Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 12554 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Alto vulnerabilidad
15/06/2026
[CVE-2025-68851] Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions.
Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit
M Alto vulnerabilidad
15/06/2026
[CVE-2025-68872] Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= …
Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics
M Alto vulnerabilidad
15/06/2026
[CVE-2026-53703] A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a R…
A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without fi…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-53704] A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a…
A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-52720] A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle…
A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that c…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50881] Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor priv…
Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and configuration changes.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50874] An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Remi…
An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50877] An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying f…
An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50879] An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to c…
An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-49954] Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that al…
Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted plugin configuration containing path traversal sequences in the directory attribute. Attackers can trigger an exception during plugin installation to bypass sanitization routines, causing malicious paths to …
M Alto vulnerabilidad
15/06/2026
[CVE-2026-45389] In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate pro…
In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificates that are not meant for client authentication (because of KeyUsage and ExtendedKeyUsage).
V Alto vulnerabilidad
15/06/2026
[CVE-2026-47835] In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary que…
In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8).
M Alto vulnerabilidad
15/06/2026
[CVE-2026-39007] An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitiv…
An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component.
B Alto vulnerabilidad
15/06/2026
[CVE-2026-41708] In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause …
In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled. Affected versions: Spring Cloud Sleuth 3.1.0 through 3.1.13.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-36670] A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Pa…
A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL commands via the 'table' GET parameter in alias_management.php.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-36213] An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges v…
An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.
M Alto vulnerabilidad
15/06/2026
[CVE-2025-56814] A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to ex…
A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell metacharacters.
M Alto vulnerabilidad
15/06/2026
[CVE-2025-68713] An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sen…
An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force arbitrary file downloads into the app's scoped storage. The resulting files appear in the application's trusted Received interface. These conditions establish a vector for arbitrary code execution if th…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-8357] LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed w…
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-6040] A heap use-after-free existed when importing the blank-width characters of an ODF number format. A p…
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the document was not checked against the length of the format-code string, so a malformed number format could be processed against memory outside that string. In fixed versions the position is bounds-checked before use.