Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1020
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-104084] SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and ref…
SmarterMail before build 9777 contains a privilege escalation vulnerability where JWT access and refresh tokens embed a role claim at issuance that is not revalidated against the account's current role when redeemed through POST /api/v1/auth/refresh-token. Attackers who capture a refresh token issued before an administrator demotion, or a demoted user whose session was not actively polling at the …
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-104082] SmarterMail before build 9777 contains a remote code execution vulnerability that allows an attacker…
SmarterMail before build 9777 contains a remote code execution vulnerability that allows an attacker holding a SysAdmin-scoped access token to bypass the Volume Mount script-directory containment control by provisioning a new mail domain with an arbitrary FileStore root path inside the trusted Scripts directory via the domain-put endpoint. Attackers can disclose the Scripts path through the AddOrU…
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-78795] An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540…
An issue in Netcore B11 Enterprise-level full Gigabit 9-port shop wireless router v1.3.241114.024540 and before allows a remote attacker to obtain sensitive information
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-33367] SNMP can be used to perform administrative actions such as retrieving configuration files, modifying…
SNMP can be used to perform administrative actions such as retrieving configuration files, modifying user accounts or device settings, and initiating firmware or bootloader upgrades or downgrades—all without any authentication.
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-39453] Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be auto…
Navigating to a certain URL on the switch’s web server causes the switch to reboot. This can be automated using a tool like curl to create DoS conditions where the switch constantly reboots.
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-39460] Usernames and passwords, including the default factory credentials, are stored in plaintext within t…
Usernames and passwords, including the default factory credentials, are stored in plaintext within the configuration file. With administrator rights, the configuration file can be viewed through the CLI or they can be exported from the device through a TFTP transfer from the web interface. A TFTP transfer can be initiated through SNMP which does not require authentication.
M Crítico vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-15340] lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.
lwIP SMTP client does not check the size of inputs, potentially allowing a buffer overflow.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-28745] Usernames and passwords, including the default credentials, are stored in the configuration file usi…
Usernames and passwords, including the default credentials, are stored in the configuration file using weak encryption. If the default credentials are known by a malicious user, they could obtain other credentials on the system.
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-29797] No authentication is required when updating firmware or bootloader, making it easy for malicious fil…
No authentication is required when updating firmware or bootloader, making it easy for malicious files to be pushed to the device. Additionally, anyone with the same software can scan a network for N-Tron devices and push/pull firmware without authenticating by using SNMP/TFTP.
M Crítico vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-108109] PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password res…
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-108106] Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows…
Xerial snappy-java before 1.1.10.9 contains an unbounded memory allocation vulnerability that allows attackers to exhaust JVM memory by declaring a large uncompressed length in compressed input. Attackers can supply a few crafted bytes to Snappy.uncompress, uncompressString, SnappyInputStream or SnappyFramedInputStream to force allocations up to 2 GB, causing OutOfMemoryError and denial of service…
M Crítico vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-108107] PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.p…
PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-108108] PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verifica…
PHPNuxBill through 2025.3.20 contains an authentication bypass vulnerability in RADIUS CHAP verification because Password::chap_verify() returns true when the supplied response does not match. Attackers who know a valid customer or PPPoE username can log in through MikroTik hotspot or PPPoE CHAP with any incorrect password to obtain network access and consume that customer's plan.
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-108101] HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAtt…
HortusFox (hortusfox-web) through 6.3 contains an unrestricted file upload vulnerability in PlantAttachmentModel that allows authenticated users to store files with client-supplied extensions under public/attachments/. Attackers can upload HTML or SVG files via /plants/attachments/add for stored cross-site scripting, or PHP files where .htaccess is unenforced to execute code.
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-107805] Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signatur…
Nginx UI is a web user interface for the Nginx web server. From 2.5.0 until 2.6.0, the node-signature authentication path performs temporary file staging of an attacker-controlled request body and synchronizes it before validating the body digest and cryptographic signature. An unauthenticated remote client that can reach the API and provide syntactically valid signature metadata can consume tempo…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Crítico vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-105278] The published Docker image for openPDC includes a fixed administrative credential with no forced cha…
The published Docker image for openPDC includes a fixed administrative credential with no forced change on first use. An attacker with network access to the management interface can authenticate using this credential and gain full administrative control of the application.
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-104081] KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function wit…
KodExplorer before 4.55 contains a path traversal vulnerability in the unzip_pre_name() function within app/function/helper.function.php, where a single non-recursive str_replace() sanitization pass can be bypassed using crafted filenames like "....//", combined with PclZip's extract() call in KodArchive.class.php lacking the PCLZIP_OPT_EXTRACT_DIR_RESTRICTION option. Authenticated attackers can u…
M Alto vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-94067] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio…
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Fuelthemes The Voux thevoux-wp allows PHP Local File Inclusion.This issue affects The Voux: from n/a through 6.9.5.
M Alto vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-94064] Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme ne…
Deserialization of Untrusted Data vulnerability in BuddhaThemes Neo | Barber Shop WordPress Theme neocut allows Object Injection.This issue affects Neo | Barber Shop WordPress Theme: from n/a through 3.5.
M Alto vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-94065] Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Inj…
Deserialization of Untrusted Data vulnerability in BuddhaThemes ColorFolio colorit allows Object Injection.This issue affects ColorFolio: from n/a through 1.3.