Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 2790 resultados ✕ Limpiar búsqueda
22,394
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1258
Esta semana
RSS
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71909] Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime functio…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability is caused by insufficient filtering of the time field before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the device's web mana…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71910] Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability is caused by insufficient validation of the CMD0, CMD3, and CMD6 fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative credentials for the …
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71911] Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The …
Multiple DrayTek VigorAP models contain a buffer overflow vulnerability in the setLan function. The vulnerability is caused by missing length checks during memory copy operations involving the lanVlanId0, lanIp, and lanNetmask fields. A remote attacker can trigger this vulnerability via crafted input, causing a denial of service or potentially executing arbitrary commands. Exploitation requires va…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71904] Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform fun…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerability is caused by insufficient filtering of dangerous characters before the event_code field is concatenated into a system command. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid a…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-71905] Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings func…
Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerability is caused by insufficient filtering of the backupkey, backuptype, and realtime fields before command execution. A remote attacker can trigger this vulnerability via crafted input to execute arbitrary commands with root privileges. Exploitation requires valid administrative cr…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78465] A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX…
A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit builds only. When processing a PCX image file, the plugin calculates memory allocation sizes based on the image dimensions and the number of color planes. If a crafted file sets the number of planes to 4 alongside sufficiently large dimensions, the calculation exceeds the 32-bit integer limit and overflows, resulting in an undersize…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78367] A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source arc…
A vulnerability was found in RPM's rpmbuild tarball processing. When processing a crafted source archive, the getTarSpec() function in tools/rpmbuild.cc passes an attacker-controlled tar archive member name to rpmExpand() as part of a %{basename:...} macro expression. A specially crafted .spec member name can therefore inject RPM macros, including Lua expressions, resulting in arbitrary code execu…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-76848] TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression …
TypeORM's SelectQueryBuilder.distinctOn accepts an array of strings and stores it on the expression map without validation. For PostgreSQL-family drivers, createSelectDistinctExpression in src/query-builder/SelectQueryBuilder.ts joins that array and interpolates the result into the generated statement as SELECT DISTINCT ON (values), with no escaping, quoting, identifier validation or allowlist, an…
M Alto vulnerabilidad
24/08/2026
Vulnerabilidad XSS sin autenticación en Urna versiones ≤2.6.2 (CVSS 7.1)
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) sin autenticación en Urna versiones 2.6.2 e inferiores que permite a atacantes inyectar código malicioso y comprometer sesiones de usuarios. Esta vulnerabilidad afecta especialmente a plataformas de votación y gestión electoral en organismos públicos y privados de LATAM. El riesgo es alto dado que no requiere credenciales previas para explotarse.
M Alto vulnerabilidad
24/08/2026
Eliminación arbitraria de archivos sin autenticación en ShopBuilder Pro ≤ 2.2.0
ShopBuilder Pro, extensión de Elementor para WooCommerce, presenta una vulnerabilidad alta (CVSS 8.6) que permite a atacantes no autenticados eliminar archivos arbitrarios del servidor. Afecta directamente a tiendas en línea y sitios de comercio electrónico en México y LATAM que utilizan versiones anteriores a 2.2.1. El riesgo es severo: pérdida de datos altas, degradación de servicios y potencial exposición de información sensible.
M Alto vulnerabilidad
24/08/2026
[CVE-2026-19200] The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other is…
The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL function, the global artifact repository is used which allows callers to overwrite existing artifacts without the required permissions.  The attacker need only have the NOTEBOOK_EDIT permission (e.g. an analyst role) to be able to call this function.
M Alto vulnerabilidad
23/08/2026
[CVE-2026-9769] justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial o…
justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBuilder.finish() unconditionally calls _populate_selectedcontent(), which recursively traverses the DOM tree via _find_elements()/_find_element() without a depth bound. An attacker who can supply HTML for parsing can provide deeply nested elements (e.g.…
M Alto vulnerabilidad
23/08/2026
Vulnerabilidad alta en GitLab CE/EE permite ejecución remota de código
GitLab ha reportado una vulnerabilidad de path traversal en el registro de paquetes que afecta versiones 18.8 a 19.2.1, permitiendo a usuarios autenticados ejecutar código remoto. Esta afecta directamente a empresas en LATAM que utilizan GitLab como plataforma de CI/CD y gestión de repositorios. El CVSS 8.5 indica severidad alta, requiriendo acción inmediata en entornos productivos.
M Alto vulnerabilidad
23/08/2026
[CVE-2026-77115] Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into pop…
Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.
M Alto vulnerabilidad
23/08/2026
Vulnerabilidad de inyección de código en CHIRP permite ejecución remota vía archivos CSV malformados
CHIRP (chirpmyradio) versiones anteriores a 39178db contiene una vulnerabilidad de inyección eval en el controlador Kenwood ITM que permite a atacantes ejecutar código arbitrario mediante archivos CSV especialmente diseñados. Esto afecta a operadores de radiocomunicaciones y empresas que utilizan esta herramienta para configuración de equipos en México y Latinoamérica.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
22/08/2026
Vulnerabilidad alta en docker-socket-proxy permite lectura no autorizada de archivos en contenedores
docker-socket-proxy no valida correctamente los endpoints de lectura en el namespace /containers de la API de Docker cuando la variable CONTAINERS está configurada, permitiendo a atacantes acceder a archivos arbitrarios y descargar sistemas de archivos completos de contenedores. Esta vulnerabilidad afecta directamente a infraestructuras containerizadas en empresas LATAM que ejecutan Docker en entornos multi-inquilino o con segregación insuficiente de permisos.
M Alto vulnerabilidad
22/08/2026
Vulnerabilidad alta en NLTK: lectura arbitraria de archivos locales en versiones anteriores a 3.10.0
NLTK anterior a la versión 3.10.0 contiene una vulnerabilidad que permite la lectura arbitraria de archivos locales mediante StreamBackedCorpusView, eludiendo los controles de pathsec.ENFORCE al llamar directamente a builtins.open(). Un atacante que controle el parámetro fileid puede acceder a archivos sensibles del sistema, credenciales de aplicaciones y datos confidenciales, independientemente de la configuración de seguridad habilitada. Afecta principalmente a aplicaciones de procesamiento de lenguaje natural desplegadas en entornos empresariales de LATAM.
M Alto vulnerabilidad
22/08/2026
[CVE-2026-2996] The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to I…
The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and including, 1.6.21. This is due to a logic flaw in the 'validate_cart_data' function. This makes it possible for unauthenticated attackers to bypass required paid addons and complete purchases at the base product price only, effectively stealing pro…
M Alto vulnerabilidad
22/08/2026
[CVE-2026-57998] better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by inte…
better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option into a command string in src/handlers/handleInput.ts without validation or quoting, then passes that string to child_process.exec() in index.ts, which spawns a shell. A registry value containing shell metacharacters such as a semicolon, pipe, or command …
M Alto vulnerabilidad
21/08/2026
Escalada de privilegios alta en LeafWiki versiones 0.1.0 a 0.10.0 (CVE-2026-53527)
LeafWiki, plataforma wiki autohospedada, contiene una vulnerabilidad de escalada de privilegios (CVSS 8.8) en su API de actualización de usuarios. Un atacante autenticado puede modificar su rol y escalar permisos de usuario regular a administrador, comprometiendo el control de acceso de la instancia. El riesgo es alta para empresas en LATAM que usan LeafWiki como repositorio interno de conocimiento sin restricciones de registro público.