Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 3 horas
14,928
Total alertas
3375
Críticas
11165
Altas
8
Ransomware
865
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-55484] ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking …
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a question mark and then performs the unchecked p[0] access without checking whether the resulting path is empty. An unauthenticated client can send a malformed…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-55485] Piccolo Admin is an admin interface and content management system for Python, built on top of Piccol…
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while piccolo_api/session_auth/tables.py exposes SessionsBase.token because the token column is no…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-55215] MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL …
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js sends credentials before completing certificate fingerprint validation. In lib/cmd/handshake/auth/handshake.js, a server that selects mysql_clear_password as…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-55108] KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until…
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones a repository supplied through a core.oam.dev/v1beta1 ComponentDefinition and follows repository-controlled variables.tf …
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-55065] Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api…
Vikunja is an open-source self-hosted task management platform. From 0.24.6 until 2.4.0, DELETE /api/v1/projects/:project/views/:view permits an authenticated user to supply a view identifier from another project while authorizing only against an attacker-controlled project identifier. ProjectView.CanDelete in pkg/models/project_view_permissions.go does not establish that the view belongs to the p…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-55066] Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/project…
Vikunja is an open-source self-hosted task management platform. Prior to 2.4.0, POST /api/v1/projects/{project}/views/{view}/buckets/{bucket}/tasks accepts a body supplied task_id but TaskBucket.CanUpdate in pkg/models/kanban_task_bucket.go authorizes only the project, view, and bucket from the URL. updateTaskBucket then calls Task.ReadOne without a separate task permission check, returns the vict…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-54788] dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, da…
dd-trace-rs provides Datadog application performance monitoring for Rust. From 0.1.0 until 0.3.3, datadog-opentelemetry/src/propagation/tracecontext.rs parses the W3C tracestate header and collects every semicolon-separated key and value pair in the Datadog dd=... vendor entry into a HashMap without enforcing a pair count or entry size limit. Because tracecontext extraction is enabled by default, …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-82227] Contributor SQL Injection in WPBulky <= 1.2.2 versions.
Contributor SQL Injection in WPBulky
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81757] Author Remote Code Execution (RCE) in Rank Math SEO <= 1.0.276 versions.
Author Remote Code Execution (RCE) in Rank Math SEO
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81760] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngine allows Reflected XSS. This issue affects JetEngine: from n/a through 3.8.14.2.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81767] Unauthenticated Broken Access Control in Simple Payment <= 2.5.2 versions.
Unauthenticated Broken Access Control in Simple Payment
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81285] Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization <= 4.2.0 versio…
Unauthenticated Denial of Service Attack in Smush Image Compression and Optimization
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81019] wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is…
wolfProvider before 1.2.2 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known reco…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-81020] wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is s…
wolfEngine before 1.4.1 generates the 8-byte explicit AES-GCM nonce once when the TLS write key is set and never increments it per record. As a result every TLS 1.2 and DTLS 1.2 AES-GCM record within a connection is encrypted under an identical key and nonce pair. Reusing a GCM key and nonce discloses the keystream (the XOR of two ciphertexts equals the XOR of their plaintexts, so one known record…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-6176] The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripti…
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the aggregated review form submission in versions up to and including 5.106.0. This is due to insufficient input sanitization and output escaping on user-supplied review comment text. The plugin accepts review submissions from unauthenticated users through the 'cr_local_forms_submit' AJAX act…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-5934] The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, a…
The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.21.0.1. This is due to insufficient input sanitization and output escaping of user-supplied data via the rocket_beacon AJAX endpoint. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected p…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-56854] The source-address critical option in the Permissions returned by an authentication callback was onl…
The source-address critical option in the Permissions returned by an authentication callback was only enforced for the PublicKeyCallback and VerifiedPublicKeyCallback paths, extending the fix for CVE-2026-46595. Permissions returned by the PasswordCallback, KeyboardInteractiveCallback, NoClientAuthCallback, and GSSAPIWithMICConfig.AllowLogin callbacks were not validated against the client's remote…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-50979] A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.…
A command injection vulnerability in the 'advanced/curl' component of Osbil Technology oPanel v1.19.50 and earlier allows authenticated attackers to execute arbitrary shell commands via the 'url' parameter
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-38638] An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to caus…
An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-37237] vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exha…
vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image functions in multimodal/inputs.py fetch user-supplied media URLs using aiohttp and call r.read() without enforcing a maximum response size, allowing an attacker to exhaust server memory by providing a URL to an arbitrarily large file.