Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,949
Total alertas
3186
Críticas
10491
Altas
8
Ransomware
1139
Esta semana
RSS
M Alto vulnerabilidad
26/06/2026
[CVE-2026-54833] Unauthenticated Backdoor in Enable CORS <= 2.0.3 versions.
Unauthenticated Backdoor in Enable CORS
M Alto vulnerabilidad
26/06/2026
[CVE-2026-54834] Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone <= 2.3.2 versions.
Unauthenticated Sensitive Data Exposure in Object Cache 4 everyone
F Alto vulnerabilidad
26/06/2026
[CVE-2026-45257] The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data …
The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and safe to modify. This assumption does not hold for data placed on a socket by sendfile(2), which can reference file-backed memory directly through non-anonymous M_EXTPG pages or EXT_SFBUF mbufs. When the sender transmits such data over a loopback connection without enabling KTLS …
M Alto vulnerabilidad
26/06/2026
[CVE-2026-30041] An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to ex…
An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.
M Alto vulnerabilidad
26/06/2026
[CVE-2025-68052] Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking
M Alto vulnerabilidad
26/06/2026
[CVE-2025-68063] Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Ho…
Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey
M Alto vulnerabilidad
26/06/2026
[CVE-2025-68064] Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
P Alto vulnerabilidad
26/06/2026
[CVE-2026-57920] Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-cont…
Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57915] It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA …
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which fixes this issue.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-40711] Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-power…
Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57912] Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited s…
Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57913] Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meetin…
Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57918] libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_sock…
libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.
K Alto vulnerabilidad
26/06/2026
[CVE-2026-13325] A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set…
A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the target virt-handler binds a plain TCP listener on all interfaces (0.0.0.0/::) on a random port with no authentication, peer allow-list, or handshake token. This listener proxies directly into the target virt-launcher's virtqemud control socket. An attack…
M Alto vulnerabilidad
26/06/2026
[CVE-2026-11625] Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. …
Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in multiprocess applications are predictable across processes.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
26/06/2026
[CVE-2026-11702] Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked proce…
Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an object is initialised before forking, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in multiprocess applications are predictable across processes.
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57872] An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011…
An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient validation of user-supplied file path input before the requested file is accessed by the CGI component. A remote attacker may exploit this vulnerability by sending a crafted request to read arbitrary files accessible to t…
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57873] An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVisio…
An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of multipart upload headers when processing certificate-related upload fields. A remote attacker may exploit this vulnerability by sending a malformed multipart request, causing the affected CGI process…
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57874] An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2…
An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing filename values in multipart upload data. A remote attacker may exploit this vulnerability by sending a crafted upload request with overly long input, causing memory corruption and resultin…
M Alto vulnerabilidad
26/06/2026
[CVE-2026-57875] An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic o…
An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI components in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper validation of required HTTP request metadata before it is used by the affected components. A remote attacker may exploit this vulnerability by sending a specially crafted HTTP …