Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
14,046
Total alertas
3206
Críticas
10568
Altas
8
Ransomware
1050
Esta semana
RSS
G Alto vulnerabilidad
30/06/2026
[CVE-2026-13779] Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote at…
Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
G Crítico vulnerabilidad
30/06/2026
[CVE-2026-13780] Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed …
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
G Crítico vulnerabilidad
30/06/2026
[CVE-2026-13781] Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a…
Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
M Alto vulnerabilidad
30/06/2026
[CVE-2025-71349] picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle…
picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using trace.Trace.run in the reduce method to achieve arbitrary code execution when pickle.load processes the file.
M Alto vulnerabilidad
30/06/2026
[CVE-2025-71350] picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run fu…
picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed undetected code in pickle files that executes remote commands when loaded by victims.
M Alto vulnerabilidad
30/06/2026
[CVE-2025-71352] picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used i…
picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files with trace.Trace.runctx payloads that bypass picklescan detection and execute code upon pickle.load() invocation.
M Alto vulnerabilidad
30/06/2026
[CVE-2025-71363] picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allow…
picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files with cProfile.run payloads that bypass picklescan detection and achieve code execution upon deserialization.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/06/2026
[CVE-2025-71368] picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle fil…
picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files embedding doctest.debug_script calls that bypass picklescan detection and execute arbitrary commands upon pickle.load invocation.
M Alto vulnerabilidad
30/06/2026
[CVE-2025-71371] picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.ru…
picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce methods. Attackers can craft pickle payloads that bypass picklescan detection and execute arbitrary code when loaded via pickle.load().
M Alto vulnerabilidad
30/06/2026
[CVE-2025-71374] picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used …
picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce methods, allowing attackers to execute arbitrary code. Remote attackers can craft malicious pickle files that bypass picklescan detection and achieve code execution upon deserialization.
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-58449] txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body …
txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver, which performs __import__ and getattr on the caller-supplied dotted path with no allowlist. When the API is exposed with no TOKEN configured (authentication is opt-in, so all endpoints are unauthenticated) and the index is configured writable, a rem…
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-50003] A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode wr…
A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, using both relative (../) paths and absolute paths.
M Alto vulnerabilidad
30/06/2026
[CVE-2026-50254] An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak m…
An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.
M Alto vulnerabilidad
30/06/2026
[CVE-2026-52196] Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to…
Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_416f28 component
M Alto vulnerabilidad
30/06/2026
[CVE-2026-52868] An unauthenticated attacker can read worklist records from a directory outside the intended per-AE w…
An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/06/2026
[CVE-2026-57585] MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out…
MessagePack is the serializer implementation for Python msgpack.org. Prior to 1.2.1, there is an Out-of-bounds read/crash on Unpacker reuse after a caught error, potentially leading to a DoS attack. If the Unpacker is used repeatedly after an error occurs, the process may crash with a SEGV. This issue has been fixed in version 1.2.1.
I Alto vulnerabilidad
30/06/2026
[CVE-2026-11541] IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Se…
IBM CICS Transaction Gateway for Multiplatforms 9.1, 9.2, 9.3, and 10.1 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are affected by an HTTP request smuggling vulnerability.
M Alto vulnerabilidad
30/06/2026
[CVE-2026-35505] An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. I…
An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.
M Crítico vulnerabilidad
30/06/2026
[CVE-2026-37106] An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via …
An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this is disputed by the Supplier because this is the intentional behavior when the product is configured for self-registration (a non-default feature). The supplier also notes that there is no configuration migration scenario that would result in the self…
I Alto vulnerabilidad
30/06/2026
[CVE-2025-36359] IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expirati…
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.