Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 43 min
Buscando: "Quest" — 12 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1009
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-107839] ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Ag…
ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology games. Prior to version 1.15.2, the AoE3 POST /game/cloud/getFileURL handler in the bundled game server has no request body size limit or cap on the attacker-controlled JSON names array and allocates response storage directly from the unbounded array length. A remot…
M Alto vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-107840] yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the…
yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacke…
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-75349] EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability…
EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-108113] ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI questio…
ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server u…
M Alto vulnerabilidad Nuevo
Hace 5 horas
[CVE-2026-107811] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenti…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node auth…
M Alto vulnerabilidad Nuevo
Hace 6 horas
[CVE-2026-107805] Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signatur…
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume tempo…
M Alto vulnerabilidad Nuevo
Hace 7 horas
[CVE-2026-62026] Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allo…
Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allows Cross Site Request Forgery.This issue affects Dashboard Notes: from n/a through 1.0.3.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 11 horas
Vulnerabilidad CSRF alta en Featured Image from URL (fifu.app) versiones hasta 6.0.7
Se detectó una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) en el plugin Featured Image from URL para WordPress que permite a atacantes ejecutar acciones no autorizadas en sitios afectados. La vulnerabilidad impacta versiones desde la inicial hasta la 6.0.7, afectando miles de sitios WordPress en LATAM que utilizan este plugin para gestión de imágenes destacadas. Con CVSS 8.8, representa un riesgo alta para la integridad y disponibilidad de contenido.
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-78024] Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Si…
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, Server-side request forgery, and Unauthorized access.
M Alto vulnerabilidad Nuevo
Hace 13 horas
[CVE-2026-19575] The user-mode verification handler for the device_deinit() system call, z_vrfy_device_deinit() in ke…
The user-mode verification handler for the device_deinit() system call, z_vrfy_device_deinit() in kernel/device.c, validated its dev argument with K_SYSCALL_OBJ_INIT(dev, K_OBJ_ANY). k_object_validate() short-circuits its type comparison when the requested type is K_OBJ_ANY, so the check reduced to "this pointer is the base address of some kernel object the calling thread has been granted" — the o…
M Alto vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-93548] The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitle…
The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales WordPress plugin before 1.43.3 act as an arbitrary other user, including an administrator, resulting in that user's account details being exposed and their account being taken over.
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-107914] Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration ex…
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission.