Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 2 horas
Buscando: "X" — 12527 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1208
Esta semana
RSS
M Alto vulnerabilidad
03/10/2026
[CVE-2026-101928] The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Script…
The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is p…
M Alto vulnerabilidad
03/10/2026
[CVE-2026-92977] The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored …
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Maliciou…
M Alto vulnerabilidad
03/10/2026
[CVE-2026-97644] The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Pr…
The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Privilege Escalation via Contact Identity Rebinding in all versions up to, and including, 4.9 The vulnerability exists because the `create_contact` function in the v3 REST endpoint (`POST /gh/v3/contacts`) is gated solely by the `add_contacts` capability and forwards the full request payload — includi…
M Alto vulnerabilidad
03/10/2026
[CVE-2026-92536] The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict C…
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract other users' email addres…
M Alto vulnerabilidad
03/10/2026
[CVE-2026-104478] Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authe…
Formwork before 2.3.13 contains a path traversal vulnerability in BackupController that allows authenticated panel users to read or delete arbitrary files. Attackers with backup download or delete permission can supply a base64-encoded backslash-separated traversal payload that bypasses PHP basename on Linux to access files outside the backup directory.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-94591] Armatura One stores database and message-broker credentials in an install configuration file, encryp…
Armatura One stores database and message-broker credentials in an install configuration file, encrypting them with AES-128-CBC when this protection is enabled. The encryption key and initialization vector are fixed values embedded in the software itself and are identical across every installation. An attacker with a copy of the installation package can recover this key and initialization vector, a…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-94592] Armatura One's database initialization routine assigns a fixed, vendor-defined password to the datab…
Armatura One's database initialization routine assigns a fixed, vendor-defined password to the database superuser account at creation time, rather than generating a unique password per installation. An individual with access to the server operating system and knowledge of this value can authenticate as the database superuser on a deployment where it has not been changed.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
02/10/2026
[CVE-2026-94593] Armatura One's backup and restore routine records the full database connection command, including th…
Armatura One's backup and restore routine records the full database connection command, including the superuser password, in plain text in a log file on the host. Credentials disclosed by this finding can be used to access the database when access to the server operating system is available.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-82044] UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticat…
UTMStack before 11.2.16 contains a server-side request forgery vulnerability that allows authenticated attackers to make the server request arbitrary internal resources by supplying an unvalidated url parameter to the PdfService.downloadPdf() method exposed via GET /api/generate-pdf-report. Attackers can leverage this to force the web-pdf microservice to fetch internal backend endpoints, the OpenS…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-82039] UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBu…
UTMStack before 11.2.16 contains a SQL injection vulnerability in UtmAssetGroupService.searchQueryBuilder() that allows authenticated attackers to inject arbitrary SQL by supplying malicious assetType and groupName values that are inserted unsanitized into a native PostgreSQL query via String.format(). Attackers can exploit the GET /api/utm-asset-groups/searchGroupsByFilter endpoint to execute arb…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-96940] Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileg…
Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
M Alto vulnerabilidad
02/10/2026
[CVE-2020-37278] Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote att…
Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host system by supplying a file: URL to the downloadUrl parameter of the saveYZJFile endpoint. Attackers can exploit this flaw to read sensitive files such as /etc/passwd or configuration and credential files, and the same endpoint's support for http(s) URLs a…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104861] probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/pars…
probe-image-size gets image dimensions without downloading the entire file. Prior to 7.4.0, lib/parse_sync/svg.js and lib/parse_stream/svg.js use the searching regular expression /]*>/, which repeatedly scans to the end of input when attacker-controlled data contains many less-than characters without a closing greater-than character. The synchronous parser converts and scans the…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-67989] crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular…
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in Mistral model capability matching on Ruby 3.1.x
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104845] Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify cap…
Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.6.3, deserializeTypedArray in fromJSON and fromCrossJSON trusts a deserialized source value as an ArrayBuffer and does not bound the serialized element count. An attacker can provide a small untrusted JSON object with a large length value, causing the array-like TypedArray cons…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103622] Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute a…
Use after free in SVG in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
02/10/2026
[CVE-2026-103625] Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute ar…
Type confusion in V8 in Google Chrome prior to 154.0.8037.97 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104637] A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473…
A weakness has been identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. The affected element is the function add_patient/add_physician/add_account/update_account/update_subaccount/edit_physician/edit_patient of the file php/controller.php. Executing a manipulation of the argument img can lead to unrestricted upload. The attack may be launched remo…
M Alto vulnerabilidad
02/10/2026
[CVE-2026-104026] In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git …
In Sapling SCM prior to v0.2.20260929-102736, control characters were allowed to be embedded in Git subtree URLs. A maliciously constructed repository, if cloned by a target, could trigger code execution on otherwise read-only actions such as sl log/blame/annotate.
M Alto vulnerabilidad
02/10/2026
[CVE-2026-94422] An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an a…
An incorrect implementation of message filtering in xdg-dbus-proxy versions before 0.1.9 allows an attacker to bypass the intended message filtering on the D-Bus session bus by setting a reply serial number on non-reply messages. A malicious or compromised Flatpak app could use this to achieve arbitrary code execution outside its sandbox. xdg-dbus-proxy was designed to be part of the sandbox bound…