Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 16924 resultados ✕ Limpiar búsqueda
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1263
Esta semana
RSS
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-103475] yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting …
yii2-starter-kit through 4.2.0 exposes the Yii debug and Gii modules to all IP addresses by setting allowedIPs to ['*'] in its default development configuration. Unauthenticated remote attackers can access the debug endpoint to read sensitive data including session cookies and database queries, or access the Gii endpoint to generate and write PHP files into the application directory.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102376] Subscriber Cross Site Scripting (XSS) in Branda <= 3.4.32 versions.
Subscriber Cross Site Scripting (XSS) in Branda
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102377] Contributor PHP Object Injection in Photo Gallery by 10Web <= 1.8.46 versions.
Contributor PHP Object Injection in Photo Gallery by 10Web
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102391] Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102392] Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons a…
Shop manager PHP Object Injection in Extra Product Options For WooCommerce | Custom Product Addons and Fields
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100510] Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-100512] Contributor PHP Object Injection in Nested Pages <= 3.3.2 versions.
Contributor PHP Object Injection in Nested Pages

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-62308] Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6,…
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.6, Tugtainer allows an authenticated user to make the backend server send outbound HTTP requests to arbitrary user-supplied URLs through the notification test endpoint. The /settings/test_notification endpoint accepts a urls field and passes it directly to Apprise without restricting protocols, hostna…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-55494] Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4,…
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.4, Tugtainer Agent allows unauthenticated access to Docker management APIs when AGENT_SECRET is not configured. The Agent uses request signatures to protect its API routes. However, in agent/auth.py, the signature verification function returns successfully if Config.AGENT_SECRET is empty. This causes …
M Alto vulnerabilidad
30/09/2026
[CVE-2026-46711] Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.…
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, the workspace HTTP service that listens on 0.0.0.0:8080 inside each sm-ws-* Fly Machine exposes endpoints (/health, /file/, /archive/) without any authentication or origin check. Any host that can reach TCP/8080 on a workspace can read arbitrary files under that workspace's…
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-55176] Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.…
Soft Machine is a Virtual Machine–based agentic development environment / Cloud OS. In versions 0.2.247 and prior, two authentication helpers in /app/server.js — verifyContainerAuth() and authenticateWorkspaceHttp() — accept the global CONTAINER_SHARED_SECRET as a bearer token without verifying which workspace the caller belongs to. Because that secret is set identically on every container in the …
M Crítico vulnerabilidad
30/09/2026
[CVE-2026-55181] Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3,…
Tugtainer is a self-hosted app for automating updates of Docker containers. Prior to version 1.30.3, Tugtainer's OIDC authentication can still be initiated even when OIDC_ENABLED=false. The /auth/oidc/enabled endpoint correctly reports that OIDC is disabled. However, a direct request to /auth/oidc/login still starts the OIDC login flow, returns HTTP 302, sets an oidc_state cookie, and redirects th…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-103232] A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcf…
A weakness has been identified in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c. This affects the function mysqli_query of the file admin/table_booking.php. This manipulation of the argument Name causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. The proje…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47598] NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module event …
NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module event delivery path where an unprivileged local user could cause a use-after-free through a race between asynchronous event delivery and file close. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tamper…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47599] NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where …
NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47600] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer wh…
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an error-handling path could operate on an improperly initialized resource. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47601] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel m…
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-only buffer from another device's DMA-BUF exporter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denia…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47602] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver w…
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode driver where a local user can cause the driver to dereference an untrusted pointer. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47591] NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unpri…
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could bypass read-only memory protection due to incorrect authorization, enabling write access to memory marked read-only. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47592] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer wh…
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.