Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 4220 resultados ✕ Limpiar búsqueda
13,599
Total alertas
3086
Críticas
10241
Altas
8
Ransomware
1805
Esta semana
RSS
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-45439] Unauthenticated SQL Injection in Realtyna Organic IDX plugin <= 5.1.0 versions.
Unauthenticated SQL Injection in Realtyna Organic IDX plugin
M Alto vulnerabilidad
15/06/2026
[CVE-2026-42668] Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend <= 1.18.0 versi…
Unauthenticated Broken Authentication in Email Marketing for WooCommerce by Omnisend
M Alto vulnerabilidad
15/06/2026
[CVE-2026-53704] A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a…
A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-52719] An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad.…
An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream without validating it against available data. A remote attacker could trick a user into opening a specially crafted JPEG file, causing downstream parsing to read beyond the provided input buffer, leading to a crash or potential informa…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-52722] A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream…
A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, bypassing a length check and leading to out-of-bounds reads. A remote attacker could trick a user into opening a specially crafted VMnc file, potentially causing a crash or information disclosure.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50881] Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor priv…
Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and configuration changes.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50882] An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Den…
An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50884] Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administr…
Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components.
L Alto vulnerabilidad
15/06/2026
[CVE-2026-50889] An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a…
An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a crafted refresh-token header.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50874] An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Remi…
An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50877] An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying f…
An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50878] An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to ca…
An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-50879] An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to c…
An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
M Alto vulnerabilidad
15/06/2026
[CVE-2026-49954] Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that al…
Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted plugin configuration containing path traversal sequences in the directory attribute. Attackers can trigger an exception during plugin installation to bypass sanitization routines, causing malicious paths to …
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-50871] An OS command injection vulnerability in the media archiving and export pipeline component of kanish…
An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-38812] RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affect…
RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges to access sensitive database information.
B Alto vulnerabilidad
15/06/2026
[CVE-2026-41708] In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause …
In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is vulnerable when it uses a vulnerable version of org.springframework.cloud:spring-cloud-sleuth-instrumentation and Spring TX instrumentation is not disabled. Affected versions: Spring Cloud Sleuth 3.1.0 through 3.1.13.
M Crítico vulnerabilidad
15/06/2026
[CVE-2026-36537] ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code e…
ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of the /login/oauth2/code/ endpoint. By manipulating the email address in this JSON object, a remote attacker can bypass authentication and gain full access to any existing user account on the platform w…
M Alto vulnerabilidad
15/06/2026
[CVE-2026-8357] LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed w…
LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very long formula made up of many opening tokens. The array that tracks nesting depth was allocated one element too small for that worst case, so such a formula wrote one element past its end. In fixed versions the array is sized to hold the largest possible nesting.
E Alto vulnerabilidad
15/06/2026
[CVE-2026-5079] Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service …
Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested field names in multipart form data. The append-field dependency parses bracket notation in field names with no limit on nesting depth, allowing an attacker to force allocation of deeply nested object structures that consume CPU and memory. A single HTTP request with a crafted multi…