Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 2792 resultados ✕ Limpiar búsqueda
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1272
Esta semana
RSS
M Alto vulnerabilidad
22/07/2026
[CVE-2026-64797] Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trus…
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63265] Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Re…
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations out…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13072] When compute mode is enabled on a standalone mongod instance, insufficient validation of externally …
When compute mode is enabled on a standalone mongod instance, insufficient validation of externally sourced BSON data during aggregation pipeline processing can result in memory corruption, potentially leading to process termination or other unintended behavior. This configuration is non-default and requires explicit enablement at startup.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-65013] Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnera…
Onlook through 0.2.32, fixed in commit 423e2e9, contains a broken object level authorization vulnerability that allows authenticated attackers to access and manipulate other users' resources by supplying arbitrary UUID values to tRPC API procedures including project.get, member.remove, and chat.conversation.delete. Attackers can provide arbitrary projectId or conversationId values without authoriz…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-12617] The issue is unexpected program termination based on ordering and/or specific content in responses t…
The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. Or, if …
N Alto vulnerabilidad
22/07/2026
[CVE-2026-32665] In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enab…
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and large input buffers are allocated later, after only the 2-byte length prefix has been received from the initial streams. As a result, a remote client can make Un…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13185] In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in R…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13186] In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-b…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13187] In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tam…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processing and enabling chained exploitation.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13189] In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language para…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell check handler may allow an attacker to influence server-side file path resolution and trigger unintended server-side requests.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13190] In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persi…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13181] In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUp…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13182] In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can d…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13183] In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing ma…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13184] In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is …
In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/07/2026
[CVE-2026-12987] The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data o…
The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget chain reaches a database query that is built without parameterisation, so an unau…
G Alto vulnerabilidad
21/07/2026
[CVE-2026-16423] Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convince…
Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
O Alto vulnerabilidad
21/07/2026
[CVE-2026-62561] Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operat…
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle…
O Alto vulnerabilidad
21/07/2026
[CVE-2026-62565] Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year…
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll Year End). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete acce…
O Alto vulnerabilidad
21/07/2026
[CVE-2026-62567] Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). S…
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). While the vulnerability is in Oracle HRMS (UK), attacks may significantly impact additional products (scope change). …