Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2124 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Crítico vulnerabilidad
31/08/2026
ToolJet anterior a v3.16.208: Falla de validación de organizationId permite acceso no autorizado
ToolJet antes de la versión 3.16.208 no valida que el parámetro organizationId en las solicitudes de API coincida con el workspace autenticado del usuario. Un administrador de workspace puede crear, visualizar y eliminar tablas de base de datos en otros workspaces modificando el parámetro organizationId, comprometiendo la seguridad de datos en entornos multi-tenant críticos para empresas en LATAM.
M Alto vulnerabilidad
31/08/2026
Vulnerabilidad de escalada de privilegios en ToolJet Database anterior a v3.16.44
ToolJet Database versiones anteriores a v3.16.44 contienen una vulnerabilidad de escalada de privilegios en el endpoint join_tables que otorga capacidades JOIN_TABLES a todos los usuarios autenticados sin validar rol o pertenencia al workspace. Atacantes pueden leer tablas arbitrarias de cualquier workspace en ToolJet Database suministrando identificadores de workspace víctima en la ruta de solicitud mientras se autentican con su propio workspace.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82659] nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level…
nodemailer before 9.0.1 fails to apply disableFileAccess and disableUrlAccess flags to message-level raw option, allowing authenticated attackers to read arbitrary files or perform server-side request forgery by supplying path or href properties. Attackers can exploit this by crafting raw messages with file paths or URLs that bypass the intended sandbox, with fetched content delivered in the outgo…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82630] A vulnerability was identified in PowerJob up to 5.1.2. Impacted is the function MuConnectionManager…
A vulnerability was identified in PowerJob up to 5.1.2. Impacted is the function MuConnectionManager.getOrCreateConnection of the file powerjob-server/powerjob-server-starter/src/main/java/tech/powerjob/server/web/controller/TestController.java of the component Transport Endpoint. The manipulation leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit …
M Alto vulnerabilidad
31/08/2026
[CVE-2026-40463] WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log File…
WaveSuite is affected by an insufficient role-based access control vulnerability in the CPB Log Files feature. Successful exploitation allows an authenticated low-privilege user to load pages restricted to higher-privilege roles by requesting the corresponding URL directly in the browser.
M Alto vulnerabilidad
30/08/2026
[CVE-2026-56718] AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in …
AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows unauthenticated remote attackers to read arbitrary files with root privileges by supplying path traversal sequences in the HTTP request URI. Attackers can send crafted HTTP requests to port 80 without authentication to access sensitive files including cleartext R…
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82657] Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for foru…
Admidio before 5.0.12 fails to enforce login-only module restrictions in RSS feed endpoints for forum and announcements modules. Unauthenticated attackers can retrieve forum topics and announcements by sending GET requests to rss/forum.php or rss/announcements.php, disclosing titles, full post text, author names, and timestamps.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82648] WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL …
WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fe to reach cloud metadata services and loopback interfaces.
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82645] AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/vie…
AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the endpoint to return any restream's stream_key and stream_url (credentials for external platforms such as YouTube, Facebook…
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82638] jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthe…
jina-ai reader disables its private-address guard outside Google Cloud deployments, allowing unauthenticated attackers to perform server-side request forgery. Attackers can supply publicly resolvable hostnames mapping to private addresses to retrieve cloud metadata and internal service content.
M Alto vulnerabilidad
30/08/2026
Vulnerabilidad alta de desbordamiento de búfer en NASA Trick 19.6.0 (CVE-2026-82478)
Se identificó una vulnerabilidad de desbordamiento de búfer en pila en NASA Trick 19.6.0, específicamente en la función JSONVariableServerThread::parse_request del manejador de sockets TCP. Esta falla permite ejecución remota de código sin autenticación previa. Afecta principalmente a instituciones de investigación, universidades y centros aeroespaciales en Latinoamérica que utilizan esta herramienta de simulación científica.
M Crítico vulnerabilidad
29/08/2026
Escalada de Privilegios Crítica en Plugin Custom User Registration Fields para WooCommerce (CVE-2026-15369)
El plugin Custom User Registration Fields para WooCommerce (versiones hasta 2.2.3) permite a atacantes no autenticados escalar privilegios mediante manipulación del parámetro afreg_select_user_role en la API /wc/store/v1/checkout. Esta vulnerabilidad afecta directamente tiendas en línea alojadas en servidores WordPress en México y LATAM, permitiendo que usuarios no autenticados asuman roles administrativos sin validación. El CVSS 9.8 indica riesgo crítico con alcance de red y sin requerimientos de autenticación.
M Alto vulnerabilidad
29/08/2026
Vulnerabilidad alta en KubeEdge CloudCore 1.23.1 permite falsificación de estado de actualización de nodos
KubeEdge CloudCore versiones hasta 1.23.1 acepta reportes de estado de tareas sin autenticación en puerto 10002, permitiendo a atacantes modificar el estado de trabajos de upgrade. Esto compromete la integridad del plano de control en infraestructuras edge/IoT, siendo alta para organizaciones en LATAM con despliegues en manufactura, utilities y telecomunicaciones que dependen de orquestación automática de actualizaciones.
M Crítico vulnerabilidad
29/08/2026
Vulnerabilidad crítica en argocd-mcp 0.8.0: exposición de interfaz HTTP sin autenticación
ArgoCD MCP versión 0.8.0 expone su transporte HTTP en todas las interfaces de red sin requerir credenciales cuando ARGOCD_API_TOKEN está configurado. Atacantes con acceso a la red pueden invocar la superficie completa de herramientas utilizando el token del operador para crear aplicaciones, ejecutar sincronizaciones y modificar recursos de Argo CD. Esta vulnerabilidad afecta crítica a infraestructuras de CI/CD en empresas que operan Kubernetes en LATAM.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-77012] The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its…
The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not require a per-install secret for one of its unauthenticated endpoints, relying on a hardcoded default, and does not validate the URLs or destination paths it is given, allowing unauthenticated attackers to read arbitrary files from the server, force it to issue arbitrary requests and retrieve the responses, and write attacker-supplied conten…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/08/2026
[CVE-2026-77007] The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perfo…
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the shared secret used to sign API requests to the connected BigBlueButton server.
M Alto vulnerabilidad
29/08/2026
[CVE-2026-16600] The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJ…
The SmartAIPress WordPress plugin through 1.2.0 does not perform a capability check on one of its AJAX actions and does not validate a user-supplied URL before fetching it server-side, allowing users with subscriber-level access and above to make the site retrieve arbitrary internal or external URLs and read the response, resulting in a full-read Server-Side Request Forgery.
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16947] The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a …
The Total processing card payments for WooCommerce WordPress plugin through 7.3 does not validate a user-supplied path before using it to build a server-side verification request, and does not verify the authenticity of the response, allowing unauthenticated attackers to redirect that request to an arbitrary host (disclosing the merchant's payment-gateway credentials) and to forge a success respon…
M Crítico vulnerabilidad
29/08/2026
[CVE-2026-16259] The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified th…
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password,…
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en MapFish Print permite inyección XXE en servidores de mapas
MapFish Print versiones anteriores a 3.28.30, 3.30.32, 3.31.24, 3.33.16 y 4.0.5 contienen una vulnerabilidad de inyección XML External Entity (XXE) en el endpoint /api/print3/print. Un atacante remoto puede enviar capas GML maliciosas para ejecutar ataques XXE sin validación de entidades externas, poniendo en riesgo servidores de cartografía y sistemas SIG en gobiernos, empresas constructoras y plataformas de infraestructura en LATAM.