Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
22,093
Total alertas
4671
Críticas
16834
Altas
8
Ransomware
1017
Esta semana
RSS
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100707] Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespac…
Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to inconsistent path interpretation between validation and execution. A low-privilege tenant can use percent-encoded dot-segments in urlPath to bypass namespace checks and read resources from other namespaces using the Kyverno admission controller's ServiceAccount credentials…
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100682] Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload …
Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extracts user-supplied ZIP archives without proper symlink validation. Attackers with BUILDER role can craft a malicious ZIP with leaf symlink entries followed by duplicate file entries to write arbitrary files as root, enabling remote code execution.
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100636] SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoi…
SiYuan versions before v3.8.4 contain a path traversal vulnerability in the exportBrowserHTML endpoint that allows authenticated administrators to write arbitrary HTML content to index.html outside the workspace directory. Attackers can supply a folder parameter with directory traversal sequences to escape the export directory and overwrite index.html in any pre-existing kernel-writable location, …
M Alto vulnerabilidad
26/09/2026
[CVE-2026-100520] Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/uploa…
Laranode versions before 1.2.1 contain a path traversal vulnerability in the POST /filemanager/upload-file endpoint that allows authenticated users to write arbitrary files outside their home directory. Attackers can supply directory traversal sequences in the path parameter to write PHP files into other tenants' web roots and execute code as those tenants.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-100372] ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor…
ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authenticated administrators to overwrite PHP files by supplying directory traversal sequences in the folder parameter. Attackers with manage_template_access permission can traverse outside the layout directory to modify executable PHP files and achieve remote code execution as the web …
M Alto vulnerabilidad
25/09/2026
[CVE-2026-49850] InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. …
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POST and validating a CSRF token. When an authenticated administrator loads attacker-controlled content that requests an affected route, the application can delete an…
M Alto vulnerabilidad
25/09/2026
[CVE-2026-50547] InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. …
InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the XMLconfigs helper directory and includes the resulting PHP path without validating the identifier. A low-privileged attacker who can influence the e-invoice configuration can use traversal sequenc…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
25/09/2026
[CVE-2026-84882] IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle …
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload component. An authenticated remote attacker could exploit this vulnerability to write arbitrary files to the system.
M Alto vulnerabilidad
25/09/2026
[CVE-2026-85029] IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, del…
IBM Guardium Data Protection 12.2 could allow a remote attacker to obtain sensitive information, delete arbitrary files, or execute arbitrary code due to improper limitation of a pathname to a restricted directory.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-48070] Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated…
Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store attacker-controlled avatarUrl values that are later reused by avatar cleanup without confinement to the intended directory on local-storage deployments. A low-privileged user can cause deletion of arbitrary local files or directories reachable by the Docmost service account. This is…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-91123] Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0…
Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src traversal guard did not treat literal backslashes as path separators after decoded dot segments. A crafted source could therefore pass an allowed_iframes subpath check while browser URL normalization moved the iframe outside the intended allowed path. The resulting iframe could load…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-90959] A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' pa…
A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file repository privileges to specify a local file URL for Pulp to download and store. A URL scheme validation check uses a string prefix comparison that only rejects URLs beginning with 'file://', but Python's URL parser recognizes the 'file:' scheme without double sl…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-82094] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse …
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the system due to improper limitation of a pathname to a restricted directory.
M Alto vulnerabilidad
24/09/2026
[CVE-2026-81547] IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute a…
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to path traversal.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad de Path Traversal alta en plugin eesy_ID2WP para WordPress
El plugin eesy_ID2WP – Publish InDesign HTML5 en todas sus versiones hasta la 1.0.3 contiene una vulnerabilidad de recorrido de directorios (Path Traversal) a través del parámetro `id2wp_path` que permite a atacantes no autenticados leer archivos arbitrarios del servidor. Esto expone credenciales de bases de datos, configuraciones sensibles y datos de clientes en sitios WordPress de empresas mexicanas y latinoamericanas que utilizan este plugin. Con CVSS 7.5, representa riesgo significativo para negocios digitales y agencias que publican contenido desde Adobe InDesign.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta en MasterStudy LMS permite ejecución de código PHP arbitrario
El plugin MasterStudy LMS para WordPress anterior a la versión 3.7.50 no valida correctamente los parámetros de configuración de estilo de visualización, permitiendo que usuarios con rol de Colaborador o superior incluyan y ejecuten archivos PHP arbitrarios en el servidor. Esta vulnerabilidad afecta principalmente a instituciones educativas y plataformas de capacitación en LATAM que utilizan este plugin para gestión de cursos en línea, comprometiendo la confidencialidad e integridad de datos de estudiantes y contenido académico.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta de traversal de directorios en ShopXO hasta versión 2.2.7
Se detectó una vulnerabilidad de traversal de directorios en ShopXO versión 2.2.7 y anteriores en el componente Ueditor Upload Interface (archivo config/ueditor.php). Un atacante remoto puede manipular el parámetro path_type para acceder a archivos fuera del directorio permitido. El exploit es público y activo; afecta directamente a plataformas de comercio electrónico en LATAM que utilizan este CMS.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-75887] A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal …
A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against …
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96275] A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary loc…
A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91801] A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resource…
A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution.