Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54629] Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file…
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions. A remote attacker can use SQLite CREATE VIRTUAL TABLE statements to provide a local path to these modules, which use hashi…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90946] DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenti…
DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSocket endpoint that accepts repo_url as a filesystem path with no containment. Attackers can supply arbitrary directory paths to read all files with supported extensions including Python, JavaScript, YAML, and JSON files containing hardcoded secrets and credentials.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-90932] LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrad…
LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. CoreUpgradeController and BackupService (e.g. BackupService::deleteBackup()) concatenate the user-supplied backup_file/filename value directly onto the backup directory path without normalisation, without applying basename(), and without verifying that the resolved path remains in…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86751] Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing auth…
Snipe-IT before 8.7.0 fails to properly sanitize markdown image syntax in note fields, allowing authenticated users to read arbitrary server files and issue server-side HTTP requests. Attackers can submit markdown image syntax in checkout acceptance notes that survive HTML escaping, are expanded by CommonMark parser, and resolved by laravel-mail-auto-embed via file_get_contents or curl, exfiltrati…
M Alto vulnerabilidad
09/09/2026
[CVE-2026-86741] Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in …
Snipe-IT versions before 8.7.0 fail to sanitize the category EULA text field before rendering it in checkout confirmation emails. Attackers with low-privilege permissions can inject markdown image syntax or raw HTML img tags pointing to local files or remote URLs, which the mail auto-embed library resolves server-side and returns as email attachments, exfiltrating sensitive files like .env credent…
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad alta de traversal de rutas en SiYuan anterior a v3.8.2
SiYuan versiones anteriores a v3.8.2 contienen una vulnerabilidad de traversal de rutas en el endpoint /api/riff/removeRiffDeck que no valida correctamente el parámetro deckID. Un administrador autenticado puede explotar esta falla para eliminar archivos .deck y .cards arbitrarios fuera del directorio de trabajo, comprometiendo la integridad de bases de datos y repositorios documentales en empresas que utilizan esta herramienta colaborativa.
M Alto vulnerabilidad
09/09/2026
Vulnerabilidad alta en Dell SCG 5.0: control externo de rutas de archivo (CVE-2026-79692)
Dell SCG 5.0 Appliance (versiones anteriores a 5.36.00.16) y Dell SCG 5.0 Application (versiones anteriores a 5.36.00.00) contienen una vulnerabilidad de control externo de nombres/rutas de archivo (CWE-73). Un atacante remoto no autenticado puede explotar esta falla para acceder al sistema de archivos del servidor. Afecta principalmente a infraestructuras de almacenamiento en centros de datos de empresas medianas y grandes en LATAM que utilizan soluciones Dell para gestión de contenido.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69805] External control of file name or path in .NET allows an unauthorized attacker to elevate privileges …
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69383] External control of file name or path in Windows Shell allows an authorized attacker to elevate priv…
External control of file name or path in Windows Shell allows an authorized attacker to elevate privileges locally.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-69355] External control of file name or path in Microsoft Exchange Server allows an authorized attacker to …
External control of file name or path in Microsoft Exchange Server allows an authorized attacker to execute code over a network.
M Alto vulnerabilidad
08/09/2026
[CVE-2026-62804] External control of file name or path in Microsoft Office Word allows an unauthorized attacker to ex…
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to execute code locally.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-80118] PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics …
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a crash-dump-format (PAGEDU64) image of all physical memory to a caller-supplied file path in…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-80119] PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics …
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path to an exposed IOCTL. Attackers can issue a single IOCTL call to trigger the driver…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85687] surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the …
surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. Attackers can read any image or PDF file on the host by supplying arbitrary file paths to Image.open or pypdfium2.PdfDocument, obtaining rendered contents as base64 and using /info as an existence oracle.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85668] Xinference (affected commit 4a94832, v3.x) contains an unauthenticated arbitrary-path file read vuln…
Xinference (affected commit 4a94832, v3.x) contains an unauthenticated arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-register endpoint, which accepts a caller-supplied model_path parameter without authentication or path confinement. The endpoint reads and parses config.json, tokenizer_config.json, and chat_template.jinja files at the supplied path and reflects the parsed c…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85176] DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to…
DbGate fails to validate jslid parameters in the jsldata controller, allowing authenticated users to read and write arbitrary files via file:// scheme resolution. Attackers can exploit getJslFileName() to bypass directory containment and access sensitive files including encrypted database credentials stored in connections configuration.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85160] AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerabili…
AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token validation and unsanitized key parameter concatenation. Attackers can craft an image tag with a traversal payload like key=../../videos to trigger recursive deletion of the videos directory when an admin visit…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84478] WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allo…
WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter. Attackers can exploit this to destroy audit logs and probe for file existence on the server, with the vulnerability enabling both file deletion and information disclosure abo…
M Alto vulnerabilidad
01/09/2026
[CVE-2026-84374] Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, i…
Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled $destination supplied through Excel::store(), $export->store(), or storeExcel() against the process working directory with realpath() instead of the configured filesystem disk. If the path names an ex…
M Alto vulnerabilidad
31/08/2026
[CVE-2026-82393] pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a t…
pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped names. During pnpm install, the unvalidated name reaches raw path joins in pnpm11/installing/deps-resolver/src/resolvePeers.ts, pnpm11/installing/deps-re…