Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1019
Esta semana
RSS
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de Path Traversal en gitoxide (gix ≤ 0.72.0 y gix-validate ≤ 0.10.0)
gitoxide, conjunto de herramientas Rust para gestión de repositorios Git, contiene una vulnerabilidad de path traversal (CVSS 7.5) en la validación de nombres de submódulos. La función de validación solo verifica la primera ocurrencia de '..', permitiendo nombres manipulados como 'a..b/../../../.git/' eludir el control. Esta validación tampoco se ejecuta en rutas de código de producción, exponiendo sistemas que procesan repositorios Git no confiables a acceso no autorizado de archivos.
M Alto vulnerabilidad
28/08/2026
Vulnerabilidad de traversal de ruta en gitoxide anterior a 0.52.1 mediante validación deficiente de submódulos
gitoxide versiones anteriores a 0.52.1 no valida correctamente nombres de submódulos en configuración .gitmodules, permitiendo ataques de traversal de ruta que redirigen operaciones hacia repositorios fuera del directorio .git/modules. Atacantes pueden inyectar submódulos maliciosos para provocar confusión de repositorio e inspección de código controlado por el adversario, afectando integridad de repositorios en empresas que utilizan esta librería en LATAM.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-54083] Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints an…
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The  ip-customblock  active response script contains a path traversal vulnerability that lets an attacker create or delete arbitrary files on the filesystem as root. The script builds a file path by concatenating the  srcip  field taken from alert JSON directly onto the fixed  /ip…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81730] Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message…
Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepath = $path . $filename . '.' . $ext and hands it to file_put_contents(), and the private saveAttachment() in htdocs/emailcollector/class/emailcollecto…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-76639] Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerabilit…
Unitree G1 EDU firmware through 1.5.2 contains an unauthenticated remote code execution vulnerability that allows network-adjacent attackers to execute arbitrary commands as root by chaining three weaknesses: an unauthenticated WebRTC-to-DDS bridge on TCP port 9991, a static AES-128 key stored with world-readable permissions, and a path traversal flaw in the chat_go knowledge upload API. Attackers…
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81491] A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_…
A flaw has been found in boxpositron with-context-mcp up to 3.0.7. This affects the function ingest_notes/teleport_notes/sync_notes/project_folder of the file src/index.ts. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has no…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-61792] Weblate is a web-based continuous localization platform used to manage software translations. In ver…
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves attacker-influenced paths without adequately confining them to the repository. This is an incomplete fix for CVE-2026-34242, whose original patch fai…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
26/08/2026
[CVE-2026-54550] IzPack is a widely used tool for packaging applications on the Java platform as cross-platform insta…
IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack-installer/src/main/java/com/izforge/izpack/installer/unpacker/UnpackerBase.java obtains an attacker-controlled PackFile targetPath, passes it through IoHelper.translatePath(), which only converts separators, and constructs a File without n…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-15990] The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up t…
The Formidable Charts plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.0.1 via the 'frm_graph' parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Successful exploitation requires Formidable Forms Lite, Formidable Forms Pro, and Formidable Cha…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-75797] The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it …
The AI Engine WordPress plugin before 3.7.2 does not confine a caller-supplied URL when mapping it to a local filesystem path before reading the file and forwarding its contents to an external service, allowing users with a subscriber-level account to read arbitrary files from the server and exfiltrate them off-host. Reaching the issue at subscriber level requires a non-default public API feature…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-57171] Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance doc…
Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an attacker-influenced output path without path-traversal validation, allowing arbitrary file write outside the Trestle workspace. …
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad de traversal de ruta en NVIDIA OpenShell Sandbox para Linux (CVE-2026-65092)
NVIDIA OpenShell Sandbox para Linux contiene una vulnerabilidad que permite a atacantes eludir la política de seguridad de red L7 REST mediante traversal de ruta, facilitando acceso no autorizado a información sensible y manipulación de datos. Esta falla afecta infraestructuras de contenedorización y edge computing en datacenters de LATAM que dependen de OpenShell para aislamiento de cargas de trabajo.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55540] PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses …
PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, is_path_within_directory() uses os.path.abspath() rather than os.path.realpath() for the workspace boundary. A symlink inside workspace can point outside and still pass the check, allowing read_file and other code tools to access files outside the configured workspace. This issue is fixed in version 4.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-55527] PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor…
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the FileMemory constructor joins unsanitized user_id into self.user_path. A caller supplying ../ or path separators can escape the memory directory and write JSON data to arbitrary process-writable locations. The fix sanitizes user_id before constructing self.user_path. This issue is fixed in version 1.6.58.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79622] A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the …
A weakness has been identified in dekdee adobe-xd-mcp 1.0.0. Impacted is an unknown function of the file src/parsers/xd-parser.ts of the component file-access-from-request Endpoint. Executing a manipulation of the argument outputFile/outputDir can lead to path traversal. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. T…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
25/08/2026
[CVE-2026-57863] Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that all…
Crater Invoice through 6.0.6 contains a path traversal vulnerability in the self-update API that allows authenticated company owners to write arbitrary files outside the intended extraction directory by supplying crafted ZIP archives with ../ sequences to the unzip endpoint. Attackers can exploit unsanitized ZIP entry names passed to PHP's ZipArchive::extractTo() to write arbitrary PHP files into …
M Alto vulnerabilidad
25/08/2026
[CVE-2026-68062] SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerabili…
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an …
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78677] GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers t…
GitPython before 3.1.59 omits --separate-git-dir from unsafe_git_clone_options, allowing attackers to create arbitrary git directories outside the intended clone destination. Attackers can pass a separate_git_dir parameter to Repo.clone_from() or Repo.clone() to redirect repository metadata to an attacker-controlled filesystem path, enabling arbitrary directory creation and potential hook executio…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-72695] Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that al…
Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with directory traversal sequences. The method validates only the basename portion of the filename while preserving unvalidated directory paths containing ../ sequences that are passed to unli…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-34968] Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the data…
Adminer before 5.4.3 contains an arbitrary file deletion vulnerability in SQLite mode where the database-list drop action fails to validate file extensions before deletion. An authenticated attacker can submit arbitrary relative file paths in the db[] parameter to delete any files writable by the PHP process.