Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 436 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55247] plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iC…
plone.app.event provides the event content type for Plone. Prior to versions 5.2.4 and 6.0.1, the iCalendar import in src/plone/app/event/ical/importer.py accepts insufficiently restricted calendar and event URLs, does not adequately bound downloaded bytes or imported events, and commits work per event. A logged-in editor can make the server request internal network resources or local calendar fil…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-54745] Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. …
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function accepts an arbitrary attacker-controlled HTTP or HTTPS target and passes its o…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-71187] The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticat…
The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-19092] The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal …
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81098] The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller cre…
The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's authentication headers in a mode that did not fail when they were absent, so a request without any credential completed initialisation and dispatched tools. Dispatch f…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-54569] SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.…
SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SENAITE.CORE JSON API permits unauthenticated remote code execution through a two-request chain involving missing authorization and unsafe evaluation. The state-changing routes in src/bika/lims/jsonapi/update.py, including update, update_many, remove, doActionFor, doActionFor_many,…
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80528] In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while us…
In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal_info handle_reply() stores a `ceph_mds_request` pointer in `current->journal_info` while filling the inode and dentry cache from an MDS reply. An allocation in this section can enter direct reclaim and prune dentries from another filesystem. If this dirties an ext4 inode, ext…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
26/08/2026
[CVE-2026-80349] TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header…
TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's proxy option to true without naming which upstream proxies may be trusted and without limiting the number of forwarded hops, so the request address Koa reports is taken from the X-Forwarded-For header supplied by the caller. In midware/ssoMidware.js a single branch covers both th…
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica en ClipBucket V5: ejecución de comandos arbitrarios en instalador web
El instalador web de ClipBucket V5 no valida correctamente el parámetro php_cli_filepath, permitiendo que atacantes no autenticados ejecuten comandos arbitrarios con privilegios del servidor web mediante una solicitud POST maliciosa. Afecta principalmente a plataformas de video hosting y streaming implementadas en datacenters de LATAM sin actualizaciones de seguridad.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-65905] Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, b…
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay window.   This issue affects Apache Tomcat: …
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de traversal de directorios en DB-GPT permite ejecución de código remoto
DB-GPT construye rutas de destino para habilidades cargadas usando nombres de archivo sin validación, permitiendo ataques de traversal de directorios. Un atacante puede escribir archivos fuera del directorio designado e inyectar código malicioso. Afecta infraestructuras de IA/ML en empresas mexicanas y latinoamericanas que utilizan esta plataforma para procesamiento de datos.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-76193] Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that …
Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-49845] SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on …
SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updates, truncation targets, and file-metadata cache operations) via crafted partition names in metastore RPC requests when direct SQL is enabled…
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-13214] The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getcon…
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled JSON "key" string into the caller's fixed 50-byte stack buffer (skey[CISTR50], declared in subsys/net/lib/ocpp/ocpp.c) using an unbounded strcpy(). The parsed key value points dire…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-76835] OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may sk…
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns true, and isAllowedPath in oauthproxy.go matches the s…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-71933] Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslo…
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-76840] RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buff…
RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in libs/clipboard/src/windows/wf_cliprdr.c requests that many bytes of a remote file through cliprdr_send_request_filecontents and then executes CopyMemo…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-78169] A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the functio…
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
M Crítico vulnerabilidad
22/08/2026
Vulnerabilidad crítica SSRF en plugin Mailgun para WordPress permite acceso no autorizado
El plugin Mailgun for WordPress versiones hasta 2.2.0 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) por validación insuficiente en la función add_list(). Atacantes no autenticados pueden explotar el path traversal mediante claves controladas en $_POST['addresses'] para acceder a recursos internos del servidor. Afecta directamente a sitios WordPress en México y LATAM que utilizan este plugin para gestión de correos transaccionales.
M Crítico vulnerabilidad
21/08/2026
[CVE-2026-61539] Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and …
Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Llama3 tool-call output to eval() in xinference/model/llm/tool_parsers/llama3_tool_parser.py and xinference/model/llm/utils.py. Requests to /v1/chat/completions with a tools field flow through xinference/api/restful_api.py, xinference/model/llm/transfor…