Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2124 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad de omisión de autorización en @better-auth/stripe afecta gestión de suscripciones
Las versiones 1.4.11 a 1.6.20 y 1.7.0-beta.0 a 1.7.0-beta.9 de @better-auth/stripe contienen una falla de validación que permite eludir controles de autorización en acciones de suscripción organizacional. Un atacante puede manipular parámetros de ID de organización para acceder o modificar suscripciones de terceros. Afecta principalmente a plataformas SaaS y aplicaciones con modelos multi-tenancy que utilicen esta librería para autenticación con Stripe.
M Crítico vulnerabilidad
01/08/2026
Vulnerabilidad crítica de inyección de comandos en flujos de trabajo de Wazuh (CVE-2026-67308)
Los flujos de trabajo de Wazuh anteriores a la versión 44bf114 contienen una vulnerabilidad de inyección de shell en GitHub Actions que permite a atacantes ejecutar comandos arbitrarios mediante pull requests manipulados con archivos VERSION.json especialmente crafteados. La explotación facilita la inyección de metacaracteres de shell en variables de entorno interpoladas directamente en pasos de ejecución, permitiendo robo de secretos como GITHUB_TOKEN y acceso no autorizado a sistemas CI/CD en organizaciones de LATAM que usen este software para orquestación de seguridad.
M Alto vulnerabilidad
01/08/2026
Vulnerabilidad alta de desreferencia nula en FreeRDP 3.28.x y anteriores
FreeRDP versiones anteriores a 3.29.0 contiene una vulnerabilidad de desreferencia de puntero nulo en el manejo de solicitudes de control de dispositivos smartcard. Un atacante puede enviar peticiones IRP malformadas con datos de estado de lector truncados para causar el bloqueo del proceso. Esta vulnerabilidad afecta servidores de acceso remoto y clientes RDP en infraestructuras de LATAM que dependen de autenticación por tarjeta inteligente.
M Alto vulnerabilidad
01/08/2026
[CVE-2026-67288] FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request d…
FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupName in SCARD_IOCTL_READCACHEA and SCARD_IOCTL_WRITECACHEA operations. When smartcard emulation is enabled, attackers can send crafted smartcard cache requests with NULL lookup-name pointers to trigger strlen() on a null pointer, causing client process…
M Crítico vulnerabilidad
01/08/2026
[CVE-2026-67289] FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in…
FreeRDP before 3.29.0 (affected versions
M Alto vulnerabilidad
01/08/2026
[CVE-2026-15988] The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to …
The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.6.5 This is due to missing or incorrect nonce validation on the reauth_for_authorize function. This makes it possible for unauthenticated attackers to create new administrator accounts with attacker-supplied credentials via a CSRF-ba…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-65981] Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using…
Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, a server using --mobility authenticates a resumed REFRESH request with the resuming user's credentials but does not verify that identity against the original allocation owner, allowing an authenticated attacker who obtains a victim MOBILITY-TICKET to receive and inject relayed traffic and consume the victim's quo…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
31/07/2026
[CVE-2026-18394] Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow re…
Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to version 0.8.2.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-53504] Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filt…
Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the convolution filter regular expression performs exponential backtracking on crafted repeated numeric input, allowing a URL request to exhaust processing time. This issue is fixed in 7.8.0.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-15722] A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_fro…
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by sending a crafted StartNSDS50ReplicationRequest extended operation containing a repl…
M Alto vulnerabilidad
31/07/2026
[CVE-2026-14930] The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or owners…
The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allowing unauthenticated users to upload files (limited to the JS Help Desk WordPress plugin before 3.1.4's inert allowed extensions) and attach them to arbitrary users' support tickets.
M Crítico vulnerabilidad
31/07/2026
[CVE-2026-14919] The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting tes…
The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check that is satisfiable with client-supplied request headers, allowing unauthenticated attackers to redirect outgoing emails, including the WordPress administrator password-reset email, to an address they control and take over the administrator account.
M Alto vulnerabilidad
31/07/2026
[CVE-2026-12721] The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from t…
The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, allowing unauthenticated attackers to perform SQL injection attacks.
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-66418] OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthent…
OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML and script payloads by submitting a crafted username in a failed login POST request, which is recorded verbatim in the audit log. When an administrator opens the notification panel, the unescaped log entry is rendered via innerHTML with a permissive C…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-66415] Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that al…
Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal resources by passing unsanitized user-supplied filenames to file_get_contents() in the Blueprints::import() method without path validation. Attackers can submit crafted filenames containing URL wrappers or path traversal sequences through the JSON-RPC AP…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/07/2026
[CVE-2026-66416] Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attac…
Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf of authenticated users by excluding the Laravel VerifyCsrfToken middleware from the global middleware stack in app/Http/Kernel.php. Attackers can craft malicious pages delivered via phishing emails or malicious websites to trigger unauthorized POST, P…
M Alto vulnerabilidad
30/07/2026
[CVE-2026-18140] Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62…
Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy-rs code generator invokes from every generated struct deserializer, might allow remote unauthenticated users to cause a denial of service (process abort via stack exhaustion) via a single small HTTP request containing deeply nested JSON to a smithy-rs generated server. To rem…
M Crítico vulnerabilidad
30/07/2026
[CVE-2026-15971] SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a s…
SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-12942] IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the s…
IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
M Alto vulnerabilidad
30/07/2026
[CVE-2026-9322] IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.…
IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted HTTP request.