Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2124 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad SSRF alta en Budibase Server anterior a 3.41.3
Budibase Server versiones anteriores a 3.41.3 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) en el endpoint de importación de consultas que no valida URLs suministradas por usuarios. Atacantes pueden enviar URLs arbitrarias para obtener respuestas de servicios internos, metadatos en cloud (AWS, Azure, GCP) y recursos de red restringidos. Esta exposición afecta principalmente a empresas en LATAM que utilizan Budibase para integración de datos entre aplicaciones internas y plataformas cloud.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de escalada de privilegios en Budibase anterior a 3.41.3
Budibase versiones anteriores a 3.41.3 no valida correctamente las asignaciones de roles de constructor a nivel de aplicación en los endpoints públicos de creación y actualización de usuarios. Un constructor autenticado con acceso limitado a una aplicación puede explotar esta falla para otorgarse a sí mismo acceso de constructor en otras aplicaciones del mismo tenant, comprometiendo la segmentación de datos en entornos multi-tenant comunes en empresas medianas de LATAM.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de autorización en Budibase anterior a v3.41.3 permite inyección de recursos
Budibase versiones anteriores a 3.41.3 contienen una vulnerabilidad de autorización faltante en el endpoint POST /api/resources/duplicate que permite a constructores autenticados inyectar tablas, automatizaciones, consultas y pantallas en otras aplicaciones sin permisos en el espacio de trabajo destino. Un atacante puede especificar un ID de espacio de trabajo arbitrario en el cuerpo de la solicitud para comprometer la integridad de múltiples proyectos.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad SSRF alta en Budibase Server anterior a 3.41.3 expone credenciales de CouchDB
Budibase Server versiones anteriores a 3.41.3 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en el endpoint de verificación de fuentes de datos. Usuarios con permisos de constructor pueden enviar URLs arbitrarias sin validación, permitiendo a atacantes extraer credenciales internas de CouchDB y obtener acceso total a bases de datos en despliegues en la nube. Esto es alta para empresas LATAM que utilizan Budibase en infraestructura compartida o multitenante.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82234] SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_reques…
SiYuan versions before v3.8.1 contain a server-side request forgery vulnerability in the http_request and web_fetch agent tools that perform DNS resolution only at guard time without validating the connect-time resolution. Attackers can use DNS rebinding to answer the guard resolution with a public IP and the connect resolution with a private or metadata IP, bypassing the SSRF defense to access cl…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82239] Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/que…
Budibase before 3.41.3 fails to enforce per-table role restrictions on the POST /api/datasources/query endpoint, allowing low-privilege BASIC users to read, create, update, or delete rows in any table regardless of configured permissions. Attackers with BASIC role can submit crafted query requests with target table identifiers to bypass table-level access controls and manipulate restricted data.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75814] The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the…
The Ebyte device does not adequately verify the origin or authenticity of requests submitted to the web management interface. An unauthenticated remote attacker could persuade an authenticated administrator to visit a crafted page, causing unauthorized configuration changes or a disruption of device availability.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
28/08/2026
[CVE-2026-76060] An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionalit…
An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HTTP request parameter is passed unsanitized into a shell command executed via PHP's exec(), allowing any authenticated user with View Events permission to execute arbitrary operating system commands on the server.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75418] A path traversal vulnerability exists in the built-in preview/development web server of Lektor <3.3.…
A path traversal vulnerability exists in the built-in preview/development web server of Lektor
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75419] go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() fun…
go-wind-cms (GoWind) before 1.0.0 has a missing authorization vulnerability. The NewAuthorizer() function in app/admin/service/internal/data/data.go and app/app/service/internal/data/data.go returns a no-op authorization engine (noop.State{}), so the authz middleware always allows requests. Any authenticated user (regardless of role or tenant) can invoke administrative APIs such as deleting users,…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-71187] The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticat…
The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacker may generate valid authentication requests and bypass authentication to obtain administrative access to the device.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-54330] Ceph is an open-source distributed storage platform providing object, block, and file storage. In ve…
Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2.4 and 19.2.6, the Ceph Object Gateway (RGW) SigV4 handler does not reject requests that carry x-amz-* headers absent from the signed header set, allowing anyone holding a presigned URL to attach arbitrary unsigned x-amz-* headers that RGW will honor. AWS S3 requires every x-amz-…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-77438] Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.10…
Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the public share-search endpoint does not enforce the per-note shareCredentials and shareHiddenFromTree controls, allowing an unauthenticated visitor to read the titles, tree paths, and content of protected shared notes. The endpoint authorizes only the ancestor note supplied in the request and…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-59324] When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emit…
When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recently consumed upstream. Spring Integration 7.1.0 Spring Integration …
M Alto vulnerabilidad
27/08/2026
[CVE-2026-59316] Spring Authorization Server's default consent page renders user-controlled values without HTML entit…
Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page presented to the end user. Spring Authorization Server 1.5.0 - 1.5.8 Spring Authorizat…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-19092] The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal …
The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rendering templates, allowing unauthenticated users to invoke arbitrary zero-argument PHP functions and receive their output.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81678] AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL functio…
AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can bypass SSRF protections via the LiveLinks proxy endpoint to reach internal services and cloud metadata endpoints by encoding private IPv4 targets in transition …
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81679] OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the …
OpenRemote versions before 1.28.0 contain a cross-realm information disclosure vulnerability in the Notification REST API that allows per-realm tenant administrators to read all tenants' sent notifications including message bodies. Attackers with read:admin credentials in one realm can submit a zero-parameter GET request to the notification endpoint to retrieve sensitive notification metadata and …
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81335] Baserow dispatches an Application Builder data source without acting on the result of its permission…
Baserow dispatches an Application Builder data source without acting on the result of its permission check. The dispatch and record-name views in backend/src/baserow/contrib/builder/api/data_sources/views.py are declared with a permission class that admits any caller, so a request carrying no credential reaches the handler. DataSourceService.dispatch_data_sources in backend/src/baserow/contrib/bui…
M Crítico vulnerabilidad
27/08/2026
[CVE-2026-81098] The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller cre…
The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and parsed the caller's authentication headers in a mode that did not fail when they were absent, so a request without any credential completed initialisation and dispatched tools. Dispatch f…