Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 584 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1016
Esta semana
RSS
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107302] msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder rea…
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the decoder reads the four-byte length of a map32 value before validating that the complete five-byte header is available. A truncated map32 header therefore causes a checked out-of-bounds buffer read and throws RangeError instead of IncompleteBufferError, which can unexpectedly terminate a request, stream, or wor…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107333] Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua …
Malcolm's nginx based reverse proxy contains a URL path normalization inconsistency between its Lua based role-based access control (RBAC) authorization layer and nginx's own request routing logic. An authenticated user can craft a specially formatted request path to bypass role-based restrictions and reach administrative or role gated endpoints they should not have access to. This affects all res…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-50054] An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with acc…
An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107295] Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. …
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A website visited by a developer can submit a browser-compatible request to a loopback-hosted chat server, causing the served agent to run and execute tools wi…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107639] ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerabili…
ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-separated options, which escapeshellcmd() does not neutralise, to write a PHP file under the web root and achieve remote code execution.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107286] Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. …
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency can retain shared concurrency slots because anyio.CapacityLimiter associates an acquired slot with the borrowing task while streaming cleanup can run in a different task. Early stream terminat…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-105833] EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\…
EspoCRM before 10.0.5 contains an insecure direct object reference vulnerability in PersonalAccount\Service that allows users with Email Account scope access to retrieve other users' IMAP passwords. Attackers who know a victim's Email Account record ID can request that record to steal stored IMAP credentials and access the victim's mailbox.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-62142] Cross-Site Request Forgery (CSRF) vulnerability in Melapress WP 2FA wp-2fa allows Cross Site Request…
Cross-Site Request Forgery (CSRF) vulnerability in Melapress WP 2FA wp-2fa allows Cross Site Request Forgery.This issue affects WP 2FA: from n/a through 4.1.0.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-66479] Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allo…
Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through 2.9.5.6.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-44031] Uncontrolled recursion in DcmSequenceOfItems::read() and DcmItem::read() in the dcmdata library of O…
Uncontrolled recursion in DcmSequenceOfItems::read() and DcmItem::read() in the dcmdata library of OFFIS DCMTK 3.7.0 allows a remote, unauthenticated attacker to cause a denial of service (stack exhaustion and process crash) via a DICOM dataset containing deeply nested sequences (SQ elements). The dataset can be sent in a C-STORE request to storescp, dcmrecv, dcmqrscp, or any other DICOM service b…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-106611] Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Forminator forminator allows Cross Site …
Cross-Site Request Forgery (CSRF) vulnerability in WPMU DEV Forminator forminator allows Cross Site Request Forgery.This issue affects Forminator: from n/a through 1.57.3.
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad alta en hMailServer 6.0.0-6.3.5: fallo en validación DANE/DNSSEC en SMTP saliente
hMailServer versiones 6.0.0 a 6.3.5 contienen una vulnerabilidad que permite eludir la validación DANE (RFC 7672) en entregas SMTP salientes. El servidor no valida correctamente respuestas DNSSEC incompletas, malformadas o sin pruebas NSEC/NSEC3, permitiendo entregas de correo a destinos no autenticados. Afecta principalmente a proveedores de correo y servidores de mensajería en LATAM que dependen de DNSSEC para seguridad de entrega.
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad alta en hMailServer: validación de Host faltante permite ataque de fuerza bruta
Progressive Robot hMailServer versiones 6.0.0 a 6.3.5 contienen deficiencias en la validación de encabezados HTTP y falta de limitación de intentos fallidos en su API REST, permitiendo ataques de DNS rebinding para comprometer credenciales de administrador. Empresas en LATAM que utilizan este servidor de correo son vulnerables a toma de control administrativo si el listener REST está habilitado, incluso en configuraciones de loopback.
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad alta de escalado de privilegios en hMailServer 6.3.4 y 6.3.5
El servicio hmailserver-update en hMailServer 6.3.4 y 6.3.5 ejecuta operaciones como root sin validar correctamente los parámetros de actualización proporcionados por la cuenta de servicio no privilegiada, permitiendo escalado de privilegios. Un atacante con acceso a la cuenta hmailserver podría comprometer completamente el servidor de correo y la infraestructura subyacente. Esta vulnerabilidad afecta directamente a empresas LATAM que ejecutan hMailServer como solución de correo corporativo.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-103692] The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce che…
The Frontend Dashboard WordPress plugin before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data, allowing unauthenticated users to take over any account, including administrators.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107230] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.0.0 until 3.0.14, connection-pool partitioning still omits identity-defining fields for Kerberos, SPNEGO, NTLM, and authenticated proxy connections. Logins without a configured principal, proxy realms, identities sharing a user name, and SOCKS or CONNECT prox…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107232] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Prior to 3.0.12 on 3.x and 2.16.1 on 2.x, the client infers that an HTTP proxy tunnel exists from the last request method rather than the CONNECT result. After a proxy rejects CONNECT, redirect or authentication handlers can write an origin request and its Authoriza…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107352] Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed a…
Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Amazon S3 data were not affected. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. No custo…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-107227] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 2.2.0 until 3.0.14, WebSocket permessage-deflate decompression is unbounded when compression is enabled. The inbound pipeline aggregates compressed frames before WebSocketClientCompressionHandler inflates them, so webSocketMaxFrameSize and webSocketMaxBufferSiz…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-20362] A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticate…
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successfu…