Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2123 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Crítico vulnerabilidad
11/09/2026
[CVE-2026-79395] An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routin…
An improper authentication vulnerability in the WS-Security (wsse:UsernameToken) verification routine within the Sofia IPC daemon in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837 and earlier allows remote attackers to bypass authentication and execute privileged ONVIF actions (including PTZ control, stream URL retrieval, and system reboot) via a crafted SOAP request supplying the admin…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89260] MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback …
MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at POST /wechat/wechatCheck. The WechatRestApi.index() method passes the raw request body to SignUtil.xmlToMap(), which uses an unhardened dom4j SAXReader without DTD or external-entity restrictions. Unauthenticated remote attackers can submit DOCTYPE declarations with external parameter ent…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89262] MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint…
MoguBlog through 6.2 contains an authorization bypass vulnerability in the comment deletion endpoint that performs ownership checks against request-body fields instead of the authenticated principal. Attackers can delete arbitrary comments and their replies by supplying comment UIDs and author UIDs obtained from unauthenticated listing endpoints.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-89013] Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthentica…
Dolibarr 23.0.4 before 24.0.1 ontains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip token validation while satisfying the authorization condition in htdocs/document.php and htdocs/viewimage.php, gaining acc…
M Alto vulnerabilidad
11/09/2026
[CVE-2026-71416] Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, th…
Headroom compresses data before the data reaches a large language model. Prior to version 0.35.0, the Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM requests without authentication. This can be exploited by a malicious WebSocket …
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad alta de lectura de archivos sin autenticación en WWBN AVideo (CVE-2026-89250)
WWBN AVideo contiene una vulnerabilidad de lectura de archivos sin autenticación en el endpoint getRecordedFile.php que expone archivos de video grabados en FLV desde el directorio temporal. Atacantes pueden descargar archivos de video en vivo sin validación de autenticación utilizando claves de stream conocidas o adivinadas. Este riesgo afecta principalmente a plataformas de streaming y educación en línea en LATAM que utilizan esta solución para transmisiones en vivo.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XSS almacenada alta en plugin YPTWallet de AVideo (CVSS 8.7)
AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenada en el plugin YPTWallet que afecta el manejo de valores de CryptoWallet. Los datos no se escapan HTML antes de guardarse en wallet_log.information, permitiendo que administradores ejecuten código malicioso al revisar solicitudes de retiro pendientes en pendingRequests.php. Empresas de streaming y plataformas de monetización en LATAM usando esta versión enfrentan riesgo de compromisos administrativos.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad SSRF alta en WWBN AVideo permite lectura de archivos locales sin autenticación
WWBN AVideo contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en la función _json_decode que permite a atacantes no autenticados enviar rutas de archivos o URLs HTTP a login.json.php para leer archivos locales o acceder a servicios internos. Los resultados se interpretan como credenciales de acceso, exponiendo configuraciones sensibles, bases de datos y tokens de sistemas en empresas de LATAM que utilizan este software para streaming de video.
M Alto vulnerabilidad
11/09/2026
Fuga de memoria en middleware compression de Node.js y Express (CVE-2026-87776)
El middleware compression para Node.js y Express en versiones anteriores a 1.8.2 presenta una vulnerabilidad que causa fuga de memoria nativa de zlib cuando clientes abortan conexiones durante respuestas comprimidas. Un atacante remoto puede agotar recursos del servidor mediante desconexiones repetidas y prematuras, impactando la disponibilidad de aplicaciones web y API REST en entornos de producción de LATAM.
M Alto vulnerabilidad
11/09/2026
[CVE-2026-87908] multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1…
multiparty is a Node.js library for parsing multipart/form-data request bodies. In versions from 2.1.0 up to but not including 4.3.1, the parser does not bound the amount of memory used while accumulating the headers of a single multipart part. An unauthenticated attacker can send a single request whose part carries a very large volume of header bytes, forcing the parser to buffer all of them and …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-82097] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-80380] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized ac…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-89049] A server-side request forgery issue due to improper validation of equivalent address representations…
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Amazon AWS Systems Manager Agent (SSM Agent) before 3.3.4851.0 on all platforms might allow an authenticated remote user to bypass the remote destination denylist and reach link-local endpoints, potentially obtaining the temporary IAM role cre…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88045] rclone is a command-line program to sync files and directories to and from different cloud storage p…
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.75.0 until 1.75.1, the serve S3 streamed multipart path in cmd/serve/s3/multipart.go passes attacker-controlled contentLength to multipart.NewRW().Reserve before reading request-body bytes. waitForTurn admits the current part and one oversized part when the buffer is empty despite -…
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88899] knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in t…
knowns versions before 0.31.0 fail to properly validate the x-opencode-directory request header in the /api/opencode proxy endpoint. Remote attackers can supply arbitrary directory paths to execute file operations outside the project root on the host system.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
10/09/2026
[CVE-2026-88018] rclone is a command-line program to sync files and directories to and from different cloud storage p…
rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any client-chosen accessKeyID with an empty ws.s3Secret. gofakes3 then verifies the request’s SigV4 signature against that same empty secret, while Server.auth passes …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-45747] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.16, the Lua TLS certificate information helper could dereference NULL certificate fields when a Lua script requested certificate information for TLS traffic where some certificate fields were absent. Crafted TLS traffic processed by a deployment using affected …
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88887] Renovate is a dependency update automation tool. When listing tags/digests for a container image, Re…
Renovate is a dependency update automation tool. When listing tags/digests for a container image, Renovate follows pagination links supplied by the remote registry in the HTTP Link header and attaches the registry credentials to the follow-up request without verifying that the pagination URL has the same origin as the original registry. A malicious or compromised container registry can therefore s…
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88880] Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagi…
Renovate before 44.11.3 fails to validate Link header destinations when following GitLab server pagination, allowing malicious servers to redirect credential-bearing requests. Attackers controlling a compromised GitLab server can specify a Link header pointing to attacker-controlled infrastructure to exfiltrate authentication credentials.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-88872] AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery…
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sending a GET request. Attackers can craft a malicious webpage that, when visited by an authenticated administrator, sets or clears any user's channel password without C…