Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2124 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55532] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, MCP HTTP Stream _validate_origin uses request_origin.startswith(allowed), allowing the attacker-controlled localhost.attacker.com HTTP origin to satisfy the localhost allowlist. A webpage can send Content-Type: text/plain requests without preflight and invoke tools/call without an API key, including file writes that persist agent …
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55533] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows …
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, create_auth_middleware() allows requests when auth=api-key lacks PRAISONAI_API_KEY or JWT authentication lacks PRAISONAI_JWT_SECRET. An externally bound Recipe server can therefore accept unauthenticated POST /v1/recipes/run requests despite authentication being enabled. This issue is fixed in version 4.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55537] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhoo…
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, JobSubmitRequest.validate_webhook_url() accepts webhook_url when resolution raises socket.gaierror because the exception path uses except socket.gaierror: pass. JobExecutor._send_webhook() later performs a fresh lookup, allowing DNS changes to direct the request to an internal service. This issue is fixed in version 4.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79622] A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the …
A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-parser.ts of the component file-access-from-request Endpoint. Executing a manipulation of the argument outputFile/outputDir can lead to path traversal. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. T…
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad de negación de servicio en Ech0 anterior a 5.0.1 por validación insuficiente de encabezados
Ech0 versiones anteriores a 5.0.1 no valida el tamaño ni estructura del encabezado Accept-Language, permitiendo que solicitudes malformadas causen agotamiento de recursos en el middleware i18n. La vulnerabilidad explota una bypass parcial de CVE-2022-32149 en la librería golang.org/x/text, afectando aplicaciones Go que procesan solicitudes HTTP desde internet público o redes no confiables.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de falsificación de solicitud en Ech0 anterior a 4.7.3
Ech0 versiones anteriores a 4.7.3 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en la función fetchPeerConnectInfo que permite a atacantes autenticados acceder a servicios internos y endpoints de metadatos en la nube mediante solicitudes HTTP no validadas. Esta falla afecta principalmente a infraestructuras cloud híbridas en empresas mexicanas y latinoamericanas que utilicen este software para operaciones de conectividad entre pares.
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-49845] SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on …
SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows authenticated users with access to Hive Metastore APIs to read, modify, or affect unintended partition metadata (including statistics updates, truncation targets, and file-metadata cache operations) via crafted partition names in metastore RPC requests when direct SQL is enabled…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-13214] The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getcon…
The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When handling a GetConfiguration request from the central system, the handler copied the attacker-controlled JSON "key" string into the caller's fixed 50-byte stack buffer (skey[CISTR50], declared in subsys/net/lib/ocpp/ocpp.c) using an unbounded strcpy(). The parsed key value points dire…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78682] NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and…
NLTK before 3.10.3 contains a server-side request forgery vulnerability in nltk.pathsec.urlopen (and callers nltk.data.load, nltk.downloader.Downloader.index/download) when an HTTP proxy is configured. pathsec.urlopen validates the requested hostname locally, but proxy-handler inheritance disables the safe HTTP/HTTPS handlers so the actual fetch is performed by the proxy against a destination that…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-77384] libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the re…
libp2p is a JavaScript implementation of the libp2p networking stack. Prior to version 4.2.9, the reservation refresh path in reservation-store.ts reuses the same retimeableSignal but unconditionally registers another abort listener on every refresh. As a result, a remote peer can repeatedly send valid RESERVE requests for the same reservation, causing unbounded listener and closure growth in @lib…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71504] Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that…
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. Attackers can supply an arbitrary user account identifier and new password in the request body to overwrite credentials and…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-76073] Label Studio does not scope the annotation detail endpoint to the requesting user's organization. An…
Label Studio does not scope the annotation detail endpoint to the requesting user's organization. AnnotationAPI in label_studio/tasks/api.py declares queryset = Annotation.objects.all() and provides no get_queryset override, so the default lookup retrieves any annotation by primary key. The view's permission_required entries name annotations.view, annotations.change and annotations.delete, and lab…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-76835] OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may sk…
OAuth2 Proxy honours a client-supplied X-Forwarded-Uri header when deciding whether a request may skip authentication, because the guard added for CVE-2026-40575 is inert in the default reverse-proxy configuration. GetRequestURI in pkg/requests/util/util.go prefers that header over the real request URI whenever CanTrustForwardedHeaders returns true, and isAllowedPath in oauthproxy.go matches the s…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-71933] Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslo…
Multiple DrayTek VigorSwitch models contain unauthorized operation vulnerabilities in multiple syslog functions. The vulnerability is caused by missing authorization checks. A remote attacker can trigger these vulnerabilities via crafted requests to modify configuration, restart services, save startup configuration, or clear logs.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71922] Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerabil…
Multiple DrayTek VigorSwitch models contain a pre-authentication null pointer dereference vulnerability in the setget.cgi interface. The vulnerability is caused by missing validation when the pass field is absent. A remote attacker can trigger this vulnerability via a crafted request to crash the service and cause a denial of service.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71366] A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. …
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates p…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-39915] TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to injec…
TIM Flow before 26.0.6 contains a CRLF injection vulnerability that allows remote attackers to inject arbitrary HTTP headers and response body content by embedding unsanitized carriage return and line feed sequences in the rt URL parameter, which is reflected into Set-Cookie response headers. Attackers can craft malicious requests to induce authenticated users to execute arbitrary JavaScript in th…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-76844] webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the reque…
webpack-dev-middleware resolves a request to a local file in getFilenameFromUrl by testing the request pathname against a traversal guard and then slicing it at a fixed character offset. The guard, UP_PATH_REGEXP applied to path.normalize(`./${pathname}`), only matches ".." that stands as a whole path segment, while the containment test is the string comparison pathname.startsWith(publicPathPathna…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-76847] act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actio…
act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and DeleteArtifact, accept a caller-supplied workflow_run_backend_id and never check that it belongs to the requester: validateRunIDV4 in pkg/artifacts/art…
M Crítico vulnerabilidad
24/08/2026
[CVE-2026-76840] RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buff…
RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in libs/clipboard/src/windows/wf_cliprdr.c requests that many bytes of a remote file through cliprdr_send_request_filecontents and then executes CopyMemo…