Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 5 horas
Buscando: "X" — 10217 resultados ✕ Limpiar búsqueda
13,735
Total alertas
3106
Críticas
10357
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
18/08/2026
[CVE-2026-74906] SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-…
SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the visibility list instead of the disabled list. Anonymous visitors can discover and read content from documents explicitly marked as forbidden from publishing by accessing search, backlink, asset content, saved criteria, recent documents, graph, and tag e…
M Alto vulnerabilidad
18/08/2026
[CVE-2026-15585] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. AKINSOFT Wolvox9 ERP / KontrolPanel.exe allows Path Traversal. This issue affects AKINSOFT Wolvox9 ERP / KontrolPanel.exe: from s26.02.17 before 26.02.22.
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-75627] Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unaut…
Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication filters by prefixing requests with arbitrary path segments. Attackers can access administrative controllers to read user listings, create manager accounts, and register managed systems, gaining control over SSH access to the managed fleet.
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-75626] SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including s…
SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject malicious HTML elements with event handlers into correlation results that execute scripts in the operator's browser when the correlations view is opened, potentially stealing API keys.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-15371] Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the…
Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked in the GUI.The code does not limit the schemes allowed in this URL , allowing an attacker to specify a JavaScript scheme exposing the user to XSS.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75091] The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnera…
The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-15748] The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up …
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler th…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
? Medio alerta
18/08/2026
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA emite alerta de seguridad: CISA Adds Four Known Exploited Vulnerabilities to Catalog. CVEs relacionados: CVE-2026-33824, CVE-2026-55040, CVE-2026-59310, CVE-2026-65400.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-11801] The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all…
The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve internal site configuration data exposed by the classifieds-types REST endpoint, including register…
M Crítico vulnerabilidad
18/08/2026
[CVE-2026-75094] A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /…
A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75089] A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue…
A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/check_availability.php. This manipulation of the argument email causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75079] A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnera…
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_subject2.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.
M Alto vulnerabilidad
18/08/2026
[CVE-2026-75080] A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. …
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the file /edit_subject1.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-9816] Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to validate BoardMe…
Mattermost versions 11.7.x
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-71424] Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers …
Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx's GET /api/mcp/servers and GET /api/mcp/servers/persona/{persona_id} endpoints expose another user's OAuth Authorization header because OnyxTokenStorage.set_tokens and OnyxTokenStorage.set_client_info in backend/onyx/server/features/mcp/api.py copy per-user tokens into a shared admin MCPConnectionConfig row and _db_mcp_se…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
17/08/2026
[CVE-2026-75110] MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is en…
MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless INTERNAL_SERVICE_SECRET environment variable is unset, the is_internal_request() check in src/memos/api/middleware/auth.py fails open: os.getenv("INTERNAL_SERVICE_SECRET") returns None and a request omitting the X-Internal-Service header al…
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75103] Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allow…
Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's password. Attackers can enumerate user accounts through the user listing endpoint and change administrator credentials to achieve full account takeover and arbitrary code execution.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-75105] phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary …
phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/index.php and app/temp_share/address.php, when the share type is 'subnets', the subnetId parameter is used directly as a database primary key to fetch an address without confirming the address belongs to the authorized subnet. An unauthenticated party ho…
C Medio vulnerabilidad
17/08/2026
[CVE-2026-75104] Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing atta…
Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model directory. Attackers can supply malicious index files with parent-directory references or absolute paths that are joined without validation, enabling file disclosure and filesystem reconnaissance.
M Alto vulnerabilidad
17/08/2026
[CVE-2026-71518] Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download rou…
Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to access restricted files by submitting path-equivalent URL variants. Attackers can substitute normalized path forms such as dot-slash prefixes, double slashes, or percent-encoded sequences to pass role-based restriction checks while the filesystem resolves …