Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 9074 resultados ✕ Limpiar búsqueda
14,046
Total alertas
3206
Críticas
10568
Altas
8
Ransomware
1054
Esta semana
RSS
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13183] In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing ma…
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-13184] In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is …
In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-44191] A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vuln…
A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts settings, allowing an attacker to inject shell separators. This can be triggered automatically during Language Server initialization or manually when ex…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-65603] The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in …
The Grav Login plugin (grav-plugin-login) versions
M Alto vulnerabilidad
22/07/2026
[CVE-2026-61390] There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthentic…
There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-61391] There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow auth…
There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-57600] Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthe…
Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
22/07/2026
[CVE-2026-4773] Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA…
Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-44189] A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider…
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly sanitized, leading to the execution of arbitrary code with the privileges of the user running VS Code. Th…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-44190] A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vuln…
A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual environment activation script, does not properly validate user input as a file path. If a user opens or exec…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-14551] The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.…
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData%\ServerEye3\update\ for a trigger file named "update_available". Due to insufficient access restric…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-63047] Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Bo…
Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - The Joomla extension Events Booking prior version 5.0-5.8.1 did not properly verify that an actor is allowed to download invoice information.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-12987] The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data o…
The Events Manager WordPress plugin before 7.3.7 does not safely handle booking-registration data on sites using No-User-Account Booking Mode: a booker-supplied registration field is stored as booking meta and later deserialized without restricting allowed classes, enabling PHP object injection. The resulting gadget chain reaches a database query that is built without parameterisation, so an unau…
M Alto vulnerabilidad
22/07/2026
[CVE-2026-3821] Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. …
Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attacker can exploit SMASH’s input capability to compromise data integrity or launch a Denial-of-Service (DoS) attack against the BMC.
M Alto vulnerabilidad
22/07/2026
[CVE-2026-12968] The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not r…
The Product Addons and Product Options With Custom Fields WordPress plugin before 1.6.15 does not restrict an unauthenticated file-upload endpoint and accepts SVG files that are stored and served inline, allowing an unauthenticated attacker to upload a malicious SVG whose embedded script executes in the session of any user (such as an administrator) who later opens the file.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/07/2026
[CVE-2026-15802] The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient …
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_locations_backup_file_callback' function in all versions up to, and including, 4.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files on the server, which can easily lead to remote code execution …
M Alto vulnerabilidad
21/07/2026
[CVE-2026-65315] Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata …
Ollama (HEAD f0078ae) contains an uncontrolled memory allocation vulnerability in the GGUF metadata parser that allows remote attackers to crash the server by supplying a crafted GGUF file with attacker-controlled length and count fields in string lengths, tensor dimension counts, and metadata array counts that are used as allocation sizes without validation against remaining file size. Attackers …
M Alto vulnerabilidad
21/07/2026
[CVE-2026-65317] Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined wi…
Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin middleware bypass that allows unauthenticated remote attackers to make the server issue arbitrary HTTP requests by supplying a crafted Origin header and attacker-controlled host and port values. Attackers can bypass the localhost origin check in the API middleware by sending any Ori…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-65318] Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerab…
Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows unauthenticated attackers to cause the backend to issue arbitrary HTTP GET requests by supplying attacker-controlled URLs through the WebSocket import endpoint. Attackers can connect to the /ws/import_files WebSocket endpoint without authentication, specify arbitrary URLs in the HT…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-65319] Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allow…
Feedbin (commit 739884a) contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve private article content by sending requests to the entries text API endpoint, which skips the authorization before-action filter entirely. Attackers can iterate sequential integer entry IDs through the GET /api/v2/entries/:id/text endpoint to enumerate and ext…