Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 2333 resultados ✕ Limpiar búsqueda
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1772
Esta semana
RSS
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-53776] Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass…
Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. Attackers in possession of a previously issued bearer token can present expired tokens to any jwt.verify() call and retain authenticated access indef…
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12315] Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firef…
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12316] Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Th…
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12304] Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Fire…
Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12293] Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Th…
Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12294] Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox E…
Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12295] Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefo…
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12296] Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefo…
Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152, and Thunderbird 140.12.
M Crítico vulnerabilidad
16/06/2026
[CVE-2026-12297] Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability …
Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, and Thunderbird 140.12.
I Crítico vulnerabilidad
15/06/2026
[CVE-2026-48713] Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when u…
Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed to untrusted input). Backend.writeFile() splits each queued missing-key string on the configured keySeparator (default .) before calling the internal setPath() walker. The walker (getLastOfPath in l…
I Crítico vulnerabilidad
15/06/2026
[CVE-2026-48714] i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fasti…
i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the missingKeyHandler blocked the literal request-body keys __proto__, constructor, and prototype (added in 3.9.3, see GHSA-5fgg-jcpf-8jjw), but did not reject dotted variants such as "__proto__.polluted". Downstream backends that split the missing-k…
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-12087] Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_s…
Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then c…
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-48836] Unauthenticated Remote Code Execution (RCE) in Easy Invoice <= 2.1.19 versions.
Unauthenticated Remote Code Execution (RCE) in Easy Invoice
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-45439] Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.
Unauthenticated SQL Injection in Realtyna Organic IDX plugin
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-39465] Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider <= 3.106.0 versions.
Editor Remote Code Execution (RCE) in Responsive Slider by MetaSlider

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50883] An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows a…
An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50873] An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allo…
An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50880] An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to e…
An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-49952] Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that…
Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter integration and the database backup API exposed by dbbak.php. Attackers can inject a crafted payload through the username paramet…
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50869] An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory t…
An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.