Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 5706 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta en GIMP: ejecución de código remoto mediante archivos GIMPressionist
Se identificó una falla en el procesamiento de archivos de preajustes GIMPressionist en GIMP que permite escritura fuera de límites de memoria. Un atacante podría distribuir archivos maliciosos disfrazados de preajustes legítimos, logrando corrupción de memoria, bloqueos del sistema o ejecución de código arbitrario en equipos de diseñadores y desarrolladores en empresas LATAM. El CVSS 7.8 indica riesgo alto con exposición práctica.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad de Path Traversal alta en plugin eesy_ID2WP para WordPress
El plugin eesy_ID2WP – Publish InDesign HTML5 en todas sus versiones hasta la 1.0.3 contiene una vulnerabilidad de recorrido de directorios (Path Traversal) a través del parámetro `id2wp_path` que permite a atacantes no autenticados leer archivos arbitrarios del servidor. Esto expone credenciales de bases de datos, configuraciones sensibles y datos de clientes en sitios WordPress de empresas mexicanas y latinoamericanas que utilizan este plugin. Con CVSS 7.5, representa riesgo significativo para negocios digitales y agencias que publican contenido desde Adobe InDesign.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta en MasterStudy LMS permite ejecución de código PHP arbitrario
El plugin MasterStudy LMS para WordPress anterior a la versión 3.7.50 no valida correctamente los parámetros de configuración de estilo de visualización, permitiendo que usuarios con rol de Colaborador o superior incluyan y ejecuten archivos PHP arbitrarios en el servidor. Esta vulnerabilidad afecta principalmente a instituciones educativas y plataformas de capacitación en LATAM que utilizan este plugin para gestión de cursos en línea, comprometiendo la confidencialidad e integridad de datos de estudiantes y contenido académico.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad de deserialización en plugin wpForo Forum WordPress anterior a v3.1.6
El plugin wpForo Forum para WordPress anterior a la versión 3.1.6 permite a usuarios autenticados con nivel Subscriber o superior inyectar objetos PHP maliciosos mediante campos de perfil sin validar durante la deserialización. La vulnerabilidad se amplifica si otros plugins wpForo instalados contienen cadenas de Property-Oriented Programming (POP) que pueden ser explotadas para ejecución de código remoto. Afecta principalmente a sitios empresariales en LATAM que utilizan este plugin para comunidades o foros internos.
M Alto vulnerabilidad
24/09/2026
Vulnerabilidad alta de traversal de directorios en ShopXO hasta versión 2.2.7
Se detectó una vulnerabilidad de traversal de directorios en ShopXO versión 2.2.7 y anteriores en el componente Ueditor Upload Interface (archivo config/ueditor.php). Un atacante remoto puede manipular el parámetro path_type para acceder a archivos fuera del directorio permitido. El exploit es público y activo; afecta directamente a plataformas de comercio electrónico en LATAM que utilizan este CMS.
M Alto vulnerabilidad
24/09/2026
SigNoz v0.8.0 a v0.142.x: Secreto JWT vacío permite falsificación de tokens de sesión
SigNoz anterior a la versión 0.143.0 configura por defecto una clave HMAC vacía para firmar tokens JWT, permitiendo que un atacante forge tokens de sesión sin autenticación válida. Afecta a despliegues que no definen explícitamente SIGNOZ_TOKENIZER_JWT_SECRET o SIGNOZ_JWT_SECRET. La validación de configuración no rechaza valores vacíos, comprometiendo la integridad de sesiones en plataformas de observabilidad y monitoreo.
M Alto vulnerabilidad
24/09/2026
Inyección SQL alta en java110 MicroCommunity 2.0 expone servidores empresariales
Se identificó una vulnerabilidad de inyección SQL (CVSS 7.3) en java110 MicroCommunity versiones hasta 2.0, específicamente en el endpoint fallBack API de BusinessApi.java. Un atacante remoto puede manipular el parámetro fallBackSql para ejecutar comandos SQL arbitrarios, comprometiendo bases de datos en servidores corporativos. El exploit está públicamente disponible y ya es utilizado en ataques activos.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/09/2026
[CVE-2026-96751] A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a081…
A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. This affects the function setSync of the file /ajax/add_project.php. Such manipulation of the argument conn_settings leads to sql injection. The attack may be launched remotely. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are…
M Alto vulnerabilidad
24/09/2026
[CVE-2026-96762] A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the fu…
A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegment of the component RPC Path Handler. This manipulation of the argument client_id/segment_id causes authorization bypass. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosur…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96603] A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_lo…
A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions.php of the component Admin Handler. Such manipulation of the argument adminid leads to missing authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release syst…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96604] A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the functi…
A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the file engine/modules/search.php of the component Search Module. The manipulation of the argument story leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did n…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96601] A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of t…
A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of the component Admin Login Handler. The manipulation of the argument id/password results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. This product implements a rolling release for ongoing delivery, which means version informati…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96602] A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file…
A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php of the component Customer Login Handler. This manipulation of the argument username/password causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continu…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-75887] A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal …
A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by manipulating the `lng` and `ns` query parameters in the `/locales/resource.json` endpoint. This allows the attacker to read sensitive `*.json` files from the pod filesystem, including plugin manifests and configuration files. Furthermore, this flaw can enable path traversal against …
M Alto vulnerabilidad
23/09/2026
[CVE-2026-19125] The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all version…
The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a mismatch, the function only assigns a WP_Error to a local variable and continues executi…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96556] A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function …
A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the file AddCashierCode.php. Executing a manipulation of the argument uname/pass/role/status can lead to improper authorization. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not res…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-6935] IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executabl…
IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequately restricting search path resolution. As a result, an attacker with local system access can manipulate the search path environment to execute untrusted or malicious code.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96889] A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincl…
A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94183] Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page…
Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen mode while the app is running in the background. A remote attacker can exploit this via a specially crafted website to render fake UI elements, such as a spoofed address bar, misleading the user about the origin of displayed content and increasing the risk of phishing.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-84714] A flaw was found in the automation-controller input-validation guard sanitize_jinj…
A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop at the first interior '}' or '%' character, so a Jinja expression containing an inner brace (for example an empty dict) is accep…