Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Quest" — 2123 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad de autorización en Craft CMS 5.0.0-RC1 a 5.10.10 permite reemplazo no autorizado de activos
Craft CMS versiones 5.0.0-RC1 hasta 5.10.10 contienen un fallo de autorización en AssetsController::actionReplaceFile que permite a usuarios autenticados con permisos limitados reemplazar archivos sin validación de permisos. El defecto ocurre cuando se omite el parámetro assetId, resolviendo el activo destino por carpeta y nombre de archivo después de las verificaciones de permisos. Empresas en LATAM con portales de contenido, sitios de agencias digitales o plataformas de gestión de medios basadas en Craft CMS están potencialmente expuestas.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad CSRF sin autenticación en Activity Log <= 2.13.1
Se ha identificado una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) sin requerimiento de autenticación en Activity Log versiones 2.13.1 y anteriores, con puntuación CVSS de 7.1. Esta falla permite a atacantes ejecutar acciones no autorizadas en sistemas vulnerables mediante solicitudes manipuladas. Organizaciones en LATAM que utilicen este componente deben evaluar su exposición inmediatamente.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad CSRF en Simply Schedule Appointments <= 1.6.12.23 permite acciones no autorizadas
Se ha identificado una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) sin autenticación en Simply Schedule Appointments en versiones hasta 1.6.12.23. Esta vulnerabilidad permite a atacantes realizar acciones no autorizadas en nombre de usuarios legítimos, afectando principalmente a empresas de servicios, clínicas y consultorías en LATAM que utilizan este plugin para gestionar citas. Con un CVSS de 8.8, representa un riesgo alto para la integridad de datos y la continuidad operativa.
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad CSRF alta en Mang Board WP versiones ≤2.3.8 permite ataques no autenticados
Se ha identificado una vulnerabilidad de Falsificación de Solicitud entre Sitios (CSRF) no autenticada en el plugin Mang Board WP hasta la versión 2.3.8, con puntuación CVSS 8.8. Esta falla permite a atacantes realizar acciones maliciosas en sitios WordPress afectados sin requerir credenciales, poniendo en riesgo la integridad de contenido, datos de usuarios y configuraciones administrativas en empresas de México y Latinoamérica que dependen de este plugin.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19219] In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog …
In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient integrity protection of dialog request parameters used by the RadEditor file browser may allow an attacker who has obtained certain application encryption key material to alter the folders the file browser reads from, writes to, and uploads into, potentially resulting in remote code execution.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-19723] The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properl…
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in an inline JavaScript event handler, leading to Reflected Cross-Site Scripting which is triggered when a user interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPr…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-12526] The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the reques…
The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user action of its front-end Forms module; it only checks a capability when the submitted role is administrator or super_admin. On a site that exposes a publicly reachable front-end form whose user-update action targets an existing ad…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/09/2026
[CVE-2026-12865] The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters be…
The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one on the Shortcode page, one on the Galleries/Albums list page), so an unauthenticated attacker can craft a link that, when opened by a logged-in administrator (or, for the first sink, a contributor), executes arbitrary JavaScrip…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84715] FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSu…
FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84700] PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the cl…
PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests. Although requirepass is intended to gate replication — a slave presents it as masterauth inside its MetaSync request — only the MetaSync handler (HandleMetaSyncRequest) validates …
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84482] WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_d…
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration changes.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84476] WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers…
WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks.
M Crítico vulnerabilidad
01/09/2026
[CVE-2023-54391] Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in …
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with a…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84366] Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/co…
Scrapy is a high-level web crawling and scraping framework for Python. Prior to 2.17.0, in scrapy/core/downloader/handlers/s3.py, Scrapy's S3DownloadHandler converts an S3-scheme bucket and key request into a plaintext HTTP request to the corresponding S3 endpoint unless request.meta["is_secure"] is explicitly enabled, then signs and sends the plaintext request with configured AWS credentials. A n…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-73780] A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a …
A vulnerability in the web-based management interface of AOS-CX switches exposes some sessions to a lack of Cross-Site Request Forgery (CSRF) protection. This could allow a remote unauthenticated attacker to execute arbitrary input against the affected interface if the attacker can convince an authenticated user of the interface to interact with a specially crafted URL.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/09/2026
[CVE-2026-8712] Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticat…
Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitrary targets by supplying a malicious `uri` query parameter to the HTTP API. Attackers can pass arbitrary `tcp://` or `unix://` URIs to affected endpoints including /api/info, /api/speech-to-text, and /api/text-to-speech to overr…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84268] A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious …
A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to write past the intended boundaries. This issue allows a malicious server to corrup…
M Crítico vulnerabilidad
01/09/2026
[CVE-2026-78012] An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-messa…
An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-18780] Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft…
Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84218] A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-co…
A flaw was found in Jolokia's JSR-160 proxy functionality where insufficient validation of client-controlled JMX service URLs allows a bypass of the denylist introduced to mitigate CVE-2018-1000130. The proxy accepts a `target.url` value from a Jolokia POST request and passes it to `JMXServiceURL` and `JMXConnectorFactory` for establishing the remote JMX connection. The existing denylist only reje…