Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Multiple Vendors" — 13275 resultados ✕ Limpiar búsqueda
22,340
Total alertas
4744
Críticas
16966
Altas
8
Ransomware
1210
Esta semana
RSS
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-104974] Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deact…
Plane is an open-source project management tool. Prior to 1.4.0, a user whose account has been deactivated by setting is_active=False can still log in with existing credentials. Successful authentication silently changes is_active back to True, reactivating the account without notifying the administrator. This issue is fixed in 1.4.0.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-104975] Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints i…
Plane is an open-source project management tool. Prior to 1.4.0, Plane's dashboard asset endpoints in plane/app/views/asset/v2.py were remediated for two cross-tenant asset IDORs, CVE-2026-27705 and CVE-2026-46558. Those fixes added a membership check and project_id and workspace__slug scoping to the asset endpoints in that file. The Spaces app in plane/space/views/asset.py serves related public-b…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-104905] FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::…
FacturaScripts before version 2026.7 contains a PHP object injection vulnerability in WidgetSelect::processFormData() that allows authenticated attackers to trigger unserialize() on raw POST data without an allowed_classes filter for multiple-select fields. Attackers can submit a serialized XLSXWriter object as the field value to invoke its __destruct() method, deleting arbitrary attacker-specifie…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-101919] A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configurat…
A flaw was found in the HyperShift operator. The operator copies user-provided Kubernetes configuration (kubeconfig) secrets directly into the privileged control plane namespace without proper validation or sanitization. An authenticated user with cluster and secret creation permissions can exploit this vulnerability by supplying a configuration containing unauthorized executable plugins. When dow…
M Alto vulnerabilidad
Hace 5 días
[CVE-2025-15643] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i…
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Jose Fernandez Adsmonetizer adsensei-b30 allows Reflected XSS.This issue affects Adsmonetizer: from n/a through 3.2.4.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105382] A flaw has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699d…
A flaw has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This affects the function update_subaccount of the file php/controller.php of the component Account Administration. This manipulation of the argument user_id causes improper authorization. Remote exploitation of the attack is possible. The exploit has been published and may be used. Th…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-105383] A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473…
A vulnerability has been found in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. This impacts an unknown function of the file php/controller.php. Such manipulation of the argument transaction_idS leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This product implements a rolling relea…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-12171] auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-change…
auto-changelog before 2.6.1 merges configuration from inside the target repository (the .auto-changelog file and the auto-changelog key in package.json) into its options, and honors security-sensitive options from that untrusted source. The handlebarsSetup option is passed to require(), so running auto-changelog over attacker-controlled repository content (for example, in a CI workflow that checks…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-104970] Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint …
Plane is an open-source project management tool. From 0.13 until 1.4.0, InstanceAdminSignUpEndpoint in apps/api/plane/license/api/views/admin.py:89-117, 173-229 uses InstanceAdmin.objects.first() for the first-admin check and performs account creation without an atomic transaction, row lock, uniqueness guard, or advisory lock. Two concurrent unauthenticated requests with different email addresses …
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-102282] adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1,…
adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, adm-zip applies the Unix permission bits stored in a zip entry directly to the extracted file via `fs.chmodSync()` when `keepOriginalPermission=true` is passed to `extractAllTo()`/`extractEntryTo()` — and it never filters the setuid/setgid/sticky bits out of those bits. A zip crafted by an attacker…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-104890] Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7…
Kunstmaan CMS is an open source content management system based on the Symfony framework. Prior to 7.3.2, src/Kunstmaan/MediaBundle/Helper/File/FileHandler.php performs the blacklisted_extensions check case-sensitively in FileHandler::getFilePath and lowercases the stored extension afterward. An authenticated backend user with media access can upload a mixed-case executable extension such as PHP t…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-104891] mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @in…
mppx-condition-gate provides conditional free-access wrappers for mppx payment methods. Prior to @insumermodel/mppx-condition-gate 3.0.0 and @insumermodel/mppx-token-gate 1.0.4, the packages read a wallet address from the client-supplied credential.source, checked whether that public address met configured on-chain conditions, and returned a successful free-access receipt without invoking the wrap…
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-92931] CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package ver…
CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially exposing sensitive information.
M Alto vulnerabilidad
Hace 5 días
[CVE-2026-77805] In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrit…
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose certificate subject name matches a broad allow list of publisher name fragments, rather t…
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta de autenticación en Casdoor hasta versión 3.161.1
Se detectó una vulnerabilidad en la función ApiFilter del componente API Endpoint de Casdoor (versiones hasta 3.161.1) que permite eludir mecanismos de autenticación mediante manipulación remota. El exploit es público y activo. Esta falla afecta directamente a sistemas de gestión de identidades y acceso en empresas latinoamericanas, exponiendo APIs internas a acceso no autorizado.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta de SSRF en feelec-yishu feelcrm-os 1.0.0
Se identificó una vulnerabilidad de Server-Side Request Forgery (SSRF) en feelcrm-os versión 1.0.0 que permite manipular el parámetro URL en el endpoint getCurlData del controlador GoogleController.class.php. Un atacante remoto puede ejecutar solicitudes no autorizadas desde el servidor afectado hacia sistemas internos o externos, comprometiendo la confidencialidad de datos y la integridad de la infraestructura. El exploit ha sido divulgado públicamente, elevando significativamente el riesgo para empresas mexicanas y latinoamericanas que utilicen este CRM.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta en controlador i3c afecta validación de memoria del sistema
Se ha identificado una vulnerabilidad en el verificador de llamadas al sistema para i3c_do_ccc() en drivers/i3c/i3c_handlers.c que no valida correctamente los búferes de datos por destino en la estructura i3c_ccc_target_payload. Un atacante local podría explotar esta deficiencia para acceder o modificar memoria del kernel, afectando sistemas embebidos e IoT industriales comúnmente desplegados en infraestructura alta de LATAM.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad alta en controlador NXP GAU ADC permite desbordamiento de búfer
El controlador ADC (conversor analógico-digital) GAU de NXP contiene un defecto de validación en la gestión de tamaño de búfer que puede permitir desbordamientos de memoria. La vulnerabilidad afecta sistemas embebidos y dispositivos IoT que utilicen este controlador, siendo especialmente relevante en infraestructura industrial y de automatización en LATAM. Con CVSS 8.4, representa un riesgo alto para integridad y disponibilidad de sistemas altas.
M Alto vulnerabilidad
Hace 5 días
SQL Injection alta en itsourcecode Online Admission System 1.0 expone datos de admisiones
Se identificó una vulnerabilidad de inyección SQL en el archivo /admin/login1.php del sistema de admisiones en línea itsourcecode versión 1.0, permitiendo a atacantes remotos manipular el parámetro User para acceder no autorizado a bases de datos. Esta falla afecta directamente a instituciones educativas en LATAM que utilizan esta solución para gestionar procesos de admisión de estudiantes. El exploit ha sido públicamente divulgado, elevando significativamente el riesgo de explotación inmediata.
M Alto vulnerabilidad
Hace 5 días
Vulnerabilidad CSRF alta en Blubrry PowerPress Podcasting hasta versión 11.17.9
Se ha identificado una vulnerabilidad de Falsificación de Solicitud Entre Sitios (CSRF) en el plugin Blubrry PowerPress Podcasting para WordPress que afecta versiones hasta 11.17.9. Esta falla permite a atacantes ejecutar acciones no autorizadas en plataformas de podcasting, incluyendo modificación de contenido y configuraciones administrativas. Es especialmente alta para medios, productoras de contenido y plataformas de distribución de audio en LATAM que utilizan este plugin.