Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 4257 resultados ✕ Limpiar búsqueda
13,696
Total alertas
3097
Críticas
10327
Altas
8
Ransomware
1772
Esta semana
RSS
M Alto vulnerabilidad
22/06/2026
[CVE-2026-6858] The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displaye…
The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS attacks against logged in administrator
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12806] A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function for…
A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manipulation of the argument selSSID leads to buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early ab…
M Crítico vulnerabilidad
21/06/2026
[CVE-2026-56395] SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace…
SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS comma…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-56396] phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRig…
phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin users with edit_user permission can set is_superadmin flag or grant arbitrary rights to escalate to SuperAdmin access.
M Crítico vulnerabilidad
21/06/2026
[CVE-2026-56397] SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace…
SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve remote code execution on any user browsing the Bazaar by embedding XSS payloads in package displayName, description, or README fields, exploiting Electron's nodeIntegration setting to execute OS comma…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-56382] Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code exec…
Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and
M Alto vulnerabilidad
21/06/2026
[CVE-2026-56242] Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_…
Capgo before 12.128.2 contains an unauthenticated security definer RPC function get_identity_apikey_only that returns the owning user_id for supplied API keys, creating an API key validity oracle and user identity disclosure primitive. Attackers can call this endpoint with valid or invalid API keys to confirm key validity and map keys to user identifiers, then chain results into other exposed RPCs…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
21/06/2026
[CVE-2026-56253] Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_member…
Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that allows unauthenticated attackers to enumerate organization members. Attackers can invoke the endpoint using only the public sb_publishable_* key and an organization UUID to retrieve sensitive member information including email addresses, user IDs, roles, and pending invitations.
K Crítico vulnerabilidad
21/06/2026
[CVE-2026-56265] Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT…
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentication tokens for any user, bypassing authentication and gaining full access to protected functionality.
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12786] A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this i…
A vulnerability has been found in Ezbsystems UltraISO Premium Edition up to 9.76. Affected by this issue is some unknown functionality in the library bootpt64.sys of the component Kernel Driver. The manipulation leads to improper access controls. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this…
L Alto vulnerabilidad
21/06/2026
[CVE-2026-12795] A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps…
A vulnerability was determined in BerriAI litellm up to 1.82.2. This affects the function json.dumps of the file litellm/proxy/management_endpoints/ui_sso.py of the component SSO Debug Flow. Executing a manipulation can lead to missing authentication. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosu…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12782] A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is a…
A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation results in improper access controls. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The affected component should be upgraded. The vendor ex…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12784] A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown fu…
A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improper access controls. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not r…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12781] A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unk…
A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to improper access controls. The attack needs to be performed locally. The exploit is publicly available and might be used. You should upgrade the affected component. The vendor explains: "We have confir…
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12778] A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affect…
A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12779] A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unkno…
A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation results in improper access controls. The attack must be initiated from a local position. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did …
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12780] A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in th…
A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any …
M Alto vulnerabilidad
21/06/2026
[CVE-2026-12775] A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909…
A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery…
L Alto vulnerabilidad
21/06/2026
[CVE-2026-12773] A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyA…
A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the component MCP Proxy. Executing a manipulation can lead to improper authentication. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The ven…
V Alto vulnerabilidad
20/06/2026
[CVE-2026-56340] vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings p…
vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can submit crafted embedding requests with malformed (negative or out-of-bounds) tensor indices, when the prompt-embeds feature is enabled, to trigger crashes or resource exhaustion (denial of service), with p…