Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3495 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-19295] IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operatin…
IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it. This allowed privilege escalation from "authenticated flow user" to arbitrary OS-level command execution under the server process identity, bypassing …
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-18527] IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow…
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing. An unauthenticated attacker can exploit this vulnerability to execute actions under another user's authenticated profile gaining elevated privileges on the IBM i system.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82288] Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v…
Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in cleartext. Unauthenticated attackers can access this endpoint to retrieve configured usernames and passwords, then use them to authenticate to the interface and access the application.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82280] Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users …
Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier. Attackers with read-only access to shared brains can read exposed prompt identifiers and overwrite system prompts affecting all brain users.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82284] Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, D…
Quivr versions through 0.0.322 fail to validate chat ownership in the GET /chat/{chat_id}/history, DELETE /chat/{chat_id}, and POST /chat/{chat_id}/question/answer endpoints. Authenticated attackers can read other users' conversation histories including private knowledge base content, delete arbitrary chats, and inject fabricated messages into other users' conversations.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82266] Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting t…
Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82269] Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API …
Gophish through 0.12.1 fails to enforce account lockout and password change requirements in the API authentication middleware. Attackers with valid API keys can bypass these security controls and retain full API access even when their account is locked or password change is required.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-55634] Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, the class-definition import endpoint /pimcore-studio/api/class/definition/configuration-view/detail/{id}/import accepts a DataObject field name that is emitted without an identifier allowlist by lib/DataObject/ClassBuilder/FieldDefinitionPropertiesBuilder.php into generated PHP properties and …
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55484] ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking …
ALOS HTTP is a Linux-first Go web framework and application server built around a custom networking stack. Prior to 0.0.0-20260617230736-314b6783e196, core/utils.go::sanitizeRequestPath calls splitPathQuery on a request path beginning with a question mark and then performs the unchecked p[0] access without checking whether the resulting path is empty. An unauthenticated client can send a malformed…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-55485] Piccolo Admin is an admin interface and content management system for Python, built on top of Piccol…
Piccolo Admin is an admin interface and content management system for Python, built on top of Piccolo. Prior to 1.14.0, piccolo_admin/endpoints.py uses superuser_validators to block PUT, PATCH, DELETE, and POST requests by non-superusers but permits GET requests to configured user and session tables, while piccolo_api/session_auth/tables.py exposes SessionsBase.token because the token column is no…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-54745] Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. …
Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows. Prior to 2.17.0, the Kubeflow Pipelines frontend exposes an unauthenticated server-side request forgery vulnerability through the /_proxy/ route in frontend/server/proxy-middleware.ts. The _routePathWithReferer() function accepts an arbitrary attacker-controlled HTTP or HTTPS target and passes its o…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-54755] Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty…
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.19, split-royalty fields decoded in core/kapp/builtInFunctions/utils.go can contain values greater than core.HundredPercent, and core/kapp/kda/create.go and core/kapp/kda/trigger.go sum those values in uint32 accumulators. Crafted values such as two 0x80000000 entries wrap the validation sum to zero and pass CheckVa…
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad alta en gitoxide anterior a 0.52.1 permite inyección de metadatos de submódulos
gitoxide versiones anteriores a 0.52.1 presenta una vulnerabilidad que permite a atacantes seguir enlaces simbólicos en el archivo .gitmodules del árbol de trabajo, facilitando la inyección de bytes maliciosos en metadatos de submódulos. Un repositorio malicioso puede redirigir la lectura de configuración hacia archivos externos arbitrarios, exponiendo información controlada por el atacante en nombres, rutas y URLs de submódulos. Afecta principalmente a equipos de desarrollo que utilizan gitoxide para control de versiones en México y Latinoamérica.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de escalada de privilegios en Budibase anterior a 3.41.3
Budibase versiones anteriores a 3.41.3 no valida correctamente las asignaciones de roles de constructor a nivel de aplicación en los endpoints públicos de creación y actualización de usuarios. Un constructor autenticado con acceso limitado a una aplicación puede explotar esta falla para otorgarse a sí mismo acceso de constructor en otras aplicaciones del mismo tenant, comprometiendo la segmentación de datos en entornos multi-tenant comunes en empresas medianas de LATAM.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de SSRF en Budibase backend-core permite eludir restricciones de red
Budibase backend-core omite el rango 100.64.0.0/10 de su lista negra predeterminada de SSRF, permitiendo que usuarios autenticados con permisos de Builder ejecuten consultas REST datasource contra redes internas. Este rango es alta en infraestructuras cloud compartidas (AWS, Google Cloud) donde se asignan direcciones privadas. La vulnerabilidad afecta principalmente a deployments autohospedados sin configuración personalizada de listas negras.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de autorización en Budibase anterior a v3.41.3 permite inyección de recursos
Budibase versiones anteriores a 3.41.3 contienen una vulnerabilidad de autorización faltante en el endpoint POST /api/resources/duplicate que permite a constructores autenticados inyectar tablas, automatizaciones, consultas y pantallas en otras aplicaciones sin permisos en el espacio de trabajo destino. Un atacante puede especificar un ID de espacio de trabajo arbitrario en el cuerpo de la solicitud para comprometer la integridad de múltiples proyectos.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad SSRF alta en Budibase Server anterior a 3.41.3 expone credenciales de CouchDB
Budibase Server versiones anteriores a 3.41.3 contiene una vulnerabilidad de falsificación de solicitud del lado del servidor (SSRF) en el endpoint de verificación de fuentes de datos. Usuarios con permisos de constructor pueden enviar URLs arbitrarias sin validación, permitiendo a atacantes extraer credenciales internas de CouchDB y obtener acceso total a bases de datos en despliegues en la nube. Esto es alta para empresas LATAM que utilizan Budibase en infraestructura compartida o multitenante.
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-82222] Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injec…
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP GiveWP allows Object Injection. This issue affects GiveWP: from n/a through 4.16.7.1.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-73208] An attacker that holds a token intended for a different purpose can authenticate, because when an OA…
An attacker that holds a token intended for a different purpose can authenticate, because when an OAuth2 token response does not contain a scope claim, the audience claim is used in its place and checked against the configured required scopes. These are different concepts, and the audience claim does not describe what a token is allowed to do. A token that grants no relevant permissions can be acc…
M Crítico vulnerabilidad
28/08/2026
[CVE-2026-40541] An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit…
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.