Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 42 min
Buscando: "Ui" — 2785 resultados ✕ Limpiar búsqueda
22,345
Total alertas
4745
Críticas
16970
Altas
8
Ransomware
1213
Esta semana
RSS
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85379] A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf4…
A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects the function ChapterModel::searchChapter of the file App/Home/Controller/ChapterController.class.php of the component Query Builder. The manipulation of the argument content results in sql injection. The attack can be launched remotely. The exploit ha…
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85451] MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSle…
MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can enumerate MOOS processes and send termination commands to trigger process shutdown by exploiting the default multicast group and port with the known passphrase.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85452] MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeG…
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply arbitrarily long MOOS identifiers that overflow the buffers when an operator selects process list entries or pokes variables, enabling code execution.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64197] There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied…
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64198] There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied …
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a few bytes past the end of an allocated heap buffer during file handling.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64199] There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied …
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read outside the bounds of an allocated data structure.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64200] There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied …
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data.   This results in a read a past the end of an allocated heap buffer during string conversion.  Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64195] There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-su…
There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-64196] There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied…
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file.  This issue affects all versions before 2026.0.0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-83959] Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in…
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84847] Unauthenticated Broken Access Control in Quick Event Manager <= 9.17 versions.
Unauthenticated Broken Access Control in Quick Event Manager
M Alto vulnerabilidad
03/09/2026
[CVE-2026-84848] Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager <= 9.17 versions.
Unauthenticated Cross Site Scripting (XSS) in Quick Event Manager
M Alto vulnerabilidad
03/09/2026
[CVE-2026-81776] Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX <= 3.8.8 versions.
Unauthenticated Cross Site Scripting (XSS) in WP QuickLaTeX
M Alto vulnerabilidad
03/09/2026
[CVE-2026-83961] ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege es…
ColdFusion is affected by an Improper Authentication vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain limited read and write access. The vulnerable component is restricted to an administrative network zone by default. Exploitation of this issue does not require user interaction. Scope is changed.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-55658] Gardens v2 is a modular governance framework that enables communities to create and manage multiple …
Gardens v2 is a modular governance framework that enables communities to create and manage multiple governance pools with customizable parameters and voting mechanisms. In 3e595f3 and prior, when a streaming proposal is funded, the cluster of streaming contracts moves real pool funds into the proposal's StreamingEscrow to back the Superfluid constant flow agreement (the CFA deposit, plus a 0.5 per…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-80741] In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix out-of-bounds read…
In the Linux kernel, the following vulnerability has been resolved: drm/log: Fix out-of-bounds read on empty message length drm_log_draw_kmsg_record() accesses s[len - 1] to strip the trailing newline, but len is unsigned int. If len is 0, the subtraction wraps to UINT_MAX, causing an out-of-bounds read. Add an early return when len is 0.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-76642] util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running …
util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation…
M Alto vulnerabilidad
03/09/2026
Vulnerabilidad en fast-uri permite validación incorrecta de autoridades en URL
fast-uri acepta hosts con corchetes de autoridad desbalanceados o mal posicionados sin generar error, lo que permite que URLs malformadas se procesen incorrectamente. Esto afecta aplicaciones Node.js que utilizan esta librería para parsear URLs, potencialmente permitiendo evasión de validaciones de seguridad en servidores web, proxies y clientes HTTP. El riesgo es alta en empresas LATAM que procesan URLs no confiables sin validación adicional.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-52831] Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4…
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container (/bin/sh, -c, ). Two fields in the trigger specification flow into this string without adequate sanitization: event.headers keys and event.body. This iss…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-52833] Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5…
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio's Java runtime generates a build.gradle file during function builds using Go's text/template package. The template renders runtimeAttributes.repositories[] values with the {{ . }} action, which performs no escaping. An attacker can embed a closing brace (}) to break out of the repositories …