Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,949
Total alertas
3186
Críticas
10491
Altas
8
Ransomware
1233
Esta semana
RSS
M Alto vulnerabilidad
19/06/2026
[CVE-2026-41156] Software installed and run as a non-privileged user may conduct improper GPU system calls to cause m…
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources creating a write use after free scenario. A shared resource (memory page) managed by a CPU thread of control (driver) and accessed by a GPU thread of control (Firmware) can cause a write UAF when the CPU thread frees the resource before the GPU FW has finished accessing …
E Alto vulnerabilidad
19/06/2026
[CVE-2026-11576] The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP …
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file was never successfully opened. Multiple error branches jump to the shared cleanup label before any file open operation has occurred, causing fx_file_close() to ope…
D Alto vulnerabilidad
19/06/2026
[CVE-2026-46461] Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerabi…
Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
M Crítico vulnerabilidad
19/06/2026
[CVE-2026-7515] The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and…
The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code e…
M Crítico vulnerabilidad
19/06/2026
[CVE-2026-8713] The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insu…
The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all versions up to, and including, 3.15.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-confi…
M Crítico vulnerabilidad
19/06/2026
[CVE-2026-54414] FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/fo…
FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename() and REGEX_FILE_NAME, which permit URL-encoded sequences (the regex blocks / and \ but not %). The raw filename is then passed to Up…
M Alto vulnerabilidad
19/06/2026
[CVE-2025-7737] DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects …
DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform. This issue affects Hitachi Virtual Storage Platform E990, E1090, E1090H: before DKCMAIN Ver.93-07-21-80/00-05, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-07-01-80/00-07, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-06-82-80/00-06, CHB(iSCSI) Ver.88-01-02-04, before DKCMAIN Ver.93-06-63-80/00-04, CHB(iSCSI)…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
P Crítico vulnerabilidad
19/06/2026
[CVE-2026-12048] Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text retur…
Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relation-does-not-exist errors and inside EXPLAIN Recheck Cond / Exact Heap Blocks fields) was passed verbatim through html-react-parser at every user-facing sink — the notifier toasts, FormFooterMessage / …
M Crítico vulnerabilidad
19/06/2026
[CVE-2026-40624] Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote,…
Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.
P Alto vulnerabilidad
19/06/2026
[CVE-2026-12044] SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<descripti…
SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS ''`` for a user-supplied description field. The Jinja templates for Domains (and their constraints), Foreign Tables, Languages, and Event Triggers, plus the Views OID-lookup query, interpolated the description directly inside a single-quoted SQL literal -- ``'{{ data.description }}'`` -- instead o…
P Crítico vulnerabilidad
19/06/2026
[CVE-2026-12045] Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence data…
Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs LLM-generated SQL inside a BEGIN TRANSACTION READ ONLY wrapper to prevent data modification. The LLM-supplied query was forwarded to…
P Crítico vulnerabilidad
19/06/2026
[CVE-2026-12046] Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_i…
Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/ and POST /sqleditor/initialize/sqleditor/update_connection/// -- were the only routes in the module missing the @pga_login_required decorator. Both reach a pickle.loads sink on session['gridData'][]['command_obj']: the close endpoint via close_sqleditor_session(), and up…
M Alto vulnerabilidad
18/06/2026
[CVE-2026-56075] PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI mo…
PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator configuration from PRAISON_APPROVAL_MODE environment variable. Authenticated attackers can instruct the LLM agent to execute arbitrary shell commands via subprocess.run with shell=True, bypassing the manual approval gate and insufficient…
M Alto vulnerabilidad
18/06/2026
[CVE-2026-56076] PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint …
PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote attackers to trigger arbitrary agent execution. The POST /agui endpoint lacks authentication and hardcodes Access-Control-Allow-Origin: * headers, combined with Starlette's Content-Type-agnostic JSON parsing, enabling attackers to bypass CORS preflight checks via simple requests a…
M Alto vulnerabilidad
18/06/2026
[CVE-2026-56078] PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to …
PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in agent IDs to read, write, or overwrite arbitrary files, enabling sensitive disclosure, denial of service, or code execution.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
O Alto vulnerabilidad
18/06/2026
[CVE-2026-54017] Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. P…
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the terminal-server reverse proxy in `backend/open_webui/routers/terminals.py` does not fully confine the user-controlled `path` segment before forwarding it to an admin-configured terminal server. An authenticated user who has been granted access to a terminal server can craft `path`…
M Crítico vulnerabilidad
18/06/2026
[CVE-2026-54130] Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disc…
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
M Alto vulnerabilidad
18/06/2026
[CVE-2026-47633] Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experience…
Exposure of sensitive information to an unauthorized actor in Cost Management Interactive Experiences allows an unauthorized attacker to disclose information over a network.
M Crítico vulnerabilidad
18/06/2026
[CVE-2026-47647] Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privilege…
Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
18/06/2026
[CVE-2026-32174] Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges ove…
Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network.