Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Aten" — 121 resultados ✕ Limpiar búsqueda
22,113
Total alertas
4677
Críticas
16848
Altas
8
Ransomware
1013
Esta semana
RSS
M Alto vulnerabilidad
21/09/2026
[CVE-2026-62182] KubeEdge is an open source system for extending native containerized application orchestration capab…
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/configupdatejob.go concatenates authenticated user-controlled updateFields values into the keadm config-update command and executes it through a system shell. A user wit…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-62371] KubeEdge is an open source system for extending native containerized application orchestration capab…
KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actions/nodeupgradejob.go concatenates authenticated user-controlled spec.version and spec.image values into the keadm upgrade edge shell command. A user with permissio…
M Alto vulnerabilidad
21/09/2026
[CVE-2026-55071] MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Pri…
MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command string without any validation or sanitization. An attacker who can invoke the MCP tool or the equivalent Python API can embed newline characters in the package argumen…
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de ejecución remota de código en plugin WP Photo Album Plus para WordPress
El plugin WP Photo Album Plus para WordPress es vulnerable a ejecución remota de código (RCE) en todas las versiones debido a sanitización insuficiente en nombres de archivo cargados. La vulnerabilidad reside en la función wppa_image_magick, donde escapeshellcmd() se aplica al comando completo en lugar de entrecomillar argumentos individuales antes de ejecutar comandos ImageMagick via exec(). Esto afecta directamente a sitios WordPress en México y Latinoamérica que dependen de este plugin para galerías de fotos.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-93591] SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt funct…
SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can inject SQL via inline HTML span tags in the getGraph endpoint to execute arbitrary queries on the read-write database and exfiltrate private data across n…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54647] CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php dir…
CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without numeric validation. An authenticated administrator can supply a comma-delimited value that changes the SET clause because HTML sanitization does not neutralize SQ…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-54612] Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stor…
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until 1.0.8.5, saveGlobalElements() in admin/controller/editor/global-trait.php concatenates the attacker-controlled file portion of data-v-save-global to the active theme directory before loadHTMLFile() and file_put_contents() operate on it. An authenticated user with the default Edi…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
16/09/2026
[CVE-2026-76425] A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQ…
A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements to an affected endp…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-55416] Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and groupby fields of a Custom Reports configuration processed by bundles/CustomReportsBundle/src/Tool/Adapter/Sql.php. The buildQueryString() method concatenates these val…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90932] LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrad…
LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation, without applying basename(), and without verifying that the resolved path remains in…
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad de control de acceso en NL Portal Backend Libraries permite acceso no autorizado a tareas
El paquete `nl.nl-portal:taak` (versiones 1.5.0 a 3.0.0) no valida correctamente la propiedad de tareas en la mutación GraphQL `submitTaakV2`, permitiendo a usuarios autenticados leer formularios de otros usuarios si conocen o adivinan su ID de tarea. Esta vulnerabilidad afecta sistemas de gobierno digital en portales de atención ciudadana que procesan información sensible de residentes, clientes y proveedores.
M Alto vulnerabilidad
11/09/2026
Vulnerabilidad XSS almacenado alta en AVideo plugin Bookmark (CVE-2026-89256)
AVideo contiene una vulnerabilidad de cross-site scripting (XSS) almacenado en el plugin Bookmark que permite a propietarios de videos inyectar código malicioso a través del parámetro de nombre de capítulo. Los nombres de capítulos no se codifican antes de insertarse en el HTML de la página pública, causando que todo visitante ejecute el payload en el origen de AVideo. Con CVSS 8.7, afecta plataformas de streaming y repositorios de video frecuentes en empresas e instituciones educativas de LATAM.
M Alto vulnerabilidad
10/09/2026
[CVE-2026-81210] IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String…
IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but DataStage job logs routinely carry connection strings, {dsnextenc} ciphertexts (decryptable via d2-f023), and customer-data ro…
M Alto vulnerabilidad
05/09/2026
[CVE-2026-52775] YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest developm…
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated user to inject arbitrary SQL via the {idreaction} and {id} URL path parameters. The parameters are concatenated directly into a SQL LIKE clause without escaping or parameterizatio…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85160] AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerabili…
AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visit…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/09/2026
CVE-2026-84292: Validación insuficiente de puerto en fast-uri permite inyección de autoridad
fast-uri no valida el componente de puerto al recomponer la autoridad de una URI, permitiendo que valores no numéricos inyecten delimitadores y redirijan la conexión a hosts controlados por atacantes. Esta vulnerabilidad afecta aplicaciones Node.js en producción que procesen URLs de fuentes no confiables, comprometiendo autenticación y enrutamiento en infraestructuras cloud de LATAM.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-14199] Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (syn…
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while th…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-75417] A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() func…
A SQL injection vulnerability was found in YzmCMS 7.5. The issue occurs in the get_arrchildid() function within application/admin/controller/category.class.php, where the user-controlled parentid parameter is concatenated directly into a FIND_IN_SET() SQL clause without proper sanitization. This allows an authenticated administrator to execute arbitrary SQL queries via boolean-based blind injectio…
M Alto vulnerabilidad
28/08/2026
[CVE-2026-54083] Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints an…
Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. The  ip-customblock  active response script contains a path traversal vulnerability that lets an attacker create or delete arbitrary files on the filesystem as root. The script builds a file path by concatenating the  srcip  field taken from alert JSON directly onto the fixed  /ip…
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79992] A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing mal…
A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution.