Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 984 resultados ✕ Limpiar búsqueda
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1782
Esta semana
RSS
A Alto vulnerabilidad
06/07/2026
[CVE-2026-24012] Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose re…
Uncontrolled Resource Consumption vulnerability in Apache IoTDB.  Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g., a very large time range combined with a minimal interval). This forces the DataNode to build an enormous result set in memory, which exhausts the Java heap and c…
M Alto vulnerabilidad
06/07/2026
[CVE-2026-11855] The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webho…
The Simple Membership WordPress plugin before 4.7.5 does not verify the authenticity of Stripe webhook requests when no signing secret is configured, nor escape a value taken from them before outputting it in an administrator notice, allowing unauthenticated attackers to inject arbitrary web scripts that execute in the context of a logged-in administrator.
M Alto vulnerabilidad
06/07/2026
[CVE-2026-12083] The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro Wor…
The Admin and Site Enhancements (ASE) WordPress plugin before 8.8.4, admin-site-enhancements-pro WordPress plugin before 8.8.4 does not perform authentication, authorization, or nonce checks on a role-restoration request handler, allowing unauthenticated attackers to restore a previously demoted administrator account back to the administrator role. This is an incomplete fix of CVE-2024-43333 / CVE…
M Alto vulnerabilidad
04/07/2026
[CVE-2026-12740] Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter…
Plack::Middleware::OAuth versions through 0.10 for Perl do not support the OAuth 2.0 state parameter. RequestTokenV2 builds the provider authorization redirect without issuing a state value, and AccessTokenV2 exchanges the callback code and registers the resulting token into the session (register_session) without verifying that the callback corresponds to an authorization request this session ini…
M Alto vulnerabilidad
04/07/2026
[CVE-2026-12746] Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 st…
Dancer2::Plugin::Auth::OAuth::Provider versions before 0.23 for Perl do not support the OAuth 2.0 state parameter. The authentication_url method builds the provider authorization redirect without issuing a state value, and the callback method exchanges the callback code and registers the resulting token into the session without verifying that the callback corresponds to an authorization request t…
L Alto vulnerabilidad
04/07/2026
[CVE-2026-53360] In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scrat…
In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use As per the GHCB spec, when using GHCB v2+ require the software scratch area to reside in the GHCB's shared buffer. Note, things like Page State Change (PSC) requests _rely_ on this behavior, as the guest can't provide a length when making the request, i.e. the size of…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-57993] Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacke…
Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/07/2026
[CVE-2026-28744] Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer to…
Gitea versions up to and including 1.26.1 allow Git smart HTTP requests authenticated with bearer tokens to bypass repository token scope checks.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-24690] Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull reque…
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches.
M Alto vulnerabilidad
03/07/2026
[CVE-2026-10055] In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker…
In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full response body to the caller. Because the destination URL is neither validated nor allowlisted, a remote attacker with access to the Theia service co…
M Alto vulnerabilidad
03/07/2026
[CVE-2026-13341] A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.…
A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform an indirect prompt injection attack and execute unintended API requests.
H Alto vulnerabilidad
03/07/2026
[CVE-2026-9546] A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared…
A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` suppresses the header, the option failed to clear the internal state. As a result the previous referrer string was erroneously reused and sent in subsequent requests, potentially leaking sensitive information to unintended serve…
W Alto vulnerabilidad
03/07/2026
[CVE-2026-13383] An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authe…
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS ikestubd process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
W Alto vulnerabilidad
03/07/2026
[CVE-2026-13384] An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authen…
An Out-of-bounds Write vulnerability in WatchGuard Fireware OS wgagent process could allow an authenticated privileged user to execute arbitrary code via a specially crafted requests to the Management Web UI.This vulnerability affects Fireware OS 12.1 up to and including 12.12 and 2025.1 up to and including 2026.2.
M Alto vulnerabilidad
02/07/2026
[CVE-2026-59092] JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that…
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux. Attackers can request the /debug/pprof/cmdline endpoint to obtain the process command line containing metadata engine connection st…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/07/2026
[CVE-2026-59095] LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows au…
LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (importFromUrl) and topic cover update (fetchImageFromUrl) endpoints, which use the global fetch without the project's ssrf-safe-fetch wrapper. Attackers can target…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-59096] Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-con…
Dapr Sentry's OIDC discovery endpoint derives the issuer and jwks_uri of the /.well-known/openid-configuration document from the request Host, honoring an attacker-controlled X-Forwarded-Host header without validation when no allowed-hosts list is configured (the default), and serves the document with a one-hour public cache lifetime. A remote unauthenticated attacker can poison the discovery docu…
M Alto vulnerabilidad
02/07/2026
[CVE-2026-58467] Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that all…
Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files or execute PHP files by including unvalidated PATH_INFO derived from REQUEST_URI in filesystem path construction without containment checks. Attackers can inject dot-dot sequences into the URL to traverse outside the designated spaces directory, …
M Alto vulnerabilidad
02/07/2026
[CVE-2026-58465] Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in …
Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that allows unauthenticated remote attackers to exhaust server memory by sending a sequence of Block1 PUT requests with incrementing block numbers. Attackers can target the registration endpoint over UDP without authentication, causing the server to repeat…
P Alto vulnerabilidad
02/07/2026
[CVE-2026-8079] In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenti…
In Progress Flowmon versions prior to 12.5.9 and 13.0.11, a vulnerability exists whereby an authenticated low-privileged user may craft a request during the PDF generation process that results in operations being performed with the privileges of another user, potentially leading to unauthorized access to sensitive data and unintended modifications to system configuration.