Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 49 min
Buscando: "Ni" — 5708 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1253
Esta semana
RSS
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad alta de ejecución remota de código en plugin WP Photo Album Plus para WordPress
El plugin WP Photo Album Plus para WordPress es vulnerable a ejecución remota de código (RCE) en todas las versiones debido a sanitización insuficiente en nombres de archivo cargados. La vulnerabilidad reside en la función wppa_image_magick, donde escapeshellcmd() se aplica al comando completo en lugar de entrecomillar argumentos individuales antes de ejecutar comandos ImageMagick via exec(). Esto afecta directamente a sitios WordPress en México y Latinoamérica que dependen de este plugin para galerías de fotos.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad XSS almacenado en plugin Asset CleanUp para WordPress afecta versiones hasta 1.4.0.5
El plugin Asset CleanUp: Page Speed Booster para WordPress contiene una vulnerabilidad de Cross-Site Scripting (XSS) almacenado que permite a atacantes no autenticados inyectar scripts maliciosos a través de comentarios. Los scripts se ejecutan cuando usuarios acceden a páginas comprometidas, afectando sitios web en México y Latinoamérica que utilizan este plugin para optimización de velocidad. Con CVSS 7.2, representa un riesgo alto para plataformas de comercio electrónico, portales corporativos y blogs que dependen de WordPress.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad XSS almacenado alta en SiYuan 3.8.4 permite ejecución de comandos del sistema
SiYuan versiones hasta 3.8.4 no sanitiza nombres de notebooks en el diálogo del selector de notas diarias, permitiendo inyección de HTML y JavaScript. Un atacante puede crear notebooks con payloads maliciosos que se ejecutan con acceso a Node.js en el renderer de Electron, comprometiendo la integridad del sistema operativo del usuario. El riesgo es alta (CVSS 8.8) para equipos que usan SiYuan como herramienta de documentación corporativa o gestión de conocimiento en entornos LATAM.
M Alto vulnerabilidad
19/09/2026
Vulnerabilidad de XPS almacenado en SiYuan hasta versión 3.8.4 permite ejecución de código
SiYuan versiones 3.8.4 y anteriores no escapan correctamente atributos de estilo en encabezados al renderizar esquemas y marcadores, permitiendo inyección de XPS almacenado. Atacantes pueden suministrar notebooks maliciosos o explotar endpoints administrativos para ejecutar código malicioso en el renderer Electron con acceso total al sistema. Afecta principalmente a usuarios con sincronización de datos o ambientes colaborativos en LATAM.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-71418] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, DNS-over-HTTP/2 processing in rust/src/http2/http2.rs retains previously processed HTTP/2 DATA frame contents instead of clearing the internal buffer. Multiple DATA frames with the EndOfStream flag set can grow the buffer to its 65 KiB limit while causing al…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-63452] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, the HTTP/1 parser limits decompression work per transaction but does not limit how many small brotli compression bombs a single flow can submit. With response-body-decompress-layer-limit enabled, repeated compressed responses make the decompression paths in …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-63446] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until 8.0.6, AppLayerParserSetTransactionInspectId() in src/app-layer-parser.c uses an inverted guard and marks only already-inspected transactions as inspected. On flows passed by a pass rule or pass-the-flow exception policy, detection is skipped, so completed transact…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-63447] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until 8.0.6, the FTP parser in src/app-layer-ftp.c can continue allocating transactions after app-layer.protocols.ftp.max-tx is reached while processing one large chunk of FTP command data. The oversized transaction list is repeatedly processed with quadratic complexity …
M Alto vulnerabilidad
18/09/2026
[CVE-2026-57227] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.0 until 7.0.17 and 8.0.6, the MQTT parser in rust/src/mqtt/mqtt.rs permits repeated PUBREC or PUBREL messages to be appended to one transaction without a limit. Crafted MQTT traffic can grow transaction state indefinitely, consuming CPU and memory and causing slowdown or d…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-57228] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 7.0.13 until 7.0.17, the SMTP MIME quoted-printable decoder in src/util-decode-mime.c can read one byte past a heap buffer when a quoted-printable escape sequence is split across traffic chunks and the following chunk contains exactly one byte. Crafted SMTP traffic can trigger…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-57223] Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M…
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.17 and 8.0.6, the Windows service installation and parameter-update logic in src/win32-service.c can pass an unquoted service ImagePath to CreateServiceA. When Suricata is installed below a path containing spaces and an earlier path component is writable by a local low…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-84071] IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector p…
IBM Guardium Data Protection 12.2 is vulnerable to OS command injection in the Universal Connector plugin upload functionality. A privileged authenticated attacker can provide a malicious filename that is incorporated into a shell command executed by the application, potentially resulting in arbitrary command execution with root-level privileges.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61819] pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, …
pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jobmon is installed and part_config.jobmon is true, exception handlers in multiple pg_partman functions place p_parent_table verbatim inside a SQL string literal used to call pg_jobmon.add_job(). A partman_user can create a parent-table name containing a single quote that terminates the lite…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-61721] FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6…
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or fluid_sample_sanitize_loop(). A crafted DLS file can place sample loop points beyond the sample buffer, causing out-of-bounds reads during audio rendering…
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11727] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11725] IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arb…
IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11726] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensit…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.
M Alto vulnerabilidad
18/09/2026
[CVE-2026-11716] IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denia…
IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.
M Alto vulnerabilidad
18/09/2026
[CVE-2021-48008] Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to …
Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of input sanitization or parameterization through UNION-based injection techniques to extract sensitive data from the underlying database. Exploitation evidence was firs…
M Alto vulnerabilidad
18/09/2026
[CVE-2019-25776] Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers…
Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET parameter in the mobile plugin endpoint. Attackers can bypass space-based filter controls by wrapping SQL keywords in parentheses to perform UNION-based injection and extract sensitive data including admi…