Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Dify" — 30 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105221] The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows …
The gist RubyGem before 6.1.0 contains an improper certificate validation vulnerability that allows on-path attackers to intercept HTTPS traffic because http_connection in lib/gist.rb sets VERIFY_NONE. Attackers can present any certificate to read or modify GitHub API traffic, stealing OAuth tokens and login credentials to read and modify the victim's gists.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105216] go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network …
go-micro before 6.0.0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default. Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens an…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105218] gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go…
gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-93697] There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Account…
There is a stored XSS vulnerability allowing arbitrary code execution in the WHM Mass Modify Accounts interface.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103766] ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated u…
ClipBucket v5 through 5.5.3-#197 contains an sql injection vulnerability that allows authenticated users with ad_manager_access permission to inject SQL via the delete parameter in admin_area/ads_manager.php. Attackers can supply time-based blind payloads concatenated into AdsManager::DeleteAd queries to extract user credentials and emails or modify and delete arbitrary records.
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad alta en Ghost 5.2.0 a 6.61.x permite inyección de contenido sin autenticación
Ghost versions 5.2.0 hasta anteriores a 6.62.0 contienen una vulnerabilidad que permite a atacantes remotos, sin autenticación, explotar el flujo de Stripe Checkout para adjuntar suscripciones pagas a miembros existentes, modificar nombres de usuarios e inyectar contenido malicioso en newsletters. El contenido inyectado puede ejecutarse como HTML o XSS dependiendo del cliente de correo, afectando principalmente a plataformas de publicación y membership en LATAM que utilizan Ghost para contenido de pago.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103256] n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the …
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated hosts. Attackers with credential update permissions can modify the host field to receive account passwords at arbitrary hosts, bypassing domain validation controls.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-15983] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Dire…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting — combined with the `s…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-85679] The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' …
The Extendify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'styles.blocks' Block Type Key in all versions up to, and including, 3.1.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because r…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-82824] Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that …
Hitachi Coding Software Suite contains a vulnerability related to Path Traversal vulnerability that allows an attacker to access, create, modify, or delete files. This issue affects Hitachi Coding Software Suite: through 3.3.0.