Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Perl" — 223 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1764
Esta semana
RSS
M Alto vulnerabilidad
17/08/2026
[CVE-2026-74801] SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-lin…
SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper process. Attackers can create a malicious workspace directory with command metacharacters in its path and trigger the Microsoft Defender exclusion flow to execute arbitrary commands with administrator privileges after UAC approval.
M Alto vulnerabilidad
16/08/2026
[CVE-2024-58375] OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when u…
OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module sources, versions, and backend configurations. As a result, values marked as sensitive may be exposed through these configuration elements instead of producing an error. This is fixed in OpenTofu 1.8.3, which adds explicit errors to prevent the use of…
M Alto vulnerabilidad
16/08/2026
Vulnerabilidad alta de evasión de autorización en WP Travel Engine (CVE-2026-17087)
El plugin WP Travel Engine para WordPress (versiones ≤6.8.4) permite a atacantes no autenticados acceder a datos privados de reservas y facturación de clientes mediante evasión de controles de autorización. Esta vulnerabilidad afecta directamente a agencias de viajes, operadores turísticos y plataformas de booking en LATAM que utilizan este plugin para gestionar reservaciones y pagos.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-19768] Improper control of generation of code ('Code Injection') in the settings feature in Devolutions Pow…
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the settings configuration file.
M Alto vulnerabilidad
14/08/2026
[CVE-2026-15205] The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplie…
The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query within its public, unauthenticated payment callback, and performs this query before verifying the payment provider's HMAC signature. This allows unauthenticated attackers to perform SQL injection and read arbitrary data from the database — including user c…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72665] Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic …
Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Osquery and Elastic Defend response actions on managed hosts via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). A Kibana user who is able to author and evaluate Elastic Security detection rules can cause response actions to be carried out against enrolled agents without holding the Osquery live que…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-72629] Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-…
Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized cross-space access via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). The result is disclosure of inference output from a trained model in a different space that the user is not authorized to list, read, or use, which exposes the behavior of a model. The same pattern also reached the …

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
13/08/2026
[CVE-2026-18846] IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client dat…
IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the host servers, a remote attacker could leverage this vulnerability to cause a denial-of-server (DoS) for that server.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-63424] During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Ma…
During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-49478] Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC)…
Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discovery, allowing a malicious or compromised issuer to perform blind SSRF, substitute and cache malicious JWKS keys, or disclose ServiceAccount tokens to external hosts.…
M Alto vulnerabilidad
13/08/2026
[CVE-2026-14677] Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause…
Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl allows an object creator to cause the server to undersize an allocation and write out-of-bounds via crafted function bodies. This may execute arbitrary code as the operating system user running the database. CVE-2026-6473 had fixed similar problems. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
M Alto vulnerabilidad
13/08/2026
[CVE-2026-14670] Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute…
Heap buffer overflow in PostgreSQL plperl return of a tied hash allows the function owner to execute arbitrary code as the operating system user running the database, via a crafted function body. Versions before PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 are affected.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-71469] A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests …
A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique token creates a permanent entry in the unbounded tokenReviews cache, which is not properly cleared. This can lead to memory exhaustion of the search-api pod, resulting in a Denial of Service (DoS).
M Alto vulnerabilidad
12/08/2026
[CVE-2026-16033] A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unco…
A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image metadata templates, LXD fails to properly sanitize or restrict template file paths from escaping the instance templates directory (specifically affecting virtual machine / QEMU driver execution paths). An attacker can exploit this flaw by providing a cr…
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72798] SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeVie…
SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymous readers to access Relation and Rollup cell contents from hidden or password-protected databases. Attackers can request published databases that relate to restricted databases to retrieve sensitive content, or bypass row filtering entirely when the first column is a non-block ty…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
12/08/2026
[CVE-2026-72789] SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating the…
SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly accessible by default. Anonymous readers can enumerate and retrieve fully decrypted document content from unlocked encrypted notebooks through the publish API without authentication or key material.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-19566] Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via un…
Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length matching `(0|[1-9][0-9]*)` and passes it to _width2bits(), which builds the mask as `'1' x ($width + 8)`, one character per bit. The _inc() method then unpacks the packed mask into a Perl array of one scalar per byte, so the …
M Alto vulnerabilidad
12/08/2026
[CVE-2026-18789] The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content ex…
The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated attackers to trigger a server-side export of the site's database, including user password hashes and password reset tokens, as well as to persistently change some of its settings.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-16977] The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-contr…
The Form Maker by 10Web WordPress plugin before 1.15.45 does not properly parameterize a user-controlled value that is substituted into a dynamic SQL query built for a database-backed choice field, allowing subscriber-level users to perform second-order SQL injection.
M Alto vulnerabilidad
12/08/2026
[CVE-2026-13613] The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied para…
The KiviCare WordPress plugin before 4.5.2 does not properly sanitise and escape user-supplied parameters before using them in a SQL query, allowing authenticated users with a clinic staff-level role to perform SQL injection.