Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1781
Esta semana
RSS
M Alto vulnerabilidad
05/06/2026
[CVE-2026-36785] Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow i…
Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter of the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.
M Alto vulnerabilidad
05/06/2026
[CVE-2026-11422] Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability…
Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript by embedding malicious content in a wavedrom fenced code block within a crafted Markdown document. Attackers can exploit the unsanitized passing of wavedrom block content to window.eval() in the VS Code webview…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-46493] HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `u…
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitable. Version 26.0.1 fixes the issue.
B Crítico vulnerabilidad
05/06/2026
[CVE-2026-45779] OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerabil…
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to execute arbitrary SQL statements. Exploitation requires no authentication or user interaction and can result in complete compromise of the underlying database. All deployments of Open XDMoD prior to 1…
G Crítico vulnerabilidad
05/06/2026
[CVE-2026-45758] Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximate…
Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious version of `guardrails-ai` (0.10.1) to PyPI. Aany user who installed `guardrails-ai==0.10.1` from PyPI on May 11, 2026 may be affected. Security researchers identified the malicious package within approximately 2 hours of publication, and PyPI qu…
B Crítico vulnerabilidad
05/06/2026
[CVE-2026-45777] OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 a…
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web server hosting Open XDMoD with the privileges of the web server process. This could allow an attacker to read or modify application data, alter system configuration, or disrupt service availability. All…
A Alto vulnerabilidad
05/06/2026
[CVE-2026-45300] The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and async…
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin, the `propagatedHeaders()` method in `Redirect30xInterceptor.java` strips `Authoriza…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
A Crítico vulnerabilidad
05/06/2026
[CVE-2026-11414] A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the…
A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauthenticated network attacker who can reach the server can forge valid download signatures and retrieve files from the Vault storage area without any authentication, session, or credentials. A separate path traversal vuln…
A Alto vulnerabilidad
05/06/2026
[CVE-2026-11419] A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController…
A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload requests. An authenticated user can supply a crafted absolute path so that the configured storage root is discarded, allowing arbitrary files to be written to any location on the server filesystem writable by the service…
A Crítico vulnerabilidad
05/06/2026
[CVE-2026-11420] Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Se…
Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on the server filesystem and to read package archive files from the server. No authentication, session, or credentials are required. Because content-controlled files can be written to web-accessible …
M Alto vulnerabilidad
05/06/2026
[CVE-2026-11400] An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amaz…
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when that user connects to the cluster through an affected wrapper. To remediate th…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-11401] An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon…
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to those of another Amazon RDS user, including rds_superuser, via a crafted function created by the actor that runs when that user connects to the cluster through the affected wrapper. To remediate thi…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-5415] The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same …
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.38. This is due to the ajax_run_tool() AJAX handler relying solely on a nonce check (check_ajax_referer) for security without performing any capability check, combined with the create_temporary_…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-5411] The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same …
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 5.38. This is due to a capability check in the save_ajax() function of the licensing module, combined with unrestricted file extraction in sync_cloud_protection(). This makes it possible for authe…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-46392] HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX …
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the filename to disk verbatim, but the `.htaccess` rule that forces `Content-Disposition: attachment` on HTML files is case-sensitive. An HTML file uploaded with an uppercase extension (`.HTML`, `.Html`, `.HTM…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
D Crítico vulnerabilidad
05/06/2026
[CVE-2026-46389] UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs…
UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, a logic error in the `client-kubernetes-secret` Keycloak client authenticator (shipped by `uds-identity-config` and consumed by UDS Core) causes the submitted `client_secret` to be overwritten with the mounted Kubernete…
M Crítico vulnerabilidad
05/06/2026
[CVE-2026-10580] The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass le…
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a logic conflation in HippooPermissions::get_user_permissions(), which returns the same null sentinel for both administrators and unauthenticated visitors — a value that HippooPermissions::has_role_acce…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-50733] Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown co…
Markdown Preview Enhanced before 0.8.28 parses WaveDrom diagrams by evaluating untrusted markdown content with eval(), allowing arbitrary JavaScript execution. The flaw affects every render path - the live preview (window.eval) and presentation mode plus HTML export (the bundled WaveDrom.ProcessAll()/eva() helpers) - and can also be triggered through a element injected via…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-49492] Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a sh…
Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not validate untrusted inputs taken from the markdown document - the diagram filename attribute, imported file paths, and the latex_engine code-chunk attribute. On Windows, a crafted markdown document can inject operating system commands that execute when the document is previewed. Fixe…
M Alto vulnerabilidad
05/06/2026
[CVE-2026-49493] Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which…
Markdown Preview Enhanced before 0.8.28 parses Bitfield fenced code blocks with interpretJS(), which evaluates the block content as code via vm.runInNewContext(), allowing arbitrary code execution. A crafted markdown document containing a malicious bitfield code block executes attacker-controlled code on the server side when the document is rendered or exported. Fixed in 0.8.28 by parsing bitfield…