Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Rti" — 412 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1764
Esta semana
RSS
M Alto vulnerabilidad
10/08/2026
[CVE-2026-48048] XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm w…
XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and prior to versions 18.0.0RC1, 17.10.13, 17.4.9 and 16.10.17, with slightly modified parameters to the `LiveTableResults`, it is still possible to discover password hashes one bit at a time, so with 768 requests, the full password salt and hash can be r…
M Alto vulnerabilidad
10/08/2026
Vulnerabilidad XSS almacenado en lobe-chat v2.2.13 permite inyección de código arbitrario
Una vulnerabilidad de cross-site scripting (XSS) almacenado en lobe-chat hasta la versión 2.2.13 permite a usuarios autenticados con privilegios bajos inyectar código JavaScript malicioso al cargar un archivo SVG manipulado como avatar. El impacto afecta a empresas que utilizan esta plataforma de chat en entornos internos o en la nube, comprometiendo la sesión de otros usuarios que visualicen el perfil afectado. Con CVSS 7.6, representa un riesgo considerable en infraestructuras compartidas de LATAM.
M Alto vulnerabilidad
10/08/2026
Vulnerabilidad alta de denegación de servicio en FastSchema v0.15.1 permite caída del servidor
Una vulnerabilidad de desreferencia de puntero NULL en FastSchema hasta la versión 0.15.1 permite que atacantes no autenticados derriben el servidor con una única solicitud HTTP. El defecto se encuentra en la función sendOTPEmail (pkg/auth/local.go) que procesa solicitudes de recuperación de contraseña sin validar correctamente el manejo de errores, causando un pánico fatal que interrumpe toda la aplicación. Afecta particularmente a empresas en LATAM que usan FastSchema en entornos de producción para autenticación de usuarios.
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad DoS alta en Klever-Go 1.7.14-1.7.17 afecta nodos blockchain
Klever-Go, implementación en Go del protocolo blockchain Klever, presenta una vulnerabilidad de denegación de servicio (DoS) remota en versiones 1.7.14 a 1.7.17. Las APIs REST utilizan Gin Engine sin configurar timeouts de lectura ni límites de encabezados HTTP, permitiendo a atacantes remotos bloquear nodos. Empresas operando infraestructura blockchain o exchange en LATAM deben revisar si ejecutan versiones afectadas.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-68772] ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component…
ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a shared artifact store to execute arbitrary code by planting a malicious pickle file. Attackers can replace a stored artifact.pkl file with a crafted cloudpickle payload containing a malicious __reduce__ method, which executes arbitrary system commands wh…
M Alto vulnerabilidad
07/08/2026
Vulnerabilidad alta de secuestro de DLL en LUCID Vision Labs Arena SDK 1.0.80.49
Una vulnerabilidad de tipo DLL Search Order Hijacking (puntuación CVSS 8.8) en Arena SDK 1.0.80.49 permite a atacantes locales ejecutar código arbitrario con los privilegios de la aplicación. El riesgo es alto en entornos de visión artificial e industria 4.0 comunes en plantas manufactureras de México y Latinoamérica, donde este SDK se integra en sistemas de inspección y control de calidad.
M Alto vulnerabilidad
07/08/2026
[CVE-2026-14943] The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress p…
The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content and account identifiers via the REST API. This re-introduces a previously-fixed i…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
06/08/2026
[CVE-2026-71488] league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2…
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-70634] TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionar…
TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compression/algorithms/dictionary.c). The forward path validates the decoded index; the reverse path uses an assertion compiled out of release builds, leaving the 64-bit Simple8b index unvalidated and the read offset attacker-controlled. Attackers with DML…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-67422] pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to …
pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in exponentially many ways, causing catastrophic backtracking. As a result, a single untrusted Markdown line under 50 bytes rend…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-45378] Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0…
Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-document verification admin UI embeds verification_attachment blobs through reusable signed Active Storage disk URLs, allowing anyone who obtains a URL to download the scanned document without an authenticated Decidim session until the signature expires. Ver…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-45414] Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2,…
Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to the organization selected by the current host, allowing a JWT issued for one tenant to be replayed against another tenant’s API to read participantDetails data and reach the proposal.answer mutation path. This issue is fixed in versions 0.31.5 and 0.32.…
M Alto vulnerabilidad
06/08/2026
[CVE-2026-19138] Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote att…
Heap buffer overflow in CrashReporting in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
06/08/2026
[CVE-2025-49506] APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with re…
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
M Alto vulnerabilidad
06/08/2026
Vulnerabilidad alta de control de acceso en CatchPulse permite escalada de privilegios local
Una falla de control de acceso impropio en CatchPulse permite que usuarios locales no administrativos se conecten a un puerto de comunicación del kernel sin restricciones, eludiendo las políticas de seguridad del producto. Esta vulnerabilidad afecta principalmente a entornos corporativos con acceso local compartido, común en infraestructuras LATAM con estaciones de trabajo de uso múltiple.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
05/08/2026
[CVE-2026-16443] A flaw was found in the SAML metadata import functionality of the keycloak-services component, which…
A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an un…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-71292] Subrion CMS's admin grid sorting helper, _gridGetSorting() in includes/classes/ia.base.controller.ad…
Subrion CMS's admin grid sorting helper, _gridGetSorting() in includes/classes/ia.base.controller.admin.php, whitelists the `dir` (ASC/DESC) request parameter via in_array(), but falls back to the raw, attacker-supplied `sort` GET parameter whenever the requested key is not present in the per-controller $_gridSorting whitelist array: `$column = isset($this->_gridSorting[$params['sort']]) ? ... : $…
M Alto vulnerabilidad
05/08/2026
[CVE-2026-70377] imagecli's `scale <ratio>` pipeline operation (Scale::apply() in src/image_ops.rs) computes output w…
imagecli's `scale ` pipeline operation (Scale::apply() in src/image_ops.rs) computes output width/height as (dimension as f32 * ratio) as u32 with no upper-bound validation on the CLI-supplied ratio, which is parsed via nom::number::complete::float with no range check. A large ratio (e.g. 100000) causes an attempted allocation of hundreds of terabytes, aborting the process. Any application …
M Alto vulnerabilidad
04/08/2026
[CVE-2026-70492] Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 un…
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math block makes KaTeX fail with a stack overflow instead of a parse error. The catch branch fell back to inserting the original math source into the page as HTML through {@html} ra…
M Alto vulnerabilidad
03/08/2026
[CVE-2026-67598] Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/ser…
Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept outbound HTTPS requests to configured LLM providers by presenting arbitrary TLS certificates, as CURLOPT_SSL_VERIFYPEER and CURLOPT_SSL_VERIFYHOST are unconditionally disabled across sendStream(), sendImageRequest(), send(), and fetchSe…