Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 86 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1038
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Ahora mismo
[CVE-2026-96278] The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUES…
The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Session History in all versions up to, and including, 9.3.03.002 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The bypass wor…
M Alto vulnerabilidad Nuevo
Hace 27 min
[CVE-2026-96558] The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to S…
The Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker plugin for WordPress is vulnerable to Stored DOM-Based Cross-Site Scripting via the 'qsm_hidden_questions' parameter in all versions up to, and including, 11.2.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene…
M Crítico vulnerabilidad Nuevo
Hace 3 horas
[CVE-2026-104732] The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions …
The Advanced IP Blocker plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 8.13.13 The vulnerability exists because `handle_login_action()` performs no server-side check — via transient, session marker, or equivalent — that a requester completed step-1 password authentication before processing a step-2 TOTP submission for the POSTed `user_id`; compoun…
M Alto vulnerabilidad Nuevo
Hace 13 horas
[CVE-2026-107839] ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Ag…
ageLANServer provides a cross-platform web server and launcher for offline multiplayer in several Age of Empires and Age of Mythology games. Prior to version 1.15.2, the AoE3 POST /game/cloud/getFileURL handler in the bundled game server has no request body size limit or cap on the attacker-controlled JSON names array and allocates response storage directly from the unbounded array length. A remot…
M Alto vulnerabilidad Nuevo
Hace 13 horas
[CVE-2026-107840] yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the…
yopass is a service for securely sharing secrets, passwords, and files. Prior to version 14.7.0, the Prometheus metrics middleware in pkg/server/server.go uses the attacker-controlled r.Method value directly as the method label for yopass_http_requests_total and yopass_http_request_duration_seconds. Because the catch-all route accepts arbitrary HTTP method tokens, an unauthenticated remote attacke…
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-75349] EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability…
EIPStackGroup OpENer v2.3.0/master up to commit 76b95cf contains an out-of-bounds read vulnerability in Connection Manager request parsing. This allows a remote attacker to cause a denial of service.
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-108113] ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI questio…
ILIAS before 9.24, 10.12, and 11.5 contains an unrestricted file upload vulnerability in QTI question import image handling (ilQtiMatImageSecurity) that allows authenticated authors to write executable files. Attackers with question pool import rights can import a crafted archive writing a .htaccess and PHP file to the web-served image directory, achieving remote code execution as the web server u…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-107811] Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenti…
Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, ordinary authenticated users can access /api/nodes and /api/nodes/:id, whose responses serialize the node token field. The same token is accepted as X-Node-Secret by AuthRequired and maps the request to initUser, allowing the user to impersonate a trusted node against a reachable cluster member. This cross-node auth…
M Crítico vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-108107] PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.p…
PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.
M Alto vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-107805] Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signatur…
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume tempo…
M Alto vulnerabilidad Nuevo
Hace 17 horas
[CVE-2026-62026] Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allo…
Cross-Site Request Forgery (CSRF) vulnerability in MIGHTYminnow Dashboard Notes dashboard-notes allows Cross Site Request Forgery.This issue affects Dashboard Notes: from n/a through 1.0.3.
M Alto vulnerabilidad Nuevo
Hace 21 horas
Vulnerabilidad CSRF alta en Featured Image from URL (fifu.app) versiones hasta 6.0.7
Se detectó una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) en el plugin Featured Image from URL para WordPress que permite a atacantes ejecutar acciones no autorizadas en sitios afectados. La vulnerabilidad impacta versiones desde la inicial hasta la 6.0.7, afectando miles de sitios WordPress en LATAM que utilizan este plugin para gestión de imágenes destacadas. Con CVSS 8.8, representa un riesgo alta para la integridad y disponibilidad de contenido.
M Alto vulnerabilidad Nuevo
Hace 21 horas
[CVE-2026-78024] Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Si…
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Server-Side Request Forgery (SSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Protection mechanism bypass, Server-side request forgery, and Unauthorized access.
M Alto vulnerabilidad Nuevo
Hace 23 horas
[CVE-2026-19575] The user-mode verification handler for the device_deinit() system call, z_vrfy_device_deinit() in ke…
The user-mode verification handler for the device_deinit() system call, z_vrfy_device_deinit() in kernel/device.c, validated its dev argument with K_SYSCALL_OBJ_INIT(dev, K_OBJ_ANY). k_object_validate() short-circuits its type comparison when the requested type is K_OBJ_ANY, so the check reduced to "this pointer is the base address of some kernel object the calling thread has been granted" — the o…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-93548] The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitle…
The FooSales WordPress plugin before 1.43.3 does not verify that an authenticated caller is entitled to act as the user a request names, allowing any authenticated user to have the FooSales WordPress plugin before 1.43.3 act as an arbitrary other user, including an administrator, resulting in that user's account details being exposed and their account being taken over.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107914] Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration ex…
Backdrop CMS 1.34 before 1.34.5 and 1.35 before 1.35.1 doesn't sufficiently protect configuration exports when delivering a compressed archive. This vulnerability is mitigated by the fact that an export must have been previously requested by someone with the "Synchronize, import, and export configuration" permission.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107781] Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side reques…
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerability in the OnlyOffice save callback editUploadOfficeFileById. Unauthenticated attackers can supply arbitrary url and key parameters to make the server fetch internal URLs and overwrite any user's stored file, then read results via queryFileToShowById.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107318] @fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. …
@fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. In versions prior to 12.7.0, all of the built-in HTTPS transports override the secure default and set rejectUnauthorized to false, so the proxy does not verify the TLS certificate of the upstream even when the application points it at an https upstream in the default configuration. An on-path networ…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-104075] TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authenticat…
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain an authentication bypass vulnerability in the web management login endpoint POST /tvu/Login that allows remote unauthenticated attackers to obtain an administrative session by submitting an empty or absent UserName parameter. Attackers can send a crafted HTTP request directly, bypassing client-side JavaScript val…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-104076] TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing auth…
TVU Networks Receiver/Transceiver devices running firmware before version 7.9 contain a missing authentication vulnerability that allows remote unauthenticated attackers to read sensitive device information and modify device configuration via unprotected REST API endpoints on port 8288. Attackers can send unauthenticated GET requests to disclose network configuration, firmware details, and cloud s…