Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 8999 resultados ✕ Limpiar búsqueda
13,971
Total alertas
3188
Críticas
10511
Altas
8
Ransomware
1115
Esta semana
RSS
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-59145] Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot,…
Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The attach-time validator si_validate_header is thorough about the header and layout (magic, version, section offsets, total_size, count and arena_used) but does not validate the three arrays it then trusts. Every lookup in si_idx_find walks a triple indir…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-59146] Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unv…
Data::SpatialHash::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via unvalidated bucket, link and free-list indices in sph_walk_cell and sph_alloc_slot. The attach-time validator sph_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. sph_walk_cell reads entries[buckets[b]] and foll…
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-59147] Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an …
Data::DisjointSet::Shared versions before 0.02 for Perl allow out-of-bounds reads and writes via an unvalidated parent index in dsu_find. The attach-time validator dsu_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. dsu_find walks and path-compresses parent[x] with x a raw file-stored index never bounded a…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-50758] Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to…
Cross Site Scripting vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to execute arbitrary code via the mcp parameter
M Alto vulnerabilidad
21/07/2026
[CVE-2026-50759] An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /stat…
An issue in exo-explore exo 1.0.69 allows a remote attacker to escalate privileges via the GET /state and DELETE /instance/{instance_id} endpoints with no authentication.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-56852] A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-46600] Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the messa…
Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-47667] CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the…
CImg Library is a C++ library for image processing. Prior to version 4.0.0 in `_load_analyze()`, the header_size field is read as an `unsigned int` from the first 4 bytes of an Analyze/NIfTI file and passed directly to `new unsigned char[header_size]` without being bounded against the actual file size. A value up to ~4 GB is accepted. If the subsequent `fread` returns `short` as it will for any m…
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-50755] An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive informat…
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value
M Alto vulnerabilidad
21/07/2026
[CVE-2026-50756] An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive informat…
An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the x-ai-provider component
M Alto vulnerabilidad
21/07/2026
[CVE-2026-50757] Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to e…
Directory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draw-io/mcp-server
M Alto vulnerabilidad
21/07/2026
[CVE-2026-30632] Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the c…
Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via crafted folder name value to the create_doc tool.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-15957] Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers fr…
Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. Uncontrolled recursion in the JSON, CBOR, and XML deserializer functions emitted by Amazon smithy-rs code generation could allow remote attackers to cause a denial of service (process abort via stac…
M Alto vulnerabilidad
21/07/2026
[CVE-2026-64877] An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access…
An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-63453] Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitati…
Buffer overflow vulnerabilities exist in the command line interface of AOS-CX. Successful exploitation of these vulnerabilities could allow a remote high-privileged user to execute arbitrary code as a privileged user on the underlying operating system.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
21/07/2026
[CVE-2026-63454] An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vuln…
An authenticated path traversal vulnerability exists in AOS-CX. Successful exploitation of this vulnerability allows an attacker to copy arbitrary files to a user readable location from the command line interface of the underlying operating system, which could lead to remote code execution.
M Alto vulnerabilidad
21/07/2026
[CVE-2026-55084] DHIS2 is a flexible information system for data capture, management, validation, analytics and visua…
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. A SQL injection vulnerability was identified in the SqlView API endpoint of the DHIS2 application in the `filter` parameter used by the `/api/sqlViews/{viewId}/data.json` endpoint. An authenticated user with access to a SqlView can inject arbitrary SQL queries inside the `filter` parameter…
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-59139] Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated ar…
Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The attach-time validator reqrep_validate_header checks the header scalars and region layout against the file size, but does not validate the array contents it then trusts. reqrep_recv_locked does memcpy(copy_buf, req_arena + arena_off, len) with arena_o…
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-59140] Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated no…
Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. The attach-time validator ss_validate_header bounds only the root index against the node pool (node_capacity). The order-statistics and min/max queries then follow children[], leftmost and rightmost node indices read raw from the mmap'd segment withou…
M Crítico vulnerabilidad
21/07/2026
[CVE-2026-59141] Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated no…
Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The attach-time validator rdx_validate_header checks the header scalars and region layout against the file size, but does not validate the node records it then trusts. rdx_find_locked indexes nodes[cur].children[k] and reads each node's label_off and label_l…