Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 9 min
Buscando: "Ni" — 3219 resultados ✕ Limpiar búsqueda
13,539
Total alertas
3075
Críticas
10192
Altas
8
Ransomware
1758
Esta semana
RSS
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-78248] A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is…
A vulnerability was determined in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/ajax.php?action=save_settings. This manipulation of the argument Name causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-76847] act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actio…
act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or actions/download-artifact@v4. The control-plane RPCs of that backend, including CreateArtifact, GetSignedArtifactURL, ListArtifacts, FinalizeArtifact and DeleteArtifact, accept a caller-supplied workflow_run_backend_id and never check that it belongs to the requester: validateRunIDV4 in pkg/artifacts/art…
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-76841] Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before …
Xinference loads models with Hugging Face remote code execution unconditionally enabled, and before version 2.12.0 exposes no setting to disable it. Six loader call sites pass trust_remote_code=True as a literal or as an unconditional default: RerankModel._get_tokenizer in xinference/model/rerank/core.py, SentenceTransformerRerankModel.load in xinference/model/rerank/sentence_transformers/core.py,…
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-59565] A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on …
A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows.
M Alto vulnerabilidad Nuevo
Hace 8 horas
[CVE-2026-59566] A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected ver…
A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS.
M Alto vulnerabilidad Nuevo
Hace 9 horas
[CVE-2026-78247] A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affec…
A vulnerability was found in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown processing of the file /fos/admin/ajax.php?action=confirm_order. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad Nuevo
Hace 10 horas
Inyección SQL alta en itsourcecode Online Clinic Management System 1.0
Se ha identificado una vulnerabilidad de inyección SQL en el módulo de login administrativo (success/login.php) de itsourcecode Online Clinic Management System versión 1.0, permitiendo ejecución remota no autenticada mediante manipulación del parámetro Username. La vulnerabilidad ha sido divulgada públicamente (CVSS 7.3) y afecta directamente a clínicas y centros médicos en LATAM que utilizan este sistema para gestionar datos sensibles de pacientes.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad Nuevo
Hace 10 horas
Vulnerabilidad XSS sin autenticación en Urna versiones ≤2.6.2 (CVSS 7.1)
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación en Urna versiones 2.6.2 e inferiores que permite a atacantes inyectar código malicioso y comprometer sesiones de usuarios. Esta vulnerabilidad afecta especialmente a plataformas de votación y gestión electoral en organismos públicos y privados de LATAM. El riesgo es alto dado que no requiere credenciales previas para explotarse.
M Alto vulnerabilidad Nuevo
Hace 10 horas
Inclusión de archivos local sin autenticación en Måne <= 1.7 (CVE-2026-66670)
Se identificó una vulnerabilidad de inclusión de archivos local (LFI) sin autenticación en Måne versión 1.7 y anteriores, con CVSS 8.1. Un atacante remoto podría acceder a archivos sensibles del sistema sin credenciales. Afecta principalmente a organizaciones en LATAM que ejecuten esta aplicación en entornos accesibles por red.
M Alto vulnerabilidad Nuevo
Hace 10 horas
[CVE-2026-66584] XSS sin autenticación en 12 Step Meeting List <= 3.19.16
Se identificó una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación en el plugin 12 Step Meeting List en versiones hasta la 3.19.16, permitiendo a atacantes inyectar código malicioso que afecta a usuarios visitantes. Empresas en LATAM que administren sitios comunitarios, grupos de apoyo o directorios de reuniones con este plugin están expuestas a robo de sesiones, credenciales y datos sensibles. Con CVSS 7.1, representa un riesgo significativo si el sitio maneja información personal o transacciones.
M Alto vulnerabilidad Nuevo
Hace 10 horas
Vulnerabilidad XSS sin autenticación en WPComplete versiones <= 2.9.5.6
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación en el plugin WPComplete que afecta versiones hasta la 2.9.5.6. Esta falla permite a atacantes inyectar código malicioso en sitios WordPress expuestos, comprometiendo la integridad de datos y robando sesiones de administradores. Es especialmente alta para empresas LATAM con presencia digital en WordPress, plataforma dominante en la región.
M Alto vulnerabilidad Nuevo
Hace 10 horas
XSS no autenticado alta en Brave Conversion Engine (PRO) versiones ≤ 0.8.6
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación en Brave Conversion Engine (PRO) versiones 0.8.6 y anteriores, con CVSS 7.1. Esta falla permite a atacantes inyectar código malicioso que se ejecuta en navegadores de usuarios finales, comprometiendo sesiones y datos sensibles. Empresas en México y LATAM que utilizan esta herramienta para conversión de contenido o procesamiento de documentos están expuestas a ataques dirigidos y robo de credenciales.
M Alto vulnerabilidad Nuevo
Hace 10 horas
Eliminación arbitraria de archivos sin autenticación en ShopBuilder Pro ≤ 2.2.0
ShopBuilder Pro, extensión de Elementor para WooCommerce, presenta una vulnerabilidad alta (CVSS 8.6) que permite a atacantes no autenticados eliminar archivos arbitrarios del servidor. Afecta directamente a tiendas en línea y sitios de comercio electrónico en México y LATAM que utilizan versiones anteriores a 2.2.1. El riesgo es severo: pérdida de datos altas, degradación de servicios y potencial exposición de información sensible.
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-78245] A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_upl…
A flaw has been found in itsourcecode Online Pharmacy System 1.0. This affects the function move_uploaded_file of the file all_users/register.php of the component User Registration. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be launched remotely. The exploit has been published and may be used.
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-78244] A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this iss…
A vulnerability was detected in itsourcecode Real Estate Management System 1.0. Affected by this issue is some unknown functionality of the file search.php. Performing a manipulation of the argument search/delivery_type/search_price/property_type results in sql injection. The attack may be initiated remotely. The exploit is now public and may be used.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad Nuevo
Hace 11 horas
[CVE-2026-10582] Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRem…
Hugo's security.http.urls allowlist is the only control on outbound fetches made by resources.GetRemote, and it inspects the URL text alone. CheckAllowedHTTPURL in config/security/securityConfig.go applies the configured pattern list and then re-checks a canonicalised form of an integer, hex or octal IPv4 host, but it never resolves the hostname and never inspects the address the HTTP client actua…
M Alto vulnerabilidad Nuevo
Hace 12 horas
[CVE-2026-75931] fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input …
fast-uri is a URI parser for Node.js. It canonicalizes a host to its ASCII form only when the input carries an explicit scheme, so a scheme-relative reference such as a host preceded by two slashes is returned with its host verbatim and no error set. As a result fast-uri's own entry points disagree with each other: parse, resolve, normalize, and equal can yield different hosts for the same input d…
M Alto vulnerabilidad Nuevo
Hace 15 horas
[CVE-2026-78202] A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_setting…
A vulnerability was found in itsourcecode Payroll System 1.0. This affects the function save_settings of the file admin_class.php. The manipulation of the argument img results in unrestricted upload. The attack may be performed from remote. The exploit has been made public and could be used.
M Alto vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-78201] A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the funct…
A vulnerability has been found in itsourcecode Payroll System 1.0. The impacted element is the function Login of the file admin_class.php. The manipulation of the argument Username leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad Nuevo
Hace 16 horas
[CVE-2026-78199] A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is a…
A vulnerability was detected in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/view_prod.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.