Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 11 min
Buscando: "Quest" — 1677 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad SSRF alta en Budibase Server anterior a 3.41.3 expone credenciales de CouchDB
Budibase Server versiones anteriores a 3.41.3 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en el endpoint de verificación de fuentes de datos. Usuarios con permisos de constructor pueden enviar URLs arbitrarias sin validación, permitiendo a atacantes extraer credenciales internas de CouchDB y obtener acceso total a bases de datos en despliegues en la nube. Esto es alta para empresas LATAM que utilizan Budibase en infraestructura compartida o multitenante.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82234] SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_reques…
SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time without validating the connect-time resolution. Attackers can use DNS rebinding to answer the guard resolution with a public IP and the connect resolution with a private or metadata IP, bypassing the SSRF defense to access cl…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82239] Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/que…
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75814] The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the…
The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a disruption of device availability.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-76060] An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionalit…
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75418] A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.…
A path traversal vulnerability exists in the built-in preview/development web server of Lektor
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75419] go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() fun…
go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz middleware always allows requests. Any authenticated user (regardless of role or tenant) can invoke administrative APIs such as deleting users,…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-54330] Ceph is an open-source distributed storage platform providing object, block, and file storage. In ve…
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-77438] Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.10…
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated visitor to read the titles, tree paths, and content of protected shared notes. The endpoint authorizes only the ancestor note supplied in the request and…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-59324] When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emit…
When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recently consumed upstream. Spring Integration 7.1.0 Spring Integration …
M Alto vulnerabilidad
27/08/2026
[CVE-2026-59316] Spring Authorization Server's default consent page renders user-controlled values without HTML entit…
Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page presented to the end user. Spring Authorization Server 1.5.0 - 1.5.8 Spring Authorizat…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81678] AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL functio…
AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can bypass SSRF protections via the LiveLinks proxy endpoint to reach internal services and cloud metadata endpoints by encoding private IPv4 targets in transition …
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81679] OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the …
OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attackers with read:admin credentials in one realm can submit a zero-parameter GET request to the notification endpoint to retrieve sensitive notification metadata and …
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81335] Baserow dispatches an Application Builder data source without acting on the result of its permission…
Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are declared with a permission class that admits any caller, so a request carrying no credential reaches the handler. DataSourceService.dispatch_data_sources in backend/src/baserow/contrib/bui…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81091] The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mou…
The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in libraries/typescript/packages/inspector/src/server/proxy/mcp-proxy.ts read the target from the X-Target-URL header or the __mcp_target parameter and proxied to it without inspecting the host, so loopback, link-local and private addresses were all accepted, as were names that resolve to…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
27/08/2026
[CVE-2026-80208] APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in Interna…
APITable through 1.13.0-beta.1 annotates both getUserHistories and closePausedUserAccount in InternalUserController with requiredLogin = false. ResourceInterceptor honours that annotation by returning before any session or API key is validated, and the nginx gateway shipped with the product proxies every /api request to the backend server, so both endpoints are reachable by any unauthenticated cli…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-75871] GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of t…
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an authenticated user with Duo Agent Platform access to redirect outbound model requests to an externally-controlled endpoint via a crafted inline flow configuration that overrides the HTTP Host header, r…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30046] A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to…
A reachable assertion vulnerability in the NUDM-UECM interface of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30047] A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7…
A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted DELETE request.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-30050] An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5g…
An issue in the ModifyAMFEventSubscriptionProcedure function (processor/event_exposure.go) of free5gc v4.1.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted PATCH request.