Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 583 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XSS almacenada alta en plugin YPTWallet de AVideo (CVSS 8.7)
AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenada en el plugin YPTWallet que afecta el manejo de valores de CryptoWallet. Los datos no se escapan HTML antes de guardarse en wallet_log.information, permitiendo que administradores ejecuten código malicioso al revisar solicitudes de retiro pendientes en pendingRequests.php. Empresas de streaming y plataformas de monetización en LATAM usando esta versión enfrentan riesgo de compromisos administrativos.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad SSRF alta en WWBN AVideo permite lectura de archivos locales sin autenticación
WWBN AVideo contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en la función _json_decode que permite a atacantes no autenticados enviar rutas de archivos o URLs HTTP a login.json.php para leer archivos locales o acceder a servicios internos. Los resultados se interpretan como credenciales de acceso, exponiendo configuraciones sensibles, bases de datos y tokens de sistemas en empresas de LATAM que utilizan este software para streaming de video.
M Alto vulnerabilidad
11/09/2026
Fuga de memoria en middleware compression de Node.js y Express (CVE-2026-87776)
El middleware compression para Node.js y Express en versiones anteriores a 1.8.2 presenta una vulnerabilidad que causa fuga de memoria nativa de zlib cuando clientes abortan conexiones durante respuestas comprimidas. Un atacante remoto puede agotar recursos del servidor mediante desconexiones repetidas y prematuras, impactando la disponibilidad de aplicaciones web y API REST en entornos de producción de LATAM.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-87908] multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1…
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An unauthenticated attacker can send a single request whose part carries a very large volume of header bytes, forcing the parser to buffer all of them and …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-82097] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-80380] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized ac…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-89049] A server-side request forgery issue due to improper validation of equivalent address representations…
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role cre…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88045] rclone is a command-line program to sync files and directories to and from different cloud storage p…
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to multipart.NewRW().Reserve before reading request-body bytes. waitForTurn admits the current part and one oversized part when the buffer is empty despite -…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88899] knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in t…
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88018] rclone is a command-line program to sync files and directories to and from different cloud storage p…
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty ws.s3Secret. gofakes3 then verifies the request’s SigV4 signature against that same empty secret, while Server.auth passes …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45747] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88887] Renovate is a dependency update automation tool. When listing tags/digests for a container image, Re…
Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the same origin as the original registry. A malicious or compromised container registry can therefore s…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88880] Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagi…
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88872] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sending a GET request. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, sets or clears any user's channel password without C…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88873] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request fo…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrators' browsers to request the endpoint, copying sensitive application log…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88876] AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vu…
AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() without password validation. Attackers can request the seo.php endpoint with a video ID to obtain the direct MP4 URL and read protected media bytes witho…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88870] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request fo…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation. Attackers can craft malicious pages with image tags pointing to savePublicKey.json.php to replace a logged-in victim's PGP 2FA public key, causing lockout or enabling account takeover if the attacker kn…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88863] capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank aga…
capgo.app (npm package `capgo`) through version 12.207.1 does not compare the caller's role rank against the requested role in the validateInvite() function of supabase/functions/_backend/private/invite_new_user_to_org.ts. The POST /private/invite_new_user_to_org endpoint only requires the org.update_user_roles permission for org_super_admin invitations, so an authenticated user holding only the o…
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.14 permite denial of service remoto
GeoVision GV-LPC2211 versión 1.14 (260903) contiene un fallo de validación en campos de longitud variable en múltiples manejadores de solicitudes VLSVR, permitiendo que atacantes no autenticados causen el colapso del servicio. Esta vulnerabilidad afecta principalmente a sistemas de vigilancia y control de acceso implementados en infraestructuras altas de México y Latinoamérica, generando riesgo de indisponibilidad operativa.
M Alto vulnerabilidad
10/09/2026
Vulnerabilidad alta en GeoVision GV-LPC2211 V1.13 permite denegación de servicio remota
La cámara IP GeoVision GV-LPC2211 versión 1.13 presenta una falla en la validación de tokens ONVIF WS-Discovery que permite a atacantes remotos sin autenticación corromper el estado de control de pila y crashear el proceso de descubrimiento. Esta vulnerabilidad afecta directamente la disponibilidad de sistemas de videovigilancia altas en infraestructuras de seguridad física de empresas, data centers y operaciones en LATAM.