Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI Noticias ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 5716 resultados ✕ Limpiar búsqueda
22,417
Total alertas
4761
Críticas
17025
Altas
8
Ransomware
1263
Esta semana
RSS
M Alto vulnerabilidad
17/09/2026
[CVE-2026-86864] pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job/<sid>/obj…
pgAdmin 4's Backup tool appended the client-supplied 'database' field from the /backup/job//object request to the pg_dump argument vector as a bare trailing positional argument, without validation. Because pg_dump parses its options with getopt_long, which permutes arguments, a value beginning with a dash was interpreted as an option rather than as a database name. A value such as --file=/abs…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-81515] Steeltoe is an open source project that provides a collection of libraries that helps users build cl…
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. From 4.0.0 until 4.3.0, EurekaDiscoveryClient deserializes the registry response as one unit, and an unrecognized actionType or status, a non-Boolean isCoordinatingDiscoveryServer, or a nonnumeric timestamp can abort the entire response. A principal that can register or upda…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92987] roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsi…
roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count. Attackers can craft XML documents with tens of thousands of attributes on a single element to consume excessive CPU time and cause denial of service.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92984] HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables inst…
HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of cookies alone, allowing unauthenticated attackers to fixate victim sessions. Attackers can obtain a valid session identifier, send victims a crafted link containing it, and replay the identifier after the victim authenticates to hijack their account and access.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-87742] A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a …
A flaw was found in quarkus-websockets-next. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by streaming messages over a single connection faster than the application can process them. Due to unbounded message buffering and a lack of read backpressure, this rapidly exhausts heap space, leading to a java.lang.OutOfMemoryError that crashes the Java Virtual Machine (JV…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-85077] Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0…
Sanic is an opensource python web server/framework. Prior to version 24.12.1, and in version 25.12.0, the HTTP/1.1 response pipeline in sanic/response/types.py serializes response header names and values without rejecting carriage-return or line-feed characters. Applications that place attacker-controlled data in response.headers, file(..., filename=...), or cookie path and domain attributes can t…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-81445] Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Man…
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-81446] Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request For…
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-77614] Opencast is a free, open-source platform to support the management of educational audio and video co…
Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to versions 19.7 and 20.2, the default security configuration in etc/security/mh_default_org.xml accepts a client-selected JSESSIONID from the ;jsessionid= URL path parameter and does not replace it when the victim logs in. An unauthenticated attacker can send a crafted link to a victim…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-80356] Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive …
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-63459] Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in pac…
Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrator-controlled description to a live element's innerHTML and then reading textContent. Active resource markup can execute an event handler during the innerHTML assi…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92972] SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route e…
SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV transfer routing table. Attackers can supply arbitrary rank_ip and rank_port values to redirect decode workers to attacker-controlled endpoints, causing denial of service or disclosure of KV transfer metadata including s…
M Alto vulnerabilidad
17/09/2026
[CVE-2026-92954] vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3…
vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and
M Alto vulnerabilidad
17/09/2026
[CVE-2026-81442] Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Man…
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering and Unauthorized access.
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66631] Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
Administrator SQL Injection in MC Woocommerce Wishlist

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66625] Administrator SQL Injection in WC Vendors Marketplace <= 2.7.2.1 versions.
Administrator SQL Injection in WC Vendors Marketplace
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66630] Administrator SQL Injection in PublishPress Series <= 3.1.3 versions.
Administrator SQL Injection in PublishPress Series
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66624] Administrator SQL Injection in WPMasterToolKit <= 2.22.0 versions.
Administrator SQL Injection in WPMasterToolKit
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66618] Administrator SQL Injection in WP Maps <= 4.9.9 versions.
Administrator SQL Injection in WP Maps
M Alto vulnerabilidad
17/09/2026
[CVE-2026-66619] Administrator SQL Injection in Newsletters <= 4.18 versions.
Administrator SQL Injection in Newsletters