Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 2785 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
15/09/2026
Vulnerabilidad alta de inyección de comandos en PraisonAI (CVE-2026-57133)
PraisonAI versiones 1.5.1 a 1.7.2 contienen una vulnerabilidad de inyección de comandos en la función shell() que permite eludir validaciones de lista blanca. Un atacante puede ejecutar comandos arbitrarios prefijando su payload con un comando permitido. Afecta especialmente a equipos que utilizan PraisonAI en pipelines de automatización altas en empresas de tecnología, fintech y servicios en LATAM.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-57135] PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mo…
PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, SandboxExecutor network-isolated mode in src/praisonai-ts/src/cli/features/sandbox-executor.ts uses buildEnv() only to inject invalid http_proxy and https_proxy environment variables and does not establish an operating-system network boundary. Programs that ignore those proxy variables can open sockets directly, allowing supposedly i…
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90880] A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function s…
A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cgi-bin/New_GUI/Set/Diagnostics.asp of the component Diagnostics. Performing a manipulation of the argument Addr results in command injection. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90876] A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by th…
A vulnerability has been found in SourceCodester Online Faculty Clearance System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_requirement.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
15/09/2026
[CVE-2026-90877] A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this is…
A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. Affected by this issue is some unknown functionality of the file /update_requirement_status.php. The manipulation of the argument haydi results in sql injection. It is possible to launch the attack remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-91143] goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allo…
goproxy through 15.3 fails to apply HTTP proxy basic authentication to CONNECT tunnel requests, allowing unauthenticated clients to bypass credential requirements. Attackers can issue CONNECT requests to establish tunnels through the authenticated proxy without providing credentials, enabling arbitrary TCP traffic relay and access to restricted destinations.
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54628] Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-…
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes URL-capable SQLite virtual table modules such as json_reader and log_reader through its unauthenticated MySQL-compatible server port without restricting outbound destinations. A remote attacker can provide a loopback, private-network, or link-local cloud metadata URL, causing go-getter in the Anyquery s…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54629] Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file…
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, anyquery server exposes file-backed SQLite virtual table modules such as csv_reader and log_reader through its MySQL-compatible server port without authentication, authorization, or directory restrictions. A remote attacker can use SQLite CREATE VIRTUAL TABLE statements to provide a local path to these modules, which use hashi…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-47253] Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugi…
Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, the clear_plugin_cache(plugin) SQL scalar function in namespace/other_functions.go passes the caller-controlled plugin parameter through path.Join to os.RemoveAll without rejecting traversal segments. A low-privileged bearer-token holder can invoke the function through the /v1/query HTTP endpoint, causing path.Join to resolve …
M Alto vulnerabilidad
14/09/2026
[CVE-2026-73494] blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0…
blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.0-M1 until 1.0.0-M42, five HTTP/1.1 conformance laxities in the hand-written Java parser under http/src/main/java/org/http4s/blaze/http/parser/ can cause blaze to derive a different request boundary than a stricter fronting intermediary. A default BlazeServerBuilder accepts inval…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54180] backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of …
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.38, the Update, Delete, and Reorder operations resolve records from the unscoped model query instead of the query configured through addClause() or addBaseClause(). An authenticated user who knows or…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54182] backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of …
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 4.1.70, 5.6.2, 6.8.13, and 7.0.36, Backpack\CRUD\Stats::makeCurlRequest in src/Stats.php is reached from BackpackServiceProvider::boot() and constructs a shell command with a URL influenced by the HTTP Host header, which i…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54175] backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of …
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.11 and 7.0.34, MyAccountController::postAccountInfoForm in src/app/Http/Controllers/MyAccountController.php at POST /admin/edit-account-info passes request data from $request->except(['_token']) to the user model inste…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-54178] backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of …
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Prior to 6.8.12 and 7.0.35, HasUploadFields::uploadMultipleFilesToDisk in src/app/Models/Traits/HasUploadFields.php trusts disk-relative paths from clear_[] and passes them to Storage::disk()->delete without confirming t…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-19499] Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of th…
Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the int…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
14/09/2026
[CVE-2026-55416] Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticated user with reports_config permission can place attacker-controlled SQL fragments in the sql, from, where, and groupby fields of a Custom Reports configuration processed by bundles/CustomReportsBundle/src/Tool/Adapter/Sql.php. The buildQueryString() method concatenates these val…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-55072] Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated…
Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objects permission can submit a malicious ClassDefinition UID because the name and ID validation expressions in models/DataObject/ClassDefinition.php validate only the beginning of each value. When a data object of that class containing a Block field is loaded, Block::load in models/D…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82427] Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each b…
Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervisor localises. That name was used to build a path under the topology's working directory without normalisation, in both `AsyncLocalizer` and `Container.createBlobstoreLinks`, and the symlink helper force-deletes whatever already exists at the target before creating the link. A s…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82429] Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker di…
Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking the tree with FTS and calling `lchown` and `chmod` on each entry's full pathname while running with an effective uid of 0. Both syscalls re-resolve the path at the time of the call, after FTS has classified the entry, and the trees being walked are owned and writable by the untr…
M Alto vulnerabilidad
14/09/2026
[CVE-2026-82430] Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes …
Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the entire worker directory to the untrusted topology user, and only afterwards reads and acts on the command file that the supervisor wrote into that same directory. The file is opened without `O_NOFOLLOW` and without re-verifying its owner, so between the ownership change and the read…