Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,046
Total alertas
3206
Críticas
10568
Altas
8
Ransomware
1052
Esta semana
RSS
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14403] Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute ar…
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14389] Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had c…
Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14393] Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute ar…
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14394] Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentiall…
Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14395] Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execu…
Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14383] Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker…
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
G Alto vulnerabilidad
01/07/2026
[CVE-2026-14385] Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attack…
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/07/2026
[CVE-2026-52190] Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to…
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_448384 component
T Alto vulnerabilidad
01/07/2026
[CVE-2026-54263] Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3…
Wagtail is an open source content management system built on Django. In versions prior to 7.0.8, 7.3.3 and 7.4.2, reflected cross-site scripting (XSS) vulnerability exists on the dynamic image URL generator view within the Wagtail admin interface. A user with a limited-permission editor account for the Wagtail admin could craft a URL that, when viewed by a user with higher privileges, could perfor…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-36912] A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE b…
A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-38891] An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 all…
An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted geometry_msgs::Twist message.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-58263] Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4…
Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be bypassed by a MathML/ carrier that hides a dangerous element from the sanitizer's element walk, so a no-interaction event handler survives into the editor value, potentially causing Mutation XSS. When an application supplies attacker-influenced…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-50521] Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over…
Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
01/07/2026
[CVE-2026-54074] Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote …
Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulnerability in the Forestry-to-Tina migration command. The internal helper addVariablesToCode unquotes any value matching the marker "__TINA_INTERNAL__:::(.*?):::" inside the stringified collection JSON. User-supplied label and name fields from .forestry/**/*.yml are placed into tha…
M Alto vulnerabilidad
01/07/2026
[CVE-2026-55153] mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c…
mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its JNDI ObjectFactory implementation (com.mchange.v2.naming.JavaBeanObjectFactory) will construct objects of arbitrary classes and initialize "JavaBean"-style properties, which for certain classes enables JNDI injection and "deserialization gadgets." Suc…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/07/2026
[CVE-2026-58592] Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module …
Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported into a WebAssembly module via the ESM path, WebAssemblyModule.cpp passes a stack-local Wasm::FunctionType by reference to create_host_function, whose host callback captures and later reads that reference; once the ESM link-loop iteration ends the Functi…
N Alto vulnerabilidad
01/07/2026
[CVE-2026-58593] NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote…
NodeBB does not bind the claimed author of an inbound ActivityPub object to the authenticated remote actor. The inbound middleware verifies the HTTP-signature actor and checks the origin of object.id, but never validates that attributedTo corresponds to the sender. In the object mock, attributedTo is used directly as a uid, and actors.assert silently ignores numeric identifiers (filtering them out…
A Alto vulnerabilidad
01/07/2026
[CVE-2026-14265] Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced …
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java object. The RemoteQueryCachePlugin uses ObjectInputStream without class filtering w…
G Alto vulnerabilidad
01/07/2026
[CVE-2026-49119] Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preproce…
Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide crafted path segments that cause os.path.join to discard the root_dir prefix entirely, resulting in a…
D Alto vulnerabilidad
01/07/2026
[CVE-2026-41121] Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Befo…
Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.