Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3488 resultados ✕ Limpiar búsqueda
22,298
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1168
Esta semana
RSS
M Alto vulnerabilidad
20/09/2026
[CVE-2026-85017] The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability ch…
The Unlimited Elements For Elementor WordPress plugin before 2.0.20 does not perform a capability check on an AJAX action and deserializes attacker-controlled stored data through it, which makes it possible for authenticated attackers with subscriber-level access to inject arbitrary PHP objects. A partial fix in the 2.0.18 to 2.0.19 releases raised the privilege required to reach the vulnerable ac…
M Alto vulnerabilidad
20/09/2026
[CVE-2026-86553] SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its…
SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Using the acquired SmartLife application authentication parameters, an attacker can directly call the backend interface /account/verify.serv to obtain the real account ID corresponding to a registered email address. By spoofing the application authentication information together wi…
M Crítico vulnerabilidad
20/09/2026
[CVE-2026-94083] Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code…
Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state is executed even though the actual state is HTTP1 (when there is a DoH2 request with an HTTP1 to HTTP2 upgrade). This requires app-layer.protocols.doh2 to be enabled, which is the default in 8.x versions.
M Crítico vulnerabilidad
19/09/2026
[CVE-2026-78030] DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm att…
DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename and does not consult @INC, so the attribute chooses the file that Perl loads and runs. The MLDBM::…
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad XLS almacenado en plugin Quill Forms para WordPress (CVE-2026-15664)
El plugin Quill Forms versiones hasta 5.7.1 es vulnerable a inyección de scripts maliciosos (XLS) a través del campo 'Other' en formularios de opción múltiple, afectando sitios WordPress sin autenticación requerida. Atacantes pueden ejecutar código JavaScript arbitrario en navegadores de usuarios visitantes, comprometiendo datos sensibles en formularios de encuestas y cuestionarios. Impacta principalmente a sitios de comercio electrónico, educación y servicios financieros en LATAM que utilizan este plugin para recolectar información de clientes.
M Crítico vulnerabilidad
19/09/2026
Vulnerabilidad crítica en plugin Forminator para WordPress permite ejecución arbitraria de shortcodes
El plugin Forminator Forms para WordPress (versiones hasta 1.57.2) es vulnerable a ejecución arbitraria de shortcodes debido a validación insuficiente en la función do_shortcode. Atacantes no autenticados pueden ejecutar código malicioso en sitios web afectados, comprometiendo la integridad de formularios de contacto y pago. Esta vulnerabilidad impacta directamente a empresas en LATAM que utilizan este plugin en formularios críticos de recolección de datos y procesamiento de pagos.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad XSS almacenado alta en SiYuan 3.8.4 permite ejecución de comandos del sistema
SiYuan versiones hasta 3.8.4 no sanitiza nombres de notebooks en el diálogo del selector de notas diarias, permitiendo inyección de HTML y JavaScript. Un atacante puede crear notebooks con payloads maliciosos que se ejecutan con acceso a Node.js en el renderer de Electron, comprometiendo la integridad del sistema operativo del usuario. El riesgo es alta (CVSS 8.8) para equipos que usan SiYuan como herramienta de documentación corporativa o gestión de conocimiento en entornos LATAM.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84083] IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap…
IBM Guardium Data Protection 12.2 is vulnerable to local privilege escalation via the SUID-root nmap_wrapper binary on the Collector appliance. A local attacker with low-privileged access to the Collector can exploit insufficient argument validation in the SUID binary to execute arbitrary commands as root, resulting in full compromise of the Collector appliance.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-81656] IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Bu…
IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-58264] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth channel. An out-of-range channel can therefore cause an out-of-bounds heap write, leading to denial of service or possible …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61714] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and writes invoke undefined behavior and may compromise confidentiality, integrity, o…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61721] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or fluid_sample_sanitize_loop(). A crafted DLS file can place sample loop points beyond the sample buffer, causing out-of-bounds reads during audio rendering…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93759] Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instea…
Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the database as a server-side JavaScript expression. An unauthenticated party able to influence the value an application supplies as a query argument may cause code of their choosing to be evaluated by the database engine. This may result in unintended disclosure of stored field value…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93760] Mongoid does not restrict which query operators may come from caller-supplied filter data when an ap…
Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that data to its query-building methods. In an application that forwards externally supplied filter parameters in this way, a party with no credentials may influence how the database evaluates the query. This may result in unintended disclosure of stored field values and in reduced d…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-32641] Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.…
Parseable is a log analytics platform built for high-volume data ingestion and analysis. Prior to 3.0.0, src/handlers/http/middleware.rs uses unwrap() while parsing the x-amz-firehose-common-attributes header before authentication. A remote unauthenticated attacker can supply non-UTF-8 header data, malformed JSON, or invalid derived header values that trigger a Rust panic and interrupt request han…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-88259] CareCam CM2507 IP cameras do not require authentication for access to its network video streaming se…
CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenticated attacker with network access to the affected device could retrieve live camera video.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84446] libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence t…
libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_t counters used by Track_Visual::decode_next_image_sample() and Track::get_next_sample_raw_data(). The resulting comparison can never reach the oversized output co…
M Crítico vulnerabilidad
18/09/2026
[CVE-2026-75031] In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was fou…
In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin feature. In default installations arbitrary Perl code can be injected and executed server-side by unauthenticated users. The Perl code normally runs within a Safe container which limits the scope of what it can do, unless the non-default AllowGlobal directive is …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-7006] Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contain…
Sublime Text for Windows through Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3) contains a local privilege escalation vulnerability that allows unprivileged local attackers to execute arbitrary code with elevated privileges by abusing the update staging mechanism. Attackers can place a malicious DLL in the user-writable staging directory under %LOCALAPPDATA%, mark it read-only to bypa…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-67549] OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format…
OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.1.16.0, A crafted 1-bit contiguous cmyk tiff is exposed through a native uint1 imagespec, so callers allocate a bit-packed buffer. tiffinput::read_native_scanline_locked() nevertheless invokes tiffinput::bit_convert() with 8-bit output and writes one expanded…