Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1023
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102116] -A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to …
-A weakness could have allowed an authenticated Kiteworks Email Protection Gateway administrator to write a file outside its intended location and cause the application to execute it, potentially resulting in remote code execution as the underlying service account.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102119] A path traversal weakness in an optional, non-default administrative feature allowed an authenticate…
A path traversal weakness in an optional, non-default administrative feature allowed an authenticated administrator to move files to unintended locations outside the feature's designated directory. This could potentially be leveraged to execute arbitrary code on the underlying system.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102097] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kite…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to Remote Code Execution. Kiteworks Email Protection Gateway allowed an authenticated administrator to import configuration whose contents were not sufficiently validated before being processed. A crafted submission could potentially allow arbitrary commands to be executed on the affected gateway.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102099] Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction o…
Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the appliance. Exploitation requires an existing, authenticated administrat…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102089] Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness i…
Kiteworks Email Protection Gateway before version 9.5.0 is vulnerable to a path traversal weakness in an administrative import function allowed an authenticated administrator to write files to arbitrary locations on the server. This could potentially be leveraged to execute arbitrary code on the underlying system.
M Alto vulnerabilidad
30/09/2026
[CVE-2023-54403] Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemailda…
Yonyou U8 CRM before V16.5 and V18 contains an arbitrary file read vulnerability in /ajax/getemaildata.php that allows unauthenticated attackers to bypass authentication using the DontCheckLogin=1 parameter and read arbitrary files via an unvalidated filePath parameter. Attackers can exploit this flaw to read sensitive files outside the web application directory, including configuration files cont…
M Alto vulnerabilidad
30/09/2026
[CVE-2024-58387] Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/…
Inspur Haiyue HCM Cloud contains an arbitrary file read vulnerability in the /api/model_report/file/download endpoint that allows unauthenticated remote attackers to read arbitrary files by supplying unvalidated path parameters index and ext. Attackers can craft requests such as /api/model_report/file/download?index=/&ext= to traverse the filesystem and disclose sensitive files including /et…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-101885] ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerabilit…
ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-101295] Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirrori…
Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the intended destination directory.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94123] Unauthenticated Arbitrary File Download in NextGEN Gallery <= 4.5.0 versions.
Unauthenticated Arbitrary File Download in NextGEN Gallery
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad alta de Directory Traversal en Plugin Product Designer App para WordPress (CVE-2026-75098)
El plugin Product Designer App para WordPress en versiones hasta 1.1.3 es vulnerable a Directory Traversal a través del parámetro 'svg', permitiendo a atacantes no autenticados leer archivos arbitrarios del servidor. Esta vulnerabilidad expone información sensible como credenciales de bases de datos, archivos de configuración y datos de usuarios en tiendas virtuales y sitios corporativos. El ataque requiere solo acceso a internet sin credenciales válidas, representando riesgo alta para e-commerce y plataformas en LATAM.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102875] VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader tha…
VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84842] IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the…
IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84421] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of paths during archive extraction.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102810] Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by -…
Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request function in src/server.rs fails to reject .. segments after percent-decoding and joining the request path to the output folder, enabling attackers to request encoded traversal sequences to access files readable …

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-19743] Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Lin…
Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local pr…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-90925] Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Inno…
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign SIEM allows Path Traversal. This issue affects Logsign SIEM: from 6.4.101 before 6.4.117.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101066] A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLin…
A vulnerability was determined in dbgate up to 7.3.1. The impacted element is the function createLink of the file packages/api/src/controllers/archive.js of the component Archive Link Creation. This manipulation of the argument linkedFolder causes path traversal. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about …
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101067] A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the funct…
A vulnerability was identified in dbgate up to 6.8.1/7.0.2/7.1.8/7.2.5/7.3.1. This affects the function saveUploadedFile of the file files.js of the component save-uploaded-file Endpoint. Such manipulation of the argument filePath/fileName leads to path traversal. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this dis…
M Alto vulnerabilidad
27/09/2026
[CVE-2026-101044] pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.…
pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and