Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "Multiple Vendors" — 13279 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1212
Esta semana
RSS
M Alto vulnerabilidad
24/06/2026
[CVE-2026-54639] Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulne…
Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4.3.0 and prior to version 5.4.4. Impact users have: direct usage of `convertTokenData(tokens, { output: 'object' });`; indirect usage, via using Expand API; and/or indirect usage via SD's transform lifecycle. Impact is high for this when style-dictionary is used as an i…
M Alto vulnerabilidad
24/06/2026
[CVE-2026-7574] Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, inc…
Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) validates only file presence and a version marker string before booting rootfs.img, but does not verify image content integrity at time-of-use. A local attacker with unprivileged code execution as the victim macOS user can modify the VM root filesystem ima…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-56785] FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where na…
FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in Smarty templates. Attackers can inject arbitrary HTML and JavaScript through these fields to execute malicious scripts in browsers of viewers including administrators, or bypass URL scheme validation to inject javascript: or da…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-41862] Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialis…
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring Statemachine 4.0.0 through 4.0.1 Spring Statemachine 3.2.0 through 3.2.4
M Alto vulnerabilidad
23/06/2026
[CVE-2026-54328] Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or…
Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension package installs used predictable paths under the operating system temporary directory. On Linux-based multi-user systems, a local attacker who can write to the shared temporary directory could prepare the expected package location before another user runs pi with a temporary extensio…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-54555] rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the …
rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter did not conservatively split or reject several shell constructs that Bash treats as command execution boundaries or nested execution. As a result, a command beginning with an allowed prefix such as git could hide a second command behind one of these constructs. rtk rewrite return…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-39253] An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivot…
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/06/2026
[CVE-2026-54321] Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent wor…
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox previews that were switched from public to private could remain reachable without authentication for a short period after the change, due to a cached visibility state that was not invalidated when the sandbox's visibility changed. This vulnerability is fix…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-54322] Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent wor…
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organization role update and delete endpoints authorized the caller as an owner of the organization named in the request path, but resolved and mutated the target role by its identifier alone, without verifying the role belonged to that organization. An authentica…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-54320] Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent wor…
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.184.0, organization invitations could be accepted (and declined) by a user whose email matched the invitation but had not been verified. Daytona authenticates users via OIDC and matches an invitation's target email against the email in the caller's token, but the invitation accept…
M Alto vulnerabilidad
23/06/2026
[CVE-2025-61024] An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers …
An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
M Alto vulnerabilidad
23/06/2026
[CVE-2025-61029] An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cau…
An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
M Alto vulnerabilidad
23/06/2026
[CVE-2026-44959] A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 …
A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which would then be executed during banner delivery. Input sanitisation has been improved to ensure that unexpected parameters are filtered out.
M Alto vulnerabilidad
23/06/2026
[CVE-2026-34914] A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and ear…
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.
M Alto vulnerabilidad
23/06/2026
[CVE-2026-34916] A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and ear…
A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during banner delivery. Input sanitisation has been improved to ensure that the parameter is properly validated.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/06/2026
[CVE-2026-12958] Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of …
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously crafted symlink that resolves to a file path outside the workspace trust boundary. To remediate this issue, users should upgrade to version 1.69.0 or higher.
M Alto vulnerabilidad
23/06/2026
[CVE-2026-13007] Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose…
Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data including cleartext LDAP credentials, SAML configuration, user accounts, and directory settings to unauthenticated remote attackers. Affected responses are served with Cache-Control: public headers and without Vary: Cookie, allowing reverse proxies and CDNs …
M Alto vulnerabilidad
23/06/2026
[CVE-2026-12957] Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all support…
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code execution. If a local user opens a maliciously crafted workspace, any commands within the project configuration files may be automatically executed. This issue requires the user to trust the workspace when prompted. To remediate this issue, users should…
M Alto vulnerabilidad
23/06/2026
[CVE-2025-61020] An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attacker…
An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
M Alto vulnerabilidad
23/06/2026
[CVE-2025-61021] An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows atta…
An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.