Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 9 min
13,434
Total alertas
3054
Críticas
10108
Altas
8
Ransomware
1740
Esta semana
RSS
M Alto vulnerabilidad
27/07/2026
[CVE-2026-17568] Improper access control in the role membership management endpoint in Devolutions Server allows an a…
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier
M Alto vulnerabilidad
27/07/2026
[CVE-2026-66729] facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body …
facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attackers to crash the server process by sending a crafted Content-Disposition header with an empty field name. Attackers can trigger a uint32_t wraparound in http_mime_parser.h causing an out-of-bounds memory read past the name pointer, resulting in a bus f…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-66730] facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser…
facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker to permanently freeze worker processes at 100% CPU by sending a multipart/form-data request with a partial closing boundary. The missing progress guard in the parser loop causes http_mime_parse to return 0 bytes consumed without setting done or error f…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-66731] facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked tran…
facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated remote attackers to crash the server by sending a negative chunk size value. Attackers can send a single POST request with a Transfer-Encoding: chunked header containing a leading minus sign in the chunk size field, causing the parser in http1_parser.…
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-63077] In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible …
In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol
M Alto vulnerabilidad
27/07/2026
[CVE-2026-24252] NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A s…
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-17191] An input validation vulnerability exists in an API component of the orchestrator. An authenticated u…
An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend queries, which may result in unauthorized access to data beyond their intended privileges and cause the underlying system to initiate unintended outbound network connections. This issue was discovered internally by Arista and the company is not awa…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/07/2026
[CVE-2026-17192] A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on …
A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to internal services that are not otherwise accessible. This vulnerability requires a minimum role of Enterprise Standard Admin. This issue was discovered internally by Arista and the company is not aware of any malicious uses of this issue in customer net…
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-66395] SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar p…
SiYuan desktop before v3.7.2 contains a reflected cross-site scripting vulnerability in the bazaar plugin readme handler that allows attackers to execute arbitrary code by crafting a malicious siyuan:// deep link. Attackers can inject HTML payloads via the plugin name parameter that execute with full Node.js access through insertAdjacentHTML rendering in an insecurely configured Electron renderer.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-66396] SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Ga…
SiYuan before v3.7.2 fails to escape the title-img Individual Attribute List value when rendering Gallery and Kanban cover images, allowing stored cross-site scripting via unescaped style attribute interpolation. Attackers with editor permissions can inject onload handlers that execute arbitrary code in the Electron renderer with full Node.js access when victims open affected documents.
M Alto vulnerabilidad
27/07/2026
[CVE-2026-66394] SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanit…
SiYuan before v3.7.3 contains stored and reflected cross-site scripting vulnerabilities in SVG sanitization that allows authenticated attackers to execute scripts by bypassing the HTML parser-based cleaner. Attackers can hide script tags within desc, style, or noscript elements which the HTML parser treats as raw text but browsers interpret as executable SVG content when served as image/svg+xml, e…
M Crítico vulnerabilidad
27/07/2026
[CVE-2025-50455] SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Al…
SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments
M Alto vulnerabilidad
27/07/2026
[CVE-2026-66050] NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer se…
NitroShare Desktop through 0.3.4 contains a path traversal vulnerability in its LAN file transfer server that allows unauthenticated attackers on the same network to write arbitrary files by sending a crafted filename containing directory traversal sequences in the JSON item header name field. Attackers can exploit the lack of path validation to write files outside the transfer root directory to a…
M Alto vulnerabilidad
27/07/2026
[CVE-2026-66427] Administrator SQL Injection in WP Google Review Slider <= 18.4 versions.
Administrator SQL Injection in WP Google Review Slider
M Crítico vulnerabilidad
27/07/2026
[CVE-2026-59550] Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.
Unauthenticated SQL Injection in AWP Classifieds

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59551] Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.10 versions.
Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPress
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59552] Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder <= 1.4.2…
Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF Viewer &amp; Embedder
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59553] Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <= 7.6.1 versions.
Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59556] Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce <=…
Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Discount Rules for WooCommerce
M Alto vulnerabilidad
27/07/2026
[CVE-2026-59558] Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4.2 versions.
Unauthenticated Cross Site Scripting (XSS) in Booking Calendar