Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 5706 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
M Alto vulnerabilidad
23/09/2026
[CVE-2026-93508] The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-…
The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX action, allowing authenticated users with Subscriber-level access and above to create, modify and delete arbitrary post meta on any post, including WooCommerce products, regardless of ownership, and to manipulate stored pricing rules on a product to reduce its checkout price.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-86608] The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of i…
The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor does it bound what that route stores, allowing unauthenticated users to write unlimited data into any user's metadata and to permanently prevent that account, including an administrator's, from loading.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-14321] The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it…
The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limiting and banning, allowing unauthenticated attackers to spoof arbitrary IP addresses in order to bypass rate limiting, ban chosen addresses from the feature, and grow a stored option without bound, resulting in denial of service.
M Alto vulnerabilidad
23/09/2026
[CVE-2022-4997] The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a pay…
The jet-form-builder-stripe-gateway WordPress plugin before 1.1.0 does not sanitise and escape a payment token before using it in a SQL statement, allowing unauthenticated users to extract arbitrary data from the database, including password hashes.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91776] TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deseriali…
TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, attacker-supplied type ID. When name-based polymorphism is configured with a fallback, for example @JsonTypeInfo(use = Id.NAME, defaultImpl = ...), every distinct unrecognized type ID resolves to the same fallback deserializer but is retained as its own key in the _deserializers m…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-91777] Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs…
Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of the pending-reference accumulator for every resolved ID. The affected paths are CollectionDeserializer.CollectionReferringAccumulator.resolveForwardReference() and the equivalent implementation in MapDeserializer. When a document first creates N unresolved object-ID references in a…
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95927] A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects…
A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the file /reviewer_0/admins/assessments/pretest/exam-delete.php. Such manipulation of the argument test_id leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95926] A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted…
A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown function of the file /reviewer_0/admins/assessments/pretest/btn_functions.php?action=update. This manipulation of the argument test_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95924] A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is …
A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=add. The manipulation of the argument difficulty_id leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-95925] A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected elem…
A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown function of the file /reviewer_0/admins/assessments/databank/btn_functions.php?action=update. The manipulation of the argument difficulty_id results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96271] Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mut…
Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim albums, exposing photos and sub-albums to anyone with the link while retaining indefinite control over token settings.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-96272] ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search end…
ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the query parameter is passed unsanitized into SQL WHERE and ORDER BY clauses. Unauthenticated attackers can exploit time-based blind SQL injection techniques to extract user credentials, email addresses, and administrator password hashes for account takeover.
M Alto vulnerabilidad
23/09/2026
[CVE-2026-94367] OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulner…
OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated administrator can supply crafted backup-area configuration input that is passed to a shell command, allowing commands to execute with the privileges of the nvr user. The underlying design has been present since at least firmware 2.2.3.4. Upgrade to version 3.5…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-61685] ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list …
ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter names as SQL column identifiers (e.g. `` `article.${key}` ``). TypeORM parameterizes values but not column names, allowing unauthenticated attackers to inject SQL through crafted query string keys. Version 3.7.0…
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95819] A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca…
A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Affected by this vulnerability is an unknown functionality of the file login.php. Such manipulation of the argument user/pass leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolli…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/09/2026
[CVE-2026-18123] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause …
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to cause a denial of service due to the improper use of reflection with externally controlled input.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-17618] IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated at…
IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote unauthenticated attacker to view and modify sensitive information and cause a denial of service due to improper authorization.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-95814] Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-…
Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries, allowing revoked and not-yet-confirmed members to retain read, write, delete, and attachment access to organization ciphers. Attackers with revoked or pending membership can exploit missing status filters in get_user_collections_access_flags, get_group_collections_access_flags, …
M Alto vulnerabilidad
22/09/2026
[CVE-2026-94450] Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow…
Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated remote user to cause a denial of service by shutting down a server endpoint via a single crafted UDP datagram. Only server endpoints specifically configured to send Retry packets are affected. To remediate this issue, users should upgrade to version v1.89.0 or later.
M Alto vulnerabilidad
22/09/2026
[CVE-2026-76712] A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized ac…
A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information disclosure, or denial of service. An unauthenticated remote attacker could exploit the vulnerable system by sending specially crafted input or intercepting network communications. Successful exploitation could result in the disclosure of sensitive information, bypass of security co…