Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2123 resultados ✕ Limpiar búsqueda
22,337
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1207
Esta semana
RSS
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86728] AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php…
AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and complete programme schedules without authentication.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86721] AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cook…
AVideo through commit c3edcc274c contains an authorization bypass vulnerability where a session cookie named 'key' with value 'value' overrides the $_REQUEST['key'] parameter in saveLive.php and related endpoints. Attackers can publish to any user's RTMP stream without authentication by using the known constant stream key value to hijack live broadcasts.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86723] AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerabil…
AVideo through c3edcc274c389816d434acadac07ee78eaf330c1 contains an authentication bypass vulnerability in LoginControl::verifyChallenge() that uses loose comparison (==) instead of strict comparison (===) against unset session values. Attackers with only a password can submit an empty request to verifyChallenge.json.php to bypass PGP two-factor authentication and gain full authenticated access.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86718] WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request fo…
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in deleteHistory.json.php and finishAll.json.php that allows unauthenticated attackers to mutate live history by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger administrator browsers to delete all live transmission history or m…
M Alto vulnerabilidad
08/09/2026
[CVE-2026-86600] In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity t…
In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and send it to a host they control. The captured token can be replayed to Snowflake f…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-61516] Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that…
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session …
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73314] XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handl…
XenForo before 2.3.13 contains a signature verification logic error in the PayPal REST webhook handler that allows unauthenticated attackers to bypass payment signature validation by submitting a webhook request with an unsupported auth_algo header value. When the algorithm cannot be mapped to a supported hash function, the verification function incorrectly returns true instead of failing, causing…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-73315] XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhoo…
XenForo before 2.3.13 contains a server-side request forgery vulnerability in the PayPal REST webhook handler that allows unauthenticated attackers to cause the server to make outbound HTTP requests to arbitrary destinations by supplying a crafted certificate URL in webhook headers without scheme, hostname, or allowlist validation. Attackers can submit a crafted POST to the PayPal webhook callback…
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta en Reyrolle 7SR5 permite denegación de servicio remota
Se identificó una falla en el servidor web de Reyrolle 7SR5 (versiones anteriores a V2.70) que no limita adecuadamente los recursos del sistema al procesar múltiples solicitudes HTTP concurrentes. Un atacante no autenticado puede explotar esta vulnerabilidad para causar el colapso y reinicio del dispositivo, interrumpiendo sistemas altas de protección en subestaciones eléctricas. En LATAM, donde estos relés protegen infraestructura eléctrica esencial, el impacto operacional es severo.
M Alto vulnerabilidad
08/09/2026
Vulnerabilidad alta de escalada de privilegios en Reyrolle 7SR5 (CVSS 8.8)
Se ha identificado un fallo en los controles de autorización del lado del servidor en la interfaz de gestión web de Reyrolle 7SR5 en todas las versiones anteriores a V2.70. Un atacante autenticado con permisos bajos puede eludir las restricciones de control de acceso basado en roles (RBAC) manipulando datos de solicitudes para escalar privilegios a nivel administrativo. Esto afecta directamente a infraestructuras altas de distribución eléctrica y subestaciones en LATAM que dependen de estos dispositivos de protección.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-81806] Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side …
Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-76969] @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multit…
@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. …
M Alto vulnerabilidad
08/09/2026
[CVE-2026-66767] SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a…
SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user's session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the applic…
M Crítico vulnerabilidad
08/09/2026
[CVE-2026-44756] A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Und…
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availabil…
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86539] knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embeddin…
knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can enumerate internal hosts and cloud metadata endpoints by observing transport error messages that reveal network reachability information.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86438] Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire a…
Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP modules from the marketplace over unsigned HTTP requests, achieving remote code execution.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86498] In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed…
In JetBrains YouTrack before 2025.3.160480, 2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission
M Alto vulnerabilidad
07/09/2026
[CVE-2026-18453] A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling…
A flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86428] commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the Attrib…
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing.
M Alto vulnerabilidad
07/09/2026
[CVE-2026-86273] A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the func…
A weakness has been identified in projeto-siga siga up to 11.1.1. Affected by this issue is the function DownloadExterno.getUrl of the file sigaex/src/main/java/br/gov/jfrj/siga/vraptor/ExUtilController.java of the component HTML-to-PDF Endpoint. This manipulation of the argument html causes server-side request forgery. The attack may be initiated remotely. The exploit has been made available to t…