Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 12563 resultados ✕ Limpiar búsqueda
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1272
Esta semana
RSS
M Alto vulnerabilidad
28/09/2026
Vulnerabilidad de validación en OpenDMARC afecta autenticación de correo en servidores hasta versión 1.4.2
Se ha identificado una falla en Trusted Domain Project OpenDMARC versiones hasta 1.4.2 que permite eludir validaciones de equivalencia en el componente Domain Handler (archivo policy.c). La vulnerabilidad puede explotarse remotamente y afecta la autenticación DMARC de correos electrónicos en servidores de correo, con riesgo de suplantación de dominios. Empresas en LATAM que usan OpenDMARC deben aplicar actualizaciones urgentes, especialmente aquellas que procesan comunicaciones altas.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101014] A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulne…
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_util_cleanup in the library libopendmarc/opendmarc_util.c of the component DMARC Record Parser. Performing a manipulation results in off-by-one. The attack may be initiated remotely. The exploit is now public and may be used. The patch is named b3b1da9264bc80324094…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82386] Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog adminis…
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to read files readable by the Roller process and reach internal network addresses by importing a crafted OPML document, because the bookmark import parser does not disable external entity resolution. No non-default configuration is required; the import is reached through the administrator boo…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82376] Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entr…
Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing rights on a weblog to cause the server to parse an attacker-influenced trackback response with an XML parser that does not disable external entity resolution, leading to disclosure of files readable by the Roller process. The Trackback control is hidden in the standard UI, but its action r…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-82379] Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a val…
Authentication Bypass by Capture-replay in Apache Roller 6.1.5 allows an attacker who captures a valid WSSE digest authentication header to replay it and gain the victim's AtomPub authority, because the authentication does not enforce nonce uniqueness or timestamp freshness. Only installations that enable the non-default AtomPub API with WSSE authentication and plaintext-compatible password storag…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101012] A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d6…
A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling re…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101013] A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec09…
A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101007] A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputS…
A vulnerability has been found in aaPanel BaoTa up to 11.8.0. This issue affects the function InputSql of the file class/database.py of the component Database Backup Handler. Such manipulation of the argument Password leads to os command injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101009] A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function p…
A vulnerability was determined in aaPanel BaoTa up to 11.8.0. The affected element is the function panelTask.bt_task._unzip of the file /www/server/panel/class/panelTask.py of the component Unzip Handler. Executing a manipulation of the argument Password can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendo…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101005] A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalI…
A vulnerability was detected in October CMS up to 4.3.4. This affects the function validateExternalImageHost of the file System/Classes/ResizeImages.php of the component SSRF Protection. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit is now public and may be used. Upgrading to version 4.3.5 is able to mitigate this issue. You should upgrad…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-100909] A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the funct…
A vulnerability was found in OctoberCMS up to 4.1.19/4.2.25/4.3.4. The impacted element is the function getSourcePathForResize of the file modules/system/classes/ResizeImages.php. The manipulation of the argument realSourcePath results in server-side request forgery. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version 4.3.5 and 4.4.0 is…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-100908] A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the compo…
A vulnerability has been found in Eyeplus 57.0.0.0308. This affects an unknown function of the component p2pcam HTTP Parser. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-100901] A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerabili…
A vulnerability was found in athlon1600 youtube-downloader up to 4.0.1. Affected by this vulnerability is the function stream of the file public/stream.php. The manipulation of the argument url results in server-side request forgery. It is possible to launch the attack remotely. The exploit has been made public and could be used. Commit 6ffe823 'better security for public/stream.php' only added CU…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-100893] A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects t…
A vulnerability was determined in Privoce VoceChat Server up to 0.5.36. This vulnerability affects the function open_graph::fetch of the file src/api/resource.rs of the component open_graphic_parse Endpoint. Executing a manipulation of the argument url can lead to server-side request forgery. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. The vend…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-100891] A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this iss…
A vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain Name Handler. Such manipulation leads to encoding error. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/09/2026
[CVE-2026-100888] A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the fun…
A weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation of the argument h can lead to out-of-bounds write. The attack can be executed remotely. The exploit has been made available to the public and could be used for …
M Alto vulnerabilidad
28/09/2026
[CVE-2026-100889] A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the functi…
A vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from remote. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
27/09/2026
[CVE-2026-100885] A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the…
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this is…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-96280] The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functio…
The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (32 bits on 32-bit systems), causing undersized allocations while subsequent operations use the original 64-bit size, leading to heap buffer overflows. An attacker controlling an OCI registry can craft a delta stream that triggers this during flatpak install/update, potentially ac…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101062] Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=tr…
Obot before v0.23.0 (affected versions