Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
[CVE-2024-14029] Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as havi…
Tornado before 6.4.1 ignores duplicate Transfer-Encoding: chunked headers, treating requests as having no message body and parsing the chunked body as a subsequent request. Attackers can exploit this inconsistency when Tornado is deployed behind proxies to perform HTTP request smuggling, enabling access control bypass, cache poisoning, or connection desynchronization.
M Alto vulnerabilidad
15/09/2026
[CVE-2023-54397] Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Con…
Tornado before 6.3.3 contains an HTTP request smuggling vulnerability due to improper parsing of Content-Length headers accepting non-standard characters. Attackers can send crafted HTTP requests with these characters to bypass proxy validation and smuggle requests when deployed behind certain proxies.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90650] The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th…
The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook event object 'id' in all versions up to, and including, 6.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The pr…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-89025] Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated …
Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to missing validation of HTTP(S) content. A remote unauthenticated attacker can send a specially crafted HTTP(S) request to a specific endpoint that is processed incorrectly, causing the device to perform an unintended reboot and resulting in a temporary denial-of-service condition. T…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-88616] An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskC…
An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java component, and the FlwTaskServiceImpl.completeTask, CompleteExecuteComponent.process, Warm-Flow TaskService.skip, POST /workflow/task/completeTask components
M Alto vulnerabilidad
15/09/2026
[CVE-2026-79425] An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of…
An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows attackers to scan internal resources via a crafted POST request.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57586] CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior t…
CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default agent-coderag sync flow in code_rag/entry/cli.py calls sync_dependencies for an indexed path, and code_rag/core/manager.py treats build.gradle or build.gradle.kts as sufficient to invoke _sync_gradle. _sync_gradle prefers a repository-controlled gradlew or gradlew.bat file and p…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-55178] GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map …
GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.2.3, multiple read and link endpoints authorize only the resource named in the request URL and fail to re-authorize a second caller-influenced dataset reached through a relationship, map layer, VRT source, externalId lookup, or request body. When a public map references a private…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-53957] Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to…
Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-server 1.7.19 and @contentful/mcp-tools 0.4.5, export_space and import_space in packages/mcp-tools/src/tools/jobs/space-to-space-migration/exportSpace.ts and packages/mcp-tools/src/tools/jobs/space-to-space-migration/importSpace.ts expose host, proxy, rawProxy, and insecure network …
M Alto vulnerabilidad
15/09/2026
[CVE-2026-54167] Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositor…
Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the GitHub App provider accepts X-GitHub-Enterprise-Host as the API host while processing webhook events containing an installation.id, before webhook signature validation or confirmation that the host matches the repository URL in the signed payload…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-16140] OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authoriza…
OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C. This issue effectively allows for privilege escalation wi…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-16141] OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated…
OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcR…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92073] Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 1…
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92062] Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, …
Privilege escalation in the Session Restore component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92055] Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156 and Fire…
Privilege escalation in the DevTools component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92054] Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156 and Firefo…
Privilege escalation in the Memory component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92053] Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox…
Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92047] Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 a…
Privilege escalation in the Crash Reporting component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92052] Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulner…
Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, and Thunderbird 156.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-92043] Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnera…
Privilege escalation due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Firefox ESR 153.3.