Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "X" — 12554 resultados ✕ Limpiar búsqueda
22,395
Total alertas
4758
Críticas
17006
Altas
8
Ransomware
1254
Esta semana
RSS
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad alta en shell-quote permite inyección de comandos via función quote()
La función quote() de la librería shell-quote procesa incorrectamente tokens de comentario, permitiendo que un atacante inyecte comandos shell arbitrarios mediante saltos de línea en cadenas de texto. Esta vulnerabilidad afecta aplicaciones Node.js en servidores de LATAM que utilizan shell-quote para sanitización de argumentos, pudiendo comprometer sistemas de CI/CD, contenedores Docker y plataformas de automatización.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102248] A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of t…
A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login of the component Login Endpoint. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
29/09/2026
Vulnerabilidad de autorización en REBUILD hasta v4.4.11 permite acceso no autorizado remoto
Se ha identificado una falla de seguridad en REBUILD versiones hasta 4.4.11 que afecta el módulo /commons/file-editor-save, permitiendo omitir controles de autorización mediante manipulación de parámetros (url/fileKey). Esta vulnerabilidad de severidad alta (CVSS 7.3) puede ser explotada remotamente y su código de ataque ya es público. Empresas en LATAM que usan REBUILD para gestión de contenidos están expuestas a acceso no autorizado a archivos sensibles.
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102245] A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknow…
A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the file surfsense_backend/app/routes/circleback_webhook_route.py of the component circleback Endpoint. Executing a manipulation can lead to missing authentication. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-102243] A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown p…
A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the file /api/search-source/connectors/mcp/test of the component MCP Connector Integration. Such manipulation leads to command injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosu…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-96326] The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to S…
The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses …
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101860] A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the functio…
A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::addSudoers of the file src/RaspAP/Plugins/PluginInstaller.php of the component sudo Configuration. Performing a manipulation results in improper privilege management. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101878] Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUs…
Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExternalId stored procedure as NVARCHAR(50) while the column it queries stores NVARCHAR(300), silently truncating the SSO login identifier on SQL Server deployments and allowing a user whose identity-provider identifier begins with another organization member's full 50-character iden…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101280] A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the functi…
A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_query_dmarc of the component Multi-Record Set Handler. The manipulation results in authentication bypass by spoofing. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any wa…
M Alto vulnerabilidad
29/09/2026
[CVE-2026-101281] A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerabilit…
A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_sp2_find_mailfrom_domain of the file libopendmarc/opendmarc_spf.c of the component SPF Macro Handler. This manipulation causes improper authentication. The attack is possible to be carried out remotely. The exploit has been published and may be used. Patch name: c48a74c75…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102335] Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, al…
Nginx Proxy Manager through 2.16.0 fails to restrict the advanced_config field to administrators, allowing non-admin users with manage permissions to inject arbitrary nginx directives. Attackers can inject malicious nginx configuration such as alias directives to serve arbitrary files or control routing for their assigned hosts.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102334] Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthe…
Nginx Proxy Manager through 2.16.0 lacks rate-limiting on authentication endpoints, allowing unauthenticated attackers to make unlimited password guesses against any account. Attackers can brute-force login credentials via POST /api/tokens and subsequently guess TOTP codes via POST /api/tokens/2fa to gain full session access and administrative control.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101188] A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects …
A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd.passwd_set of the file /ubus. Such manipulation leads to weak password recovery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
M Alto vulnerabilidad
28/09/2026
[CVE-2026-101091] SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks e…
SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyuan.db. Attackers can craft malicious .sy documents with non-read-only SQL statements that execute automatically during background indexing, rendering, or export operations without authentication.
M Alto vulnerabilidad
28/09/2026
[CVE-2024-42002] A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topi…
A code injection vulnerability has been discovered in the Robot Operating System 2 (ROS 2) 'ros2topic' command-line tool, affecting all ROS 2 distributions from Crystal Clemmys up to and including Lyrical Luth and Rolling Ridley. The vulnerability lies in the 'hz' verb, which reports the publishing rate of a topic and accepts a user-provided Python expression via the --filter option. This input is…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
28/09/2026
[CVE-2026-18413] The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small…
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to be not large enough". The NXP MCUX LPADC driver did not honour that contract. mcu…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-18414] The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small…
The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size field of struct adc_sequence in include/zephyr/drivers/adc.h documents that "the driver must ensure that samples are not written beyond the limit and it must return an error if the buffer turns out to be not large enough". The ADI MAX32 driver did not honour that contract. start_re…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102276] The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior…
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3.0.7, and 5.0.10, crafted brace patterns can exhaust the native stack in parseCommaParts because parseCommaParts recursively processes the remainder once per brace group and uses push.apply to pass every element of a very large comma-part array as a function argument. Patterns co…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-102278] The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior…
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3.0.8, and 5.0.11, deeply nested brace groups cause expand_() to recurse once per nesting level at comma-member and single-set expansion sites, exhausting the native stack before output limits can apply and potentially terminating the Node.js process. expand_ performs uncontrolled…
M Alto vulnerabilidad
28/09/2026
[CVE-2026-16513] The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/…
The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c before v4.3.0) validated the RTIO object handle and the sqes input array, but not the handle out-parameter. On the first loop iteration it executed *handle = sqe, storing the kernel address of the newly acquired submission-queue entry through a pointer taken verbatim from user m…