Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 118 resultados ✕ Limpiar búsqueda
13,509
Total alertas
3066
Críticas
10171
Altas
8
Ransomware
1797
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-78213] Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authen…
Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent malicious content into specific pages, causing arbitrary JavaScript code to execute when other users click the crafted content.
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-78180] A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the fun…
A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was …
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-78181] A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#se…
A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem ea…
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-19200] The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other is…
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.  The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.
M Alto vulnerabilidad Nuevo
Hace 12 horas
[CVE-2026-78178] A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/j…
A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated remotely. The reported GitHub issue was closed with the label "not planned".
M Alto vulnerabilidad Nuevo
Hace 12 horas
[CVE-2026-78171] A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vuln…
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/processlogin.php. The manipulation of the argument User leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
M Crítico vulnerabilidad Nuevo
Hace 13 horas
[CVE-2026-78167] A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function h…
A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session Validation Handler. This manipulation causes improper authentication. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad Nuevo
Hace 13 horas
[CVE-2026-78168] A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the fun…
A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component Session Validation Handler. Such manipulation leads to improper authentication. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in a…
M Crítico vulnerabilidad Nuevo
Hace 13 horas
[CVE-2026-78169] A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the functio…
A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempSend of the component HTTP Request Handler. Performing a manipulation of the argument Profile results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
M Alto vulnerabilidad Nuevo
Hace 13 horas
[CVE-2026-78170] A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the…
A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing a manipulation of the argument ssid can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used.
M Crítico vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-78207] exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper t…
exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or prototype keys when merging note objects. Attackers can assign parsed JSON with a malicious __proto__ property to cell notes, modifying Object.prototype and affecting all plain objects created in the process.
M Alto vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-78208] exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() fun…
exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attackers can supply arbitrary file paths to read any file accessible to the Node.js process and embed it in the generated workbook.
M Alto vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-78209] exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs i…
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers who can influence exported cell values can inject formulas that execute when the CSV file is opened in a spreadsheet application, potentially exfiltrating data or performing other malicious actions.
M Alto vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-78161] A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor o…
A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP CBOR Recording. The manipulation results in out-of-bounds write. The attack can be launched remotely. The exploit has been made public and could be used. The patch is identified as 1d44554a1bb262db63ff4e240152a9deecd99054. It is best practice to apply…
M Alto vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-78203] Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, …
Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templates from other clients to their own reports. Attackers can exploit sequential template primary keys to enumerate and attach foreign templates, then generate reports to disclose template contents including letterhead, boilerplate, and methodology text.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-78206] exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory witho…
exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compression ratio. Attackers can upload highly compressed workbooks that expand to gigabytes in memory, exhausting available resources and causing denial of service.
M Alto vulnerabilidad Nuevo
Hace 14 horas
[CVE-2026-78157] A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file …
A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Request Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The patch is named c18dc6938bf63cc7374315d3dca303d92066e746. To fix this issue, it is recommended to deploy a patch.
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-78154] A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function…
A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/api/routes/v1/user_invitation_code.py of the component Public Invitation-Code Redemption Endpoint. The manipulation of the argument code leads to missing authentication. Remote exploitation of the attack is possible. The project was informed of the pro…