Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Nsa" — 104 resultados ✕ Limpiar búsqueda
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1003
Esta semana
RSS
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-107703] @enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that…
@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or a single quote into the ImageMagick command run by child_process.exec() to execute operating system commands with Node.js process privileges.
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-107699] ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execut…
ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' to file names passed to child_process.exec() in ppt2png.js, running commands with Node.js process privileges.
M Crítico vulnerabilidad
01/10/2026
[CVE-2026-55083] DHIS2 is a flexible information system for data capture, management, validation, analytics and visua…
DHIS2 is a flexible information system for data capture, management, validation, analytics and visualization. From versions 2.42.0 to before 2.42.5.1, and from versions 2.43.0 to before 2.43.0.1, DHIS2 is vulnerable to remote code execution (RCE) via unsafe Java deserialization. This issue has been patched in versions 2.42.5.1, 2.43.0.1, and 2.44.
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-97196] Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP al…
Improper Validation of Unsafe Equivalence in Input vulnerability in Liquid Web / StellarWP GiveWP allows Authentication Bypass. This issue affects GiveWP: from n/a through 4.16.9.
M Crítico vulnerabilidad
29/09/2026
[CVE-2026-68068] The "screenID" parameter in the electronic transaction queue viewer feature within the manual transa…
The "screenID" parameter in the electronic transaction queue viewer feature within the manual transactions section is susceptible to a time-based blind SQL injection vulnerability.
M Crítico vulnerabilidad
28/09/2026
Vulnerabilidad crítica en FAST FAC1900R 20190827_2.0.2 permite desbordamiento de búfer remoto
Se identificó un desbordamiento de búfer basado en pila (stack-based buffer overflow) en la función copy_msg_element del servicio devdiscover de FAST FAC1900R versión 20190827_2.0.2. La vulnerabilidad permite ejecución remota de código sin autenticación (CVSS 10.0) y cuenta con exploits públicamente disponibles. El fabricante no ha respondido a reportes de divulgación responsable, elevando el riesgo inmediato para infraestructuras que dependan de este dispositivo en centros de datos y operaciones críticas de LATAM.
M Crítico vulnerabilidad
25/09/2026
Vulnerabilidad crítica en plugin Bookly para WordPress permite acceso no autorizado a datos de reservas
El plugin Bookly para WordPress (versiones hasta 28.2) contiene una vulnerabilidad de Referencia Directa a Objetos (IDOR) en acciones AJAX que permite a atacantes acceder y manipular datos de reservas, sesiones y órdenes sin autenticación. Afecta directamente a negocios de servicios en LATAM que usan este plugin para gestionar citas y pagos online, exponiendo información de clientes y transacciones.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
23/09/2026
[CVE-2026-18872] IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scri…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator browsers, enabling session hijacking and unauthorized operator-level payment actio…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-18162] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execut…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper neutralization of user-controlled input within the new Function constructor.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-18163] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execut…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due to improper deserialization of untrusted data.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-18169] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated atta…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensitive information due to improper validation of symbolic links.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-17635] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perfor…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actions due to improper configuration of HTTP method-based security constraints.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-17645] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated atta…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevated privileges due to improper privilege management.
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-80151] Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmwa…
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set nfs download command that passes unsanitized user input to a system() call. Attackers wit…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-80152] Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmwa…
Lantronix SLC8000 before firmware v9.7.0.3, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set script schedule command that passes unsanitized user input to a system() call. Attackers …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-80145] Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmwa…
Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers with the services permission to execute arbitrary shell commands as root by exploiting the set cifs password command that passes unsanitized user input to a system() call. Attackers wi…
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-80144] Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmwa…
Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom write command that passes unsanitized user input to a system() call. Attackers can authenticate as …
M Crítico vulnerabilidad
22/09/2026
[CVE-2026-80143] Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmwa…
Lantronix SLC8000 before firmware v9.7.0.2, EMG8500/EMG7500 before firmware v9.7.0.1, and all firmware versions of SLB882/SLCx-03/SLCx-02 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary shell commands as root by exploiting an undocumented mfc eeprom read command that passes unsanitized user input to a system() call. Attackers can authenticate as a…
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-94084] Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by r…
Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-93762] Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An app…
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.