Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2116 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1012
Esta semana
RSS
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-106038] Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allo…
Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object via Remove, RemoveByRegex, RemoveAll and BatchRemove on the coro_rpc port. Attackers can send forged requests with the force flag set to bypass lease checks, wipe keys matching any regex, or clear the entire store, causing cache loss and reques…
M Alto vulnerabilidad
Hace 3 días
Ejecución remota de código autenticada en Craft CMS 5.10.13.2
Craft CMS 5.10.13.2 contiene una vulnerabilidad de ejecución remota de código (RCE) en el panel de control que afecta a usuarios autenticados. Un atacante con acceso básico al panel puede manipular propiedades de componentes y tipos de entrada para ejecutar código arbitrario. Esta vulnerabilidad impacta principalmente a agencias web, desarrolladores y empresas en LATAM que utilizan Craft CMS como gestor de contenidos.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39728] Unauthenticated Server Side Request Forgery (SSRF) in Instapage Plugin <= 3.7.2 versions.
Unauthenticated Server Side Request Forgery (SSRF) in Instapage Plugin
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39719] Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versio…
Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-39724] Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager <= 1.3.11 versions.
Unauthenticated Cross Site Scripting (XSS) in HTTP Requests Manager
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-94293] An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH req…
An unauthenticated remote attacker can modify Asset Administration Shell submodel data via PATCH requests and can read all data exposed by the GET endpoints.
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-57559] Memory corruption while processing service requests.
Memory corruption while processing service requests.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
Hace 3 días
[CVE-2026-82989] There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a r…
There is an input injection in vCast exposed network services in ViewSonic ViewBoard that allows a remote, unauthenticated attacker to inject arbitrary input into service endpoints via network-based HTTP requests to unauthenticated endpoints
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105762] Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/…
Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data…
M Alto vulnerabilidad
Hace 3 días
[CVE-2026-105761] Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/&lt;…
Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/&lt;app_id&gt;/server endpoint in api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to retrieve an AppMCPServer by the client-supplied server ID without verifying that the server belonged to the requested application and tenant. An authenticated workspace member could therefore…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105639] Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logge…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer u…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105634] Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_up…
Plane is an open-source project management tool. Prior to 1.3.0, the ProjectMemberViewSet.partial_update method allows any project member, including a user with the lowest GUEST role, to modify another project member's role. The authorization check prevents assigning a role higher than the requester's role but does not prevent assigning a lower or equal role, allowing a Guest to demote Administrat…
M Crítico vulnerabilidad
Hace 4 días
[CVE-2026-105636] Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/a…
Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-105628] Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronizatio…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by default. An attacker can provide an avatar URL that redirects to an internal-only resource, such as a metadata endpoint, and Plane uploads the fetched response…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104973] Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validate…
Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is created in apps/api/plane/app/serializers/webhook.py. The delivery task in apps/api/plane/bgtasks/webhook_task.py performs a separate DNS resolution when sending the request and does not validate the resolved IP address, allowing DNS rebinding to bypas…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-104970] Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint …
Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs account creation without an atomic transaction, row lock, uniqueness guard, or advisory lock. Two concurrent unauthenticated requests with different email addresses …
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-92931] CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package ver…
CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad alta de SSRF en feelec-yishu feelcrm-os 1.0.0
Se identificó una vulnerabilidad de Server-Side Request Forgery (SSRF) en feelcrm-os versión 1.0.0 que permite manipular el parámetro URL en el endpoint getCurlData del controlador GoogleController.class.php. Un atacante remoto puede ejecutar solicitudes no autorizadas desde el servidor afectado hacia sistemas internos o externos, comprometiendo la confidencialidad de datos y la integridad de la infraestructura. El exploit ha sido divulgado públicamente, elevando significativamente el riesgo para empresas mexicanas y latinoamericanas que utilicen este CRM.
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad CSRF alta en Blubrry PowerPress Podcasting hasta versión 11.17.9
Se ha identificado una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) en el plugin Blubrry PowerPress Podcasting para WordPress que afecta versiones hasta 11.17.9. Esta falla permite a atacantes ejecutar acciones no autorizadas en plataformas de podcasting, incluyendo modificación de contenido y configuraciones administrativas. Es especialmente alta para medios, productoras de contenido y plataformas de distribución de audio en LATAM que utilizan este plugin.
M Alto vulnerabilidad
Hace 4 días
Vulnerabilidad SSRF alta en ChatGPTNextWeb NextChat hasta versión 2.16.1
Se ha identificado una vulnerabilidad de Server-Side Request Forgery (SSRF) en ChatGPTNextWeb NextChat versiones hasta 2.16.1, ubicada en la función proxyHandler del componente Proxy Fallback Handler (app/api/proxy.ts). Un atacante remoto puede manipular el argumento x-base-url para ejecutar solicitudes HTTP arbitrarias desde el servidor afectado, potencialmente comprometiendo datos internos, accediendo a servicios de red privados o saltando controles de seguridad perimetral. La explotación es remota y código de prueba ya está disponible públicamente.