Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 983 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1790
Esta semana
RSS
O Alto vulnerabilidad
16/06/2026
[CVE-2026-53866] OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing…
OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser case missing the expected allowlist decision, enabling shell content execution without intended approval prompts.
O Alto vulnerabilidad
16/06/2026
[CVE-2026-53840] OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP se…
OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards operator-configured custom headers during cross-origin redirects. Attackers controlling or compromising an MCP endpoint can redirect requests to exfiltrate sensitive headers like API keys or tenant-routing credentials to attacker-controlled origins.
M Alto vulnerabilidad
16/06/2026
[CVE-2026-7273] A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versi…
A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50891] Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to …
Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50882] An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Den…
An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50885] Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unaut…
Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints via a crafted request.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50888] An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Ben…
An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50875] Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows aut…
Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or delete another tenant's webhook via a crafted request.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50878] An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to ca…
An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50879] An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to c…
An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50870] An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1…
An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive information via a crafted GET request.
E Alto vulnerabilidad
15/06/2026
[CVE-2026-5079] Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service …
Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multi…
M Alto vulnerabilidad
15/06/2026
[CVE-2016-20084] WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities…
WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and inject persistent cross-site scripting payloads through the admin.php page parameters. Attackers can inject malicious JavaScript into the 'ict' and 'ics' options or the calendar 'name' parameter via GET requests to execute arbitra…
M Alto vulnerabilidad
15/06/2026
[CVE-2019-25746] WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows au…
WordPress Sliced Invoices 3.8.2 contains an authenticated SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'post' parameter. Attackers can send requests to the admin.php endpoint with action=duplicate_quote_invoice and malicious 'post' values to extract sensitive database information or modify data.
M Alto vulnerabilidad
15/06/2026
[CVE-2016-20081] WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows una…
WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the file_path parameter. Attackers can send requests to the audio-download.php endpoint with directory traversal sequences to access sensitive files like wp-config.php outside the intended gallery directory.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/06/2026
[CVE-2016-20071] The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injecti…
The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through unsanitized user input. Attackers can craft GET requests with SQL injection payloads to manipulate database queries and extract sensitive information from the WordPress database.
M Alto vulnerabilidad
15/06/2026
[CVE-2016-20072] BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unaut…
BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the uid parameter. Attackers can craft requests to pages using the plugin's shortcode with UNION-based SQL injection in the uid parameter to extract sensitive data from the WordPress database including user inf…
M Alto vulnerabilidad
15/06/2026
[CVE-2016-20073] Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unau…
Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' POST parameter. Attackers can submit crafted SQL statements to the modal.php endpoint to extract sensitive database information including WordPress terms and configuration data.
M Alto vulnerabilidad
15/06/2026
[CVE-2016-20068] WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injecti…
WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by injecting malicious code through the 'id' parameter. Attackers can send requests to the admin-ajax.php endpoint with the action parameter set to 'dex_bccf_calendar_ajaxevent' and supply crafted SQL commands in the 'id'…
M Alto vulnerabilidad
14/06/2026
[CVE-2026-54413] driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read i…
driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess() function in iso14229.c that allows a remote unauthenticated attacker to crash a UDS server and potentially read memory past the receive buffer by sending a single-byte 0x27 SecurityAccess request that follows any earlier well-formed 0x27 message. The handler reads …