Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3485 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-107908] A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/bolt_api.c) in FalkorDB b…
A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly execute arbitrary code by sending a Bolt RESET message with an attacker-chosen chunk size to the Bolt port. The handler checks the size only with ASSERT(), which is compiled out in release builds, then co…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-17189] IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 …
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107318] @fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. …
@fastify/reply-from is a Fastify plugin that forwards requests to an upstream HTTP or HTTPS server. In versions prior to 12.7.0, all of the built-in HTTPS transports override the secure default and set rejectUnauthorized to false, so the proxy does not verify the TLS certificate of the upstream even when the application points it at an https upstream in the default configuration. An on-path networ…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-84244] IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cros…
IBM Guardium Data Protection 12.2 IBM Security Guardium Data Protection is vulnerable to stored cross-site scripting (XSS) in the Quick Search results grid. An unauthenticated attacker who can influence monitored database traffic could execute malicious script in the browser of an authenticated Guardium user.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-84278] IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root …
IBM Guardium Data Protection 12.2 is affected by a command injection vulnerability in the SUID-root ssh_config_wrapper component. An authenticated high-privileged user can inject arbitrary commands through attacker-controlled arguments, resulting in command execution with root privileges.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107377] datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.8…
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_missing_weak_imports in src/datamodel_code_generator/parser/protobuf.py. Exploitation requires a victim or automated job to process the attacker-controlled…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107375] JHipster is a development platform to quickly generate, develop, and deploy modern web applications …
JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. From 7.0.0 until 9.4.0, reactive applications generated with Spring WebFlux, Spring Data R2DBC, and a SQL database pass the attacker-controlled sort request parameter from paginated entity-list endpoints into createOrderByFields in generators/spring-boot/generators/da…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107303] JHipster is a development platform to quickly generate, develop, and deploy modern web applications …
JHipster is a development platform to quickly generate, develop, and deploy modern web applications and microservice architectures. Prior to generator-jhipster 9.4.0 and react-jhipster 1.1.0, generated applications can persist attacker-controlled Blob data and companion ContentType values, return them through generated REST endpoints, and pass them to the generated openFile helper in generators/cl…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-50054] An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with acc…
An authorization flaw in Zimbra Collaboration Suite’s GrantRightsRequest allows an attacker with access to an authenticated account to grant another local account the loginAs right, creating persistent mailbox access and mail-sending authority that survives password changes and session expiry.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107295] Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. …
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.34.0 until 1.107.4 and 2.28.0, the Agent.to_web() and clai web development chat endpoint has missing request content-type validation. A website visited by a developer can submit a browser-compatible request to a loopback-hosted chat server, causing the served agent to run and execute tools wi…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-9209] mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Logi…
mJobTime through build 15.7.3.32 contains an unauthenticated SQL execution vulnerability in the Login.aspx admin panel handlers, where the runQueryButton postback and exportSqlQuery_Server PageMethod execute caller-supplied SQL against the backing Sybase SQL Anywhere database using DBA/sysadmin privileges with no server-side authentication enforced beyond a client-side sessionStorage flag. Attacke…
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107639] ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerabili…
ILIAS before 9.24, 10.x before 10.12 and 11.x before 11.5 contains an argument injection vulnerability in assImagemapQuestionGUI that allows question authors to inject ImageMagick convert options via uploaded image filenames. Attackers can embed tab-separated options, which escapeshellcmd() does not neutralise, to write a PHP file under the web root and achieve remote code execution.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-107286] Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. …
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 2.10.0 until 2.53.0, streamed requests made through ConcurrencyLimitedModel or limit_model_concurrency can retain shared concurrency slots because anyio.CapacityLimiter associates an acquired slot with the borrowing task while streaming cleanup can run in a different task. Early stream terminat…
M Crítico vulnerabilidad
Hace 1 día
[CVE-2026-14990] IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnera…
IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-66479] Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allo…
Cross-Site Request Forgery (CSRF) vulnerability in Liquid Web / StellarWP WPComplete wpcomplete allows Stored XSS.This issue affects WPComplete: from n/a through 2.9.5.6.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad alta en Progressive Robot hMailServer permite denegación de servicio remota
Una complejidad algorítmica ineficiente en la verificación de firmas DKIM y ARC en Progressive Robot hMailServer 6.0.0 a 6.3.5 permite a atacantes remotos no autenticados saturar servidores de correo mediante mensajes especialmente crafted. El procesamiento de encabezados crece exponencialmente, causando consumo excesivo de recursos y caída del servicio de correo, impactando directamente la comunicación empresarial en organizaciones que dependen de este servidor.
M Alto vulnerabilidad
Hace 1 día
Vulnerabilidad de denegación de servicio en hMailServer 6.3.0-6.3.5 en Linux por falta de timeouts
Progressive Robot hMailServer versiones 6.3.0 a 6.3.5 en Linux presenta un defecto alta donde falta configuración de timeouts en conexiones de red, permitiendo a atacantes remotos bloquear threads del servidor e interrumpir la entrega de correo saliente. Este problema afecta directamente a servidores de correo empresariales en México y Latinoamérica que utilizan estas versiones en infraestructura Linux, causando degradación severa del servicio de comunicaciones.
M Alto vulnerabilidad
Hace 1 día
[CVE-2026-71183] An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain infor…
An authorization vulnerability in Apache DolphinScheduler allows authenticated users to obtain information about data sources they are not authorized to access through the /unauth-datasource and /authed-datasource endpoints. These endpoints fail to enforce the required data source access controls and return sensitive connection information, including data source passwords. As a result, an authe…
M Crítico vulnerabilidad
Hace 2 días
[CVE-2026-103646] The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logg…
The Ultimate Multisite WordPress plugin before 2.17.0 does not require authentication before a logged-out checkout is linked to, and logged in as, an existing WordPress account matching the submitted email address, and its duplicate-account check normalizes that address differently from the lookup used to create the customer, so an unauthenticated attacker can log in as any existing user, includi…
M Alto vulnerabilidad
Hace 2 días
[CVE-2026-17196] The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File T…
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 6.3.316 via the upload_files function. This is due to missing file type validation in the upload_files function, which reads and applies an attacker-controlled extensions string from _super_elements post meta verbatim as the allowed MIME type map. Thi…