Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 5676 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100292] In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through …
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, a hidden debug interface can be enabled through an authenticated request, allowing additional commands to be sent to a backend service. Once active, this pathway can unintentionally expose system‑level functionality that could be misused if crafted inputs reach the underlying command handler.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100293] In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply…
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, both the local and cloud update mechanisms apply new firmware without any cryptographic verification, relying only on basic hashing. This design allows an attacker who can reach the update routine to introduce untrusted firmware images that the device will accept as valid.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-100294] In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credenti…
In Anjvision YSSD‑RTMP‑H5 firmware version 3.3.2.4, the firmware embeds hardcoded cloud‑API credentials that are shared across deployed devices. Anyone obtaining the public firmware package can reuse these values to interact with the cloud service in ways not intended for normal operation.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102827] simple-git, an interface for running git commands in any node.js application, enables applications t…
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin compares parsed option names with literal dangerous option spellings while Git accepts unambiguous long-option abbreviations. Attacker-influenced push arguments such as abbreviated --receive-pack or --e…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102826] simple-git, an interface for running git commands in any node.js application, enables applications t…
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. Prior to 4.0.0, the default blockUnsafeOperationsPlugin does not completely reject configuration includes supplied through customArgs to git.clone(). The missing include.path classification permits Git to load an attacker-controlled configuration file, and t…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102616] A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function g…
A vulnerability was detected in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component OAuth2 Resource Filter. Performing a manipulation of the argument year/processInstanceId results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The sink is in…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-84842] IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the…
IBM Guardium Data Protection 12.2 is vulnerable to path traversal and arbitrary file deletion in the Datasource REST component. An authenticated remote attacker could exploit this vulnerability to delete files and potentially cause denial of service or impact system integrity.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102810] Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by -…
Marmite through 0.4.2 contains a path traversal vulnerability in the development server started by --serve that allows unauthenticated attackers to read arbitrary files. The handle_request function in src/server.rs fails to reject .. segments after percent-decoding and joining the request path to the output folder, enabling attackers to request encoded traversal sequences to access files readable …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102811] Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite…
Marmite through 0.4.2 contains missing authentication in the development server endpoints /__marmite__/content, /__marmite__/config, and /__marmite__/file/, allowing unauthenticated attackers to create, modify, and overwrite site content and configuration. Attackers can exploit unsanitized path parameters in handle_create_content and handle_clone_content to write files outside the project director…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102555] A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data…
A flaw was found in libsoup. The soup_uri_decode_data_uri() function incorrectly treated base64 data-URI payloads as NUL-terminated strings when calling g_base64_decode_inplace(). If the percent-decoded payload contained embedded NUL bytes, the decoded length could remain uninitialized and be used as the size of the returned GBytes. This can lead to an out-of-bounds read or application crash when …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102697] Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experim…
Ollama versions 0.14.0 before 0.31.2 contain an incorrect authorization vulnerability in the experimental agent mode Bash tool approval mechanism that fails to properly parse shell syntax. Attackers who can influence model output through prompt injection can execute additional shell commands by appending control operators like semicolons or logical operators to approved commands, bypassing the ses…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102676] Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and C…
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-92370] An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modul…
An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuratio…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-92371] TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation v…
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-92369] TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in…
TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of th…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-19743] Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Lin…
Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local pr…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102600] Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @s…
Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 0.1.1, @socket.io/cluster-engine uses inherited object properties when looking up attacker-controlled session IDs in clustered deployments. Special property names such as __proto__ or constructor can resolve through the object prototype chain instead of identifying an actual connected client, causing the Nod…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-86035] Weblate is a web-based continuous localization platform used to manage software translations. Weblat…
Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interpreted as Mercurial options instead of literal paths. An authenticated user with project-scoped component.edit permission could exploit this through a …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-65102] NVIDIA DeepStream contains a vulnerability where an attacker could cause an integer overflow by sup…
NVIDIA DeepStream contains a vulnerability where an attacker could cause an integer overflow by supplying crafted tensor dimensions in a YAML configuration file. A successful exploit of this vulnerability might lead to denial of service, information disclosure, data tampering.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102491] A vulnerability was identified in mahonelau kykms up to 8f130c2d85842d5b44caae78cc46d65e505949f7. Th…
A vulnerability was identified in mahonelau kykms up to 8f130c2d85842d5b44caae78cc46d65e505949f7. The impacted element is the function QueryGenerator.doMultiFieldsOrder of the file QueryGenerator.java of the component SqlInjectionUtil. The manipulation of the argument column leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. …