Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 3497 resultados ✕ Limpiar búsqueda
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1272
Esta semana
RSS
M Alto vulnerabilidad
25/08/2026
[CVE-2026-59186] OpenEXR is the reference implementation and specification for the EXR image format, widely used in t…
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 …
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55571] djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to 1.0.4, LiveViewConsumer.handle_mount sends a `{"type":"navigate","to":...}` frame when login_required, permission_required, or a redirecting on_mount hook denies a LiveView mount, but returns without closing the WebSocket or clearing self.view_instance. A browser follows the redi…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55585] QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, to…
QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution. Prior to 5.1.2, the qwed package passes caller-controlled math expressions directly to SymPy parse_expr() without restricted global_dict and local_dict namespaces, allowing Python eval() to resolve builtins and execute arbitrary P…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-16233] There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info…
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-16234] There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in info…
There is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  This vulnerability affects NI LabVIEW 2026 Q3 (26.3.0) and prior versions.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79774] Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability …
Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig sandbox escape vulnerability in System\\Twig\\SecurityPolicy that allows authenticated backend users with template-editing permissions to bypass sandbox restrictions. Attackers can exploit method forwarding through Eloquent models and query builders using methods like saveQuietly(), deleteQuietly(), increment(), decrement(), an…
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-55546] QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() i…
QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engines/math_engine.py passes attacker-controlled expression and claimed_result strings directly to SymPy's parse_expr() after only normalizing caret syntax to Python exponent syntax, without restricting global_dict, removing Python built-ins, or validating the expression AST. Because…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-55640] Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud ins…
Nextcloud MCP Server is a production-ready MCP server that connects AI assistants to a Nextcloud instance. Prior to 0.117.2, the POST /webhooks/nextcloud endpoint in nextcloud_mcp_server/vector/webhook_receiver.py has no authentication by default because WEBHOOK_SECRET defaults to None and startup validation does not require it. When WEBHOOK_SECRET is unset, handle_nextcloud_webhook() accepts unau…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-69104] An authenticated user may initiate repository migration operations without required repository permi…
An authenticated user may initiate repository migration operations without required repository permissions, potentially causing information disclosure, unauthorized state changes, and service disruption. Fixed versions address the issue.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-63075] Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting p…
Issue summary: When OpenSSL processes QUIC traffic from a peer that repeatedly sends ack-eliciting packets while not acknowledging ACK-only responses, the QUIC stack can retain ACK-only packet metadata for the lifetime of the connection. Impact summary: A remote peer that can complete a QUIC handshake can cause connection-scoped memory growth which may lead to Denial of Service through memory exh…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-54874] Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes Op…
Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires. Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service. CWE: CWE-405: Asymmetric Resource Consumptio…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-18798] Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation f…
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server process, leading to Denial of Service. There is so far no evidence that this double free is exploitable for remote code execution, thus it is considered highly impro…
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad de omisión de autorización en Ech0 anterior a 4.5.1 permite acceso a endpoints administrativos
Ech0 versiones anteriores a 4.5.1 presentan una falla de autorización donde los tokens de sesión no validan permisos en el middleware RequireScopes, permitiendo que usuarios autenticados sin privilegios de administrador accedan a endpoints protegidos. Los atacantes pueden extraer registros del sistema, estadísticas de visitantes, correos de usuarios y suscribirse a logs en vivo mediante WebSocket utilizando tokens de sesión válidos.
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta de escalada de privilegios en ShopEngine Elementor WooCommerce Builder
El plugin ShopEngine Elementor WooCommerce Builder para WordPress (versiones hasta 4.9.4) contiene una vulnerabilidad de escalada de privilegios (CVSS 7.2) en la función rum_importer() que permite a atacantes ejecutar acciones administrativas sin validación de permisos. Afecta a tiendas en línea en México y LATAM que utilicen este componente para gestionar productos y opciones de WooCommerce. Un atacante puede modificar configuraciones altas, crear cuentas administrativas o inyectar código malicioso en la base de datos.
M Crítico vulnerabilidad
25/08/2026
Vulnerabilidad crítica de escalada de privilegios en plugin Total Donations para WordPress (CVE-2026-78570)
El plugin Total Donations para WordPress (versiones hasta 2.0.5) contiene una vulnerabilidad de escalada de privilegios con puntuación CVSS 9.8 que permite a atacantes no autenticados obtener permisos de administrador. Esto afecta directamente a sitios de ONG, iglesias y organizaciones benéficas en LATAM que dependen de este plugin para recaudación de fondos. La explotación no requiere autenticación previa, aumentando significativamente el riesgo de compromisos totales del sitio.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-63587] The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the …
The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Authorization' setting. The device increments a retry counter on each failed SMS password attempt; after 5 consecutive failed attempts, SMS password authorization is automatically disabled. An unauthenticated remote attacker who is able to send SMS messages to the device can deliber…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-18323] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Radio Field (Save and Continue Draft) in all versions up to, and including, 1.57.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute w…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-18328] The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vuln…
The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to DOM-Based Reflected Cross-Site Scripting via the 'error_description' parameter in all versions up to, and including, 1.57.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will ex…
M Crítico vulnerabilidad
25/08/2026
[CVE-2026-56710] Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in th…
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout counters on admin.super accounts, removing brute-force protection from the highest-privilege accounts without requiring equivalent permissions.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-56709] Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function whe…
Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows.