Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Quest" — 2117 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad
01/10/2026
[CVE-2026-73636] Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP…
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to versi…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-63292] Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server thro…
Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users ar…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12540] A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fet…
A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ",…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12405] A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in th…
A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job T…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-12423] A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable …
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the …
M Alto vulnerabilidad
01/10/2026
[CVE-2026-79896] Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parse…
Fortra BoKS Manager contains an out-of-bounds read vulnerability in the custom TLS ClientHello parser used by boks_portmux. A remote unauthenticated attacker can submit a malformed ClientHello and terminate boks_portmux. Although the daemon is normally restarted automatically, repeated requests can sustain the service interruption.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-102504] Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_…
Imager versions before 1.037 for Perl exit the process reading a raw image with an out-of-range raw_datachannels value in i_readraw_wiol. Nothing range-checks raw_datachannels. The line buffer is sized as the image width times the channel count with no overflow check, so a negative or very large count requests an excessive allocation. When it fails, Imager's allocator calls exit(3). Passing an u…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103067] Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful…
Cross-Site Request Forgery (CSRF) vulnerability in Memberful Memberful - Membership Plugin memberful-wp allows Cross Site Request Forgery.This issue affects Memberful - Membership Plugin: from n/a through 1.81.0.
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad XXE alta en Apache Camel Quarkus permite lectura de archivos locales
Apache Camel Quarkus versiones 3.2.0-3.33.2 y 3.34.0-3.39.x contienen una vulnerabilidad de inyección XXE (XML External Entity) en su extensión de soporte XSLT que permite a atacantes leer archivos locales o realizar solicitudes a sistemas internos. Empresas en México y LATAM que usan Camel Quarkus en pipelines de integración de datos quedan expuestas a filtración de credenciales y configuraciones sensibles.
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad SSRF alta en Budibase 3.41.0 afecta generación de tablas con IA
Budibase versiones hasta 3.41.0 contiene una vulnerabilidad de Server-Side Request Forgery (SSRF) en la función de generación de tablas con IA. Usuarios autenticados pueden explotar la función uploadUrl en fileUtils.ts para enviar solicitudes a URLs internas, obteniendo acceso a recursos sensibles del servidor. El impacto afecta especialmente a empresas en LATAM que usan Budibase en entornos productivos sin aislamiento de red adecuado.
M Alto vulnerabilidad
01/10/2026
Vulnerabilidad de omisión de autorización en Obot 0.21.1 a 0.24.1 (CVE-2026-103758)
Obot versiones 0.21.1 hasta 0.24.1 contienen una vulnerabilidad de omisión de controles de autorización que permite a usuarios autenticados con rol básico acceder a servidores MCP mediante la ruta /mcp-connect-composite/, no incluida en la lista de denegación. Usuarios con IDs MCP compuestos pueden enviar solicitudes proxy a través de mcpGateway.Proxy para invocar herramientas en servidores restringidos, evadiendo reglas de control de acceso.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103252] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an aut…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves project-scoped variables without validating caller access. Attackers can specify an arbitrary project ID in the request body to interpolate sensitive variables into credential test requests sent to attacker-controlled host…
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103255] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request paths without validation. Attackers can exploit workflows binding tableId to untrusted input to traverse to Auth and Storage APIs using the administrative serviceRole key, bypassing Row Level Security …
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-103248] n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filt…
n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field values. Attackers can inject filter expressions from untrusted input to read all table rows, update all records, or delete entire tables in a single request.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-103082] Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor la…
Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.6.2.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/10/2026
[CVE-2026-14995] The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Pa…
The Autoptimize plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REQUEST_URI Path in all versions up to, and including, 3.1.15.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the Critical …
M Alto vulnerabilidad
01/10/2026
[CVE-2026-96255] The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log …
The Payments for Hubtel WordPress plugin before 1.0.2 does not prevent public access to a debug log in which it records payment requests, including the store's payment gateway API credentials in plain text, allowing unauthenticated attackers to obtain those credentials.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-92412] The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supp…
The Five Star Restaurant Reviews WordPress plugin before 2.3.14 does not properly escape a user-supplied value before outputting it into an HTML tag, allowing unauthenticated attackers to inject arbitrary web script that runs in the browser of anyone tricked into submitting a crafted request, including a logged-in administrator.
M Alto vulnerabilidad
01/10/2026
[CVE-2026-19253] The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a …
The Cache Enabler WordPress plugin before 1.8.17 does not validate a URL before using it to build a filesystem path in its cache purge routine, and does not confine the resulting deletion to the cache directory, allowing unauthenticated users to delete arbitrary files and directories on sites where another installed Cache Enabler WordPress plugin before 1.8.17 or passes a request-derived URL to i…
M Alto vulnerabilidad
01/10/2026
[CVE-2026-101147] The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Pre…
The Featured Image from URL (FIFU) WordPress plugin before 6.0.8, Featured Image from URL (FIFU) Premium WordPress plugin before 8.2.8 do not correctly enforce the REST API nonce, disabling the check for the whole request when a crafted URL is used, which could allow attackers to make a logged-in administrator perform any REST API action, such as creating a new administrator account, via a CSRF at…