpo…
Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthenticated attackers to write files outside the intended directory via symlink and time-of-check-time-of-use (TOCTOU) attacks on the output_path parameter. Remote attackers can exploit insufficient path validation and symlink following to achieve arbitrary file write and potent…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-10711] Missing authentication for critical function vulnerability in AKIN Software Computer Import Export I…
Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects CafePlus: from 12.05.03 before 12.05.04.
M Alto vulnerabilidad
23/06/2026
[CVE-2025-71341] picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle f…
picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using profile.Profile.runctx in the reduce method to achieve remote code execution when the pickle file is loaded.
M Alto vulnerabilidad
23/06/2026
[CVE-2025-71365] picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.…
picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function through the reduce method. Attackers can craft malicious pickle files embedding arbitrary code that evades picklescan detection and executes remote code when loaded.
M Alto vulnerabilidad
23/06/2026
[CVE-2025-71370] picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper func…
picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded in pickle files. Attackers can craft malicious pickle files that bypass picklescan detection and execute arbitrary code when loaded via pickle.load().
M Alto vulnerabilidad
23/06/2026
[CVE-2025-71376] picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoCompl…
picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoComplete.fetch_completions in reduce methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when loaded by victims.
T Alto vulnerabilidad
23/06/2026
[CVE-2023-54365] Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 req…
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/06/2026
[CVE-2026-8172] The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input …
The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or cross-site form submission.
M Alto vulnerabilidad
23/06/2026
[CVE-2026-8163] The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some param…
The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above.
L Alto vulnerabilidad
23/06/2026
[CVE-2025-67038] Vulnerabilidad explotada activamente en Lantronix EDS5000
CISA confirma explotación activa de una vulnerabilidad en Lantronix EDS5000. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-06-26.
U Alto vulnerabilidad
23/06/2026
[CVE-2026-34910] Vulnerabilidad explotada activamente en Ubiquiti UniFi OS
CISA confirma explotación activa de una vulnerabilidad en Ubiquiti UniFi OS. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-06-26.
U Alto vulnerabilidad
23/06/2026
[CVE-2026-34909] Vulnerabilidad explotada activamente en Ubiquiti UniFi OS
CISA confirma explotación activa de una vulnerabilidad en Ubiquiti UniFi OS. No se ha confirmado uso en campañas de ransomware conocidas. Fecha límite para aplicar parche según directiva CISA: 2026-06-26.