Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Dify" — 258 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1051
Esta semana
RSS
M Alto vulnerabilidad
07/09/2026
[CVE-2026-76560] A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an …
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a dir…
M Alto vulnerabilidad
04/09/2026
[CVE-2026-80116] PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics …
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection, register offset, or value. Attackers can obtain a device handle and issue arbitrary PCI …
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85619] AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in autho…
AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database rows across workspaces. Attackers can supply a victim's object ID with their own workspace ID to bypass access controls and read, modify, or delete cross-workspace data.
M Alto vulnerabilidad
04/09/2026
Vulnerabilidad de omisión de autorización en snipe-it anterior a 8.6.3 afecta gestión de usuarios
snipe-it versiones anteriores a 8.6.3 contienen una vulnerabilidad de omisión de autorización en la funcionalidad de eliminación masiva que permite a usuarios restringidos eliminar de forma reversible usuarios fuera de su alcance autorizado. Los atacantes pueden incluir IDs de usuario no autorizados en solicitudes de eliminación masiva para eludir restricciones a nivel de instancia y modificar o desactivar cuentas que no deberían poder acceder. Esta vulnerabilidad afecta directamente a empresas LATAM que utilizan snipe-it para gestión de inventario de TI.
M Alto vulnerabilidad
04/09/2026
[CVE-2026-85540] DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers …
DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85390] Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notificati…
Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and delete monitor check history to erase incident evidence.
M Alto vulnerabilidad
03/09/2026
[CVE-2026-85214] vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users …
vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, and disable accounts including administrators to cause denial of service.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
03/09/2026
[CVE-2026-76642] util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running …
util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-45730] Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0…
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project) to bypass OPA authorization checks on write paths (PUT /api/projects/{id}, DELETE /api/projects) and modify or delete any project along with all its ass…
M Alto vulnerabilidad
02/09/2026
[CVE-2026-77180] When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exi…
When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX conf…
M Alto vulnerabilidad
02/09/2026
Vulnerabilidad alta en Craft CMS: bypass de scope de sitios en mutaciones GraphQL
Craft CMS versiones anteriores a 5.10.11 contienen una vulnerabilidad que permite a atacantes con tokens limitados a un sitio acceder, modificar o eliminar entradas en otros sitios no autorizados mediante bypass de validación en resolvers GraphQL. Esta falla afecta directamente a agencias digitales y empresas que alojan múltiples proyectos en instancias compartidas de Craft CMS en LATAM.
M Alto vulnerabilidad
02/09/2026
[CVE-2026-84715] FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSu…
FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permissions can send a crafted request to grant themselves full server control, enabling unauthorized access to sensitive data, backups, and server configuration.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-73770] An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could …
An authenticated arbitrary file write vulnerability exists in AOS-CX. Successful exploitation could allow an authenticated malicious actor, under specific conditions outside the attacker's control and following a required action by another user, to create or modify arbitrary files and execute arbitrary commands as a privileged user on the underlying operating system.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-73721] Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote att…
Vulnerabilities in the API of HPE Networking Fabric Composer could allow an authenticated remote attacker to conduct SQL injection attacks against the HPE Networking Fabric Composer instance. An attacker could exploit these vulnerabilities to obtain and modify sensitive information in the underlying database potentially leading to complete compromise of the HPE Networking Fabric Composer host.
M Alto vulnerabilidad
01/09/2026
[CVE-2026-73708] A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful explo…
A business logic vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to obtain elevated privileges and modify settings beyond what is authorized by the user's existing privilege level on a vulnerable system.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad de autenticación faltante en AVideo permite modificar transmisiones programadas
AVideo presenta una vulnerabilidad alta (CVSS 8.2) en el módulo de transmisión en vivo que permite a atacantes no autenticados modificar el estado de transmisiones programadas mediante solicitudes POST manipuladas. Esta vulnerabilidad afecta principalmente a plataformas de streaming y educativas en LATAM que utilizan este software de código abierto. Los atacantes pueden deshabilitar o sabotear retransmisiones sin acceso previo al sistema.
M Alto vulnerabilidad
01/09/2026
Ejecución remota de código en LibreNMS antes de v26.5.0 por validación insuficiente
LibreNMS en versiones anteriores a 26.5.0 contiene una vulnerabilidad de ejecución remota de código (RCE) en el controlador AboutController. El parámetro de configuración snmpget se pasa directamente a shell_exec() sin validación, permitiendo que un administrador autenticado ejecute comandos arbitrarios a través del endpoint /about apuntando a ejecutables maliciosos. Afecta principalmente a proveedores de servicios de monitoreo y operadores de infraestructura en LATAM que ejecutan LibreNMS en entornos de producción.
M Alto vulnerabilidad
01/09/2026
Vulnerabilidad CSRF alta en AVideo permite manipulación de contenido sin consentimiento
AVideo contiene una vulnerabilidad de falsificación de solicitud entre sitios (CSRF) en plugin/API/set.json.php que permite a atacantes realizar acciones que modifican el estado del sistema mediante solicitudes GET manipuladas. Los atacantes pueden redirigir navegadores de usuarios a URLs maliciosas para eliminar videos, desactivar cuentas o modificar listas de reproducción sin interacción del usuario. Esta vulnerabilidad afecta especialmente a plataformas de contenido y educación en línea operadas en LATAM.
M Alto vulnerabilidad
31/08/2026
[CVE-2026-77966] The affected Ebyte product does not provide separation between limited and administrative managem…
The affected Ebyte product does not provide separation between limited and administrative management functions. A low privileged authenticated attacker could access security sensitive configuration functions and modify settings that affect the confidentiality, integrity, or availability of the device.
M Alto vulnerabilidad
29/08/2026
[CVE-2026-76548] The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end fil…
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.