Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Multiple Vendors" — 16853 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
23/06/2026
[CVE-2025-71341] picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle f…
picklescan before 0.0.29 fails to detect the profile.Profile.runctx function when analyzing pickle files, allowing attackers to embed undetected malicious code. Remote attackers can craft malicious pickle files using profile.Profile.runctx in the reduce method to achieve remote code execution when the pickle file is loaded.
M Alto vulnerabilidad
23/06/2026
[CVE-2025-71365] picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.…
picklescan before 0.0.33 fails to detect malicious pickle files that invoke numpy.f2py.crackfortran.myeval function through the reduce method. Attackers can craft malicious pickle files embedding arbitrary code that evades picklescan detection and executes remote code when loaded.
M Alto vulnerabilidad
23/06/2026
[CVE-2025-71370] picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper func…
picklescan before 0.0.28 fails to detect malicious torch.jit.unsupported_tensor_ops.execWrapper function calls embedded in pickle files. Attackers can craft malicious pickle files that bypass picklescan detection and execute arbitrary code when loaded via pickle.load().
M Alto vulnerabilidad
23/06/2026
[CVE-2025-71376] picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoCompl…
picklescan before 0.0.29 fails to detect malicious pickle files using idlelib.autocomplete.AutoComplete.fetch_completions in reduce methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when loaded by victims.
M Crítico vulnerabilidad
23/06/2026
[CVE-2026-11374] In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the S…
In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session could be predicted by an unauthenticated user, leading to account takeover.
M Crítico vulnerabilidad
23/06/2026
[CVE-2026-9733] Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state…
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, the module defaults to using a SHA-1 hash of predictable and low-entropy sources, including the epoch time (which is leaked via the HTTP Date header) and a call to Perl's built-in rand function. A predictable state allows an atta…
M Alto vulnerabilidad
23/06/2026
[CVE-2026-10521] An high privileged remote attacker can access a hidden configuration method, that should not be acce…
An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, to modify critical program parameters. This can result in a total loss of confidentiality, integrity and availability.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/06/2026
[CVE-2026-8172] The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input …
The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it into the contact form output on validation errors, leading to a Reflected Cross-Site Scripting vulnerability that unauthenticated attackers can exploit against site visitors via a crafted link or cross-site form submission.
M Alto vulnerabilidad
23/06/2026
[CVE-2026-8379] The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce c…
The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file download handler, allowing unauthenticated attackers to download files uploaded by any user through the Frontend File Manager Plugin WordPress plugin through 23.6 by iterating identifiers.
M Alto vulnerabilidad
23/06/2026
[CVE-2026-8163] The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some param…
The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using them in SQL statements, leading to a SQL Injection vulnerability exploitable by authenticated users with Subscriber-level access and above.
M Crítico vulnerabilidad
23/06/2026
[CVE-2026-12866] All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. A…
All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code w…
M Alto vulnerabilidad
22/06/2026
[CVE-2026-56324] Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that a…
Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to circumvent rate limiting by rotating the user-controlled device_id parameter. Attackers can send multiple requests per second by changing device_id values to flood the channel_devices table and cause database exhaustion.
M Alto vulnerabilidad
22/06/2026
[CVE-2026-56280] Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that a…
Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API key holders to cancel running native builds. The endpoint registers an abort listener on the SSE stream that unconditionally invokes cancelBuildOnDisconnect() using the privileged server-side BUILDER_API_KEY when clients disconnect, bypassing the app.build_native permission check…
M Alto vulnerabilidad
22/06/2026
[CVE-2026-56314] Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates re…
Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing deleted bundles to remain selectable. Attackers can continue deploying deleted bundles to devices by exploiting the missing app_versions.deleted filter in channel version joins.
M Alto vulnerabilidad
22/06/2026
[CVE-2026-56323] Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_…
Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attackers to enumerate non-public channel names and determine app existence and subscription status. Remote attackers can send GET requests with arbitrary app_id parameters to disclose internal rollout channels, enumerate valid applications across tenants, a…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/06/2026
[CVE-2026-55409] Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 un…
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered its raw state without sanitizing HTML. Where the data stored in this field's state isn't sanitized already when the form state was filled, an attacker could plant malicious HTML or JavaScript and achieve XSS that executes for users who view the form. …
M Alto vulnerabilidad
22/06/2026
[CVE-2026-48505] Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 un…
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentication allows the same recovery code to be reused via concurrent submission. This issue does not affect email-based MFA. It also only applies when recovery codes are enabled. If an attacker gains access…
M Alto vulnerabilidad
22/06/2026
[CVE-2025-71339] Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle _…
Picklescan before 0.0.33 fails to detect the numpy.f2py.crackfortran._eval_length gadget in pickle __reduce__ methods, allowing arbitrary code execution. Attackers can craft malicious pickle files that execute arbitrary Python code when loaded by victims who trust Picklescan's safety validation.
M Alto vulnerabilidad
22/06/2026
[CVE-2025-71344] picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_p…
picklescan before 0.0.30 (affected versions 0.0.26 and earlier) fails to detect the ensurepip._run_pip built-in function when scanning pickle files, allowing attackers to execute arbitrary code. Malicious pickle files embedding ensurepip._run_pip calls in __reduce__ methods bypass picklescan detection and achieve remote code execution upon pickle.load() invocation.
M Alto vulnerabilidad
22/06/2026
[CVE-2025-71358] picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.Au…
picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.autocomplete.AutoComplete.get_entity function in reduce methods. Attackers can embed undetected code in pickle files that executes arbitrary commands when loaded by victims using pickle.load().