Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 11 min
Buscando: "Ni" — 7263 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-95102] WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate chargin…
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-97212] The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows mu…
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers. This vulnerability may allow unauthorized users to authenticate as other users or enable a malicious actor to cause a denial-of-service condition by overwhelming the backend…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-97363] The WebSocket Application Programming Interface lacks restrictions on the number of authentication r…
The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow an attacker to conduct denial-of-service attacks or brute-force attacks to gain unauthorized access.
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-82042] UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers…
UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtai…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-82039] UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBu…
UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arb…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-104019] OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution …
OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution 2.x before 2.14.12, 3.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, and 4.4.x before 4.4.3, as used by Amazon SageMaker Unified Studio, might allow an authenticated remote user with project contributor permissions to execute arbitrary commands in …
M Crítico vulnerabilidad
02/10/2026
[CVE-2023-54405] H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an un…
H3C CVM, the Cloud Virtualization Management component of the H3C CAS cloud platform, contains an unauthenticated arbitrary file upload vulnerability in the /cas/fileUpload/upload endpoint that allows remote attackers to write arbitrary files by manipulating the caller-supplied token parameter without restricting path traversal or file type. Attackers can exploit the path traversal in the token pa…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/10/2026
[CVE-2026-67989] crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular…
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
M Alto vulnerabilidad
02/10/2026
[CVE-2026-51907] In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vul…
In TaskingAI v0.3.0 in the QR Code Generator plugin save_base64_image function, a path traversal vulnerability allows attackers to write image files to arbitrary locations on the server filesystem by manipulating the project_id parameter.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-51916] TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_use…
TransformerOptimus SuperAGI v0.0.14 contains an incorrect access control vulnerability in delete_user_knowledge in superagi/controllers/knowledges.py. In affected source snapshots, POST /knowledges/delete/{knowledge_id} deletes the selected knowledge object without requiring authentication in the route and without verifying organization ownership of the supplied knowledge_id.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-101104] The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows auth…
The Meari IoT Cloud Platform OpenAPI Service is vulnerable to an authorization flaw that allows authenticated users to manipulate the configurations of devices they do not own. This vulnerability enables attackers to perform unauthorized actions, such as altering device settings or triggering unintended behaviors, without verifying ownership or permissions.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104637] A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473…
A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of the argument img can lead to unrestricted upload. The attack may be launched remo…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-93875] The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friend…
The JetAppointment plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'friendlyTime' parameter in all versions up to, and including, 2.5.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload …
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-19652] The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, an…
The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowe…
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-104610] A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impact…
A security vulnerability has been detected in Tenda HG7, HG9 and HG10 300001138_en_xpon. This impacts the function boaGetVar of the file /boaform/formLoopBack of the component Boa Web Server. Such manipulation of the argument Ethtype leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad
02/10/2026
[CVE-2026-104611] A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /…
A vulnerability was detected in Tenda AC9 15.03.02.13. Affected is an unknown function of the file /goform/fast_setting_internet_set of the component POST Request Handler. Performing a manipulation of the argument netWanType results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad alta de carga de archivos sin restricción en YesWiki anterior a 4.6.7
YesWiki versiones anteriores a 4.6.7 presentan una vulnerabilidad de carga de archivos no restringida que permite a administradores autenticados ejecutar código PHP malicioso en el servidor mediante la importación de CSV en Bazar. Un atacante puede importar un archivo CSV con referencias a URLs PHP remotas que se guardan sin validación de extensión y se ejecutan como código del lado del servidor, comprometiendo la integridad del sitio web y los datos alojados.
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad alta de autorización en YesWiki anterior a 4.6.7 expone archivos confidenciales
YesWiki versiones anteriores a 4.6.7 contienen una falla de autorización en el manejador de descargas que permite a atacantes no autenticados eludir controles de acceso (ACLs) y descargar archivos adjuntos de páginas restringidas. Esta vulnerabilidad afecta principalmente a organizaciones en LATAM que utilizan wikis internas para gestión documental, exponiendo información sensible como reportes, datos financieros y documentación confidencial sin requerir credenciales válidas.
M Alto vulnerabilidad
02/10/2026
Inyección SQL alta en onetwothreeneth HospitalManagementSystem permite acceso remoto no autorizado
Se identificó una vulnerabilidad de inyección SQL en onetwothreeneth HospitalManagementSystem (hasta versión 9ef91ed6007314b6473110ed699dff76d158f61d) en el archivo edit_accounts.php. Un atacante remoto puede manipular los parámetros user_id, patient_id, physician_id, discounts_id o services_id para ejecutar comandos SQL arbitrarios, comprometiendo bases de datos de pacientes, registros clínicos y datos sensibles. La explotación es posible sin autenticación previa y el exploit ya está disponible públicamente.
M Alto vulnerabilidad
02/10/2026
Vulnerabilidad alta de bypass de autorización en YesWiki anterior a 4.6.7
YesWiki versiones anteriores a 4.6.7 contiene un defecto de autorización en ApiService::isAuthorized() que permite a atacantes no autenticados invocar rutas API administrativas cuando el modo API público está habilitado. Los atacantes pueden modificar configuraciones, acceder y eliminar archivos de respaldo mediante endpoints como api/ci/update_config y api/archives, comprometiendo la integridad y disponibilidad de wikis empresariales en LATAM.