Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1261
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-63209] compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow…
compress provides various compression algorithms. Prior to version 1.18.7, a signed integer overflow vulnerability in s2.NewDict() allows an attacker to bypass repeat index validation by supplying a dictionary with a uvarint-encoded repeat value exceeding MaxInt64. When Dict.Encode() is subsequently called, the overflowed negative repeat value causes an out-of-bounds memory access via unsafe.Point…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-65102] NVIDIA DeepStream contains a vulnerability where an attacker could cause an integer overflow by sup…
NVIDIA DeepStream contains a vulnerability where an attacker could cause an integer overflow by supplying crafted tensor dimensions in a YAML configuration file. A successful exploit of this vulnerability might lead to denial of service, information disclosure, data tampering.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102566] CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails…
CTranslate2 before 4.8.1 contains a heap-based buffer overflow in the binary model loader that fails to validate payload length against allocated buffer size. Attackers can craft malicious model files with oversized payload lengths to write past heap allocation boundaries, causing crashes or arbitrary code execution.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102491] A vulnerability was identified in mahonelau kykms up to 8f130c2d85842d5b44caae78cc46d65e505949f7. Th…
A vulnerability was identified in mahonelau kykms up to 8f130c2d85842d5b44caae78cc46d65e505949f7. The impacted element is the function QueryGenerator.doMultiFieldsOrder of the file QueryGenerator.java of the component SqlInjectionUtil. The manipulation of the argument column leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. …
M Alto vulnerabilidad
29/09/2026
[CVE-2015-20122] Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnera…
Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in the attach_ids parameter of the file attachment download endpoint that allows remote attackers to extract arbitrary database contents without prior authentication. Attackers can inject UNION-based SQL statements through the attach_ids request parameter in downloadAtt.jsp to retrieve sensit…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-86450] Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Lim…
Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102360] A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-r…
A missing bounds check in the binary decoder in lib0, versions 0.2.1-0.2.117 and earlier and 1.0.0-rc.32 and earlier, lets any unauthenticated remote peer read adjacent process memory and receive it back. `readUint8Array` never compares the wire-supplied length against the decoder's own view, so one over-long length prefix returns whatever the host process allocated next: other tenants' document c…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102521] The decoder in `readFromDataView` in lib0 before 0.2.119 can be tricked into reading more than it sh…
The decoder in `readFromDataView` in lib0 before 0.2.119 can be tricked into reading more than it should from a buffer. The vulnerability allows reading past the decoders' view, thus exposing adjacent process memory. This can be anything that is currently in the head, for example credentials or logs. This is similar to but different from GHSA-r5c8-rf4w-qrq8.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-82804] The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization…
The scriptPath parameter is incorporated into a /bin/sh -c command without sufficient neutralization of shell metacharacters, allowing shell command substitution and execution. An authenticated user can exploit this behavior by creating a resource whose filename contains shell command substitution syntax, such as $(...), and subsequently supplying the resulting path to the Alert Script plugin's /…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-73598] Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrec…
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102437] OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSe…
OS Command Injection in internal/gitcmd (git diff filter.clean/smudge invocation) in esengine DeepSeek-Reasonix (Reasonix Studio) allows a local attacker who controls repository content (.gitattributes + .git/config) to execute arbitrary commands via the desktop app's workspace-changes diff viewer.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100831] Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Fir…
Use-after-free in the DOM: UI Events & Focus Handling component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100832] Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.…
Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Firefox ESR 115.42, and Firefox ESR 140.17.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100820] Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4…
Privilege escalation in the Address Bar component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100824] Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and …
Privilege escalation in the Places component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100825] Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR …
Use-after-free in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100813] Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 157…
Invalid pointer in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 157.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100814] Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed …
Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100815] Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox…
Use-after-free in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox ESR 153.4 and Firefox 157.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100801] Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.…
Privilege escalation in the DLL Services component. This vulnerability was fixed in Firefox ESR 153.4, Firefox 157, and Firefox ESR 140.17.