Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Budibase" — 7 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Crítico vulnerabilidad
28/08/2026
Vulnerabilidad crítica de ejecución remota de código en Budibase anterior a v3.41.3
Budibase versiones anteriores a 3.41.3 contienen una vulnerabilidad de ejecución remota de código (RCE) en el manejo de plugins que permite a usuarios administradores autenticados ejecutar código arbitrario mediante la carga de un tarball malicioso. El servidor ejecuta eval() en archivos JavaScript de plugins sin aislamiento en el proceso Node.js principal, habilitando la exfiltración de variables de entorno y credenciales con privilegios root. Empresas en LATAM que utilicen Budibase en entornos de producción o desarrollo enfrentan riesgo crítico de compromiso total del servidor.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-72850] Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to…
Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are preserved during export. Attackers can craft filenames containing .. segments that escape the temporary directory during workspace export, writing arbitrary content to any path writable by the Budibase process.
M Crítico vulnerabilidad
13/08/2026
[CVE-2026-72851] Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered …
Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers can POST attacker-controlled JSON to the webhook trigger endpoint to inject SQL payloads that execute with builder-configured database credentials, enabling data exfiltration, modification, and persistence in connected datasources like Snowflake.
M Crítico vulnerabilidad
12/08/2026
[CVE-2026-73300] Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Bu…
Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: true, enabling execution of multiple SQL statements in a single query. Attackers can inject malicious SQL commands through user input fields, leading to complete database compromise. This vulnerability is fixed in 3.40.0.
B Crítico vulnerabilidad
26/06/2026
[CVE-2026-54350] Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any p…
Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection and, where the builder has published a PUBLIC write query, modifies every document of that collection with one HTTP request. enrichContext at packages/server…
B Crítico vulnerabilidad
26/06/2026
[CVE-2026-54352] Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packag…
Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with extract-zip@2.0.1 into a temp directory, then for each entry listed in icons.json validates the icon path, opens it, and streams the bytes into MinIO. The resulting object is served back via GET /api/assets/{appI…
B Crítico vulnerabilidad
26/06/2026
[CVE-2026-50137] Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or ca…
Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) can call this endpoint with no auth and obtain a 15-minute pre-signed PUT URL minted on the victim's IAM identity. The endpoint also returns the publicUrl so the attacker knows exactly where their PUT lands. Because bucket …