Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada hace 1 hora
Buscando: "Perl" — 356 resultados ✕ Limpiar búsqueda
22,162
Total alertas
4698
Críticas
16876
Altas
8
Ransomware
1037
Esta semana
RSS
M Alto vulnerabilidad
30/08/2026
[CVE-2026-82654] SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, …
SiYuan before v3.8.1 fails to properly escape block name, alias, and memo fields in hint, backlink, and breadcrumb rendering functions. Attackers can set a block's name to contain HTML/script tags that execute when another user views documents referencing or displaying that block.
M Alto vulnerabilidad
29/08/2026
[CVE-2026-76548] The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end fil…
The User Profile Builder WordPress plugin before 4.0.1 does not properly restrict its front-end file upload feature, granting unauthenticated visitors capabilities reserved to privileged roles. This allows them to list the site's media library and to modify unpublished posts, pages and media items belonging to other users.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82289] Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host w…
Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab., or github. prefix regardless of known-hosts list membership. Attackers can submit URLs with attacker-controlled hostnames to trigger outbound connections to arbitrary hosts and disclose GitHub personal access tokens via HTTP basic credentials.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-82281] Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_con…
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.
M Alto vulnerabilidad
28/08/2026
[CVE-2026-14558] The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions …
The User Frontend WordPress plugin before 4.3.10 does not properly validate field type definitions and deserialises user-controlled post metadata when rendering submitted posts, allowing users with Editor-level access and above to inject arbitrary PHP objects, which can lead to remote code execution when a suitable POP chain is present on the site.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-81699] openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in cra…
openssl_encrypt versions before 1.4.9 fail to properly validate key derivation function costs in crafted files, allowing attackers to trigger unbounded memory and CPU exhaustion during pre-authentication processing. Attackers can supply malicious files with excessive KDF parameters to exhaust system resources and crash or wedge the process before password verification occurs.
M Alto vulnerabilidad
27/08/2026
[CVE-2026-66155] A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-n…
A vulnerability has been identified in Element maps-ng V47 (All versions < V47.12.3), Element maps-ng V48 (All versions < V48.11.3), Element maps-ng V49 (All versions < V49.16.1). The si-map component does not properly neutralize user-controllable input of the points property that is used to render the tooltip label of map pins. This could allow an attacker to craft a malicious URL that, when loa…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
27/08/2026
Vulnerabilidad de escalada de privilegios en CodeMeter Runtime (CVE-2026-81572)
La herramienta cmu.exe en CodeMeter Runtime crea archivos temporales predecibles sin validar reparse points de NTFS (junctions y symbolic links), permitiendo que un atacante local redirija operaciones de archivo hacia rutas arbitrarias del sistema. Dado que CodeMeter ejecuta con privilegios de Sistema, esta vulnerabilidad posibilita escalada de privilegios y comprometer servidores, bases de datos y aplicaciones altas en infraestructuras de LATAM que dependan de este software de protección de licencias.
M Alto vulnerabilidad
26/08/2026
[CVE-2026-55228] Weblate is a web-based continuous localization platform used to manage software translations. In ver…
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via these unvalidated requests, a user could grant access to projects they were not au…
M Alto vulnerabilidad
26/08/2026
[CVE-2026-58089] When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach P…
When a process calls execve(2) to execute a setuid or setgid image, hwpmc(4) is supposed to detach PMCs owned by unprivileged processes. An inverted check meant that this scenario was not handled properly. An unprivileged local user who has attached PMCs to a process can continue monitoring it after the process executes a setuid or setgid binary, contrary to the intended policy.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-79655] A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local a…
A flaw was found in sos clean, a utility within the sos package. This vulnerability allows a local attacker to perform arbitrary file creation or overwrite. By crafting a malicious tar archive, an attacker can exploit a path traversal issue during tar extraction, where symlink and hardlink targets are not properly validated. This enables the attacker to write files to arbitrary locations on the sy…
M Alto vulnerabilidad
25/08/2026
Vulnerabilidad alta en Ech0 anterior a 4.7.3 permite acceso autenticado perpetuo por tokens no revocados
Ech0 antes de la versión 4.7.3 presenta un fallo grave en la revocación de tokens de acceso configurados con opción de no expiración, permitiendo a atacantes mantener acceso autenticado permanente tras robo de credenciales. Tres mecanismos de revocación fallan simultáneamente: logout genera pánico en campo ExpiresAt nulo, RevokeToken se omite cuando remainTTL es cero, y eliminación administrativa no registra en lista negra el JTI, dejando tokens JWT robados válidos criptográficamente. Afecta sistemas de autenticación en infraestructuras altas de empresas mexicanas y latinoamericanas.
M Alto vulnerabilidad
25/08/2026
[CVE-2026-78654] A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the funct…
A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.1 will fix this i…
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78180] A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the fun…
A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was …
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78181] A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#se…
A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a manipulation can lead to improperly controlled modification of object prototype attributes. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem ea…

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
24/08/2026
[CVE-2026-78178] A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/j…
A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated remotely. The reported GitHub issue was closed with the label "not planned".
M Alto vulnerabilidad
22/08/2026
Vulnerabilidad alta en docker-socket-proxy permite lectura no autorizada de archivos en contenedores
docker-socket-proxy no valida correctamente los endpoints de lectura en el namespace /containers de la API de Docker cuando la variable CONTAINERS está configurada, permitiendo a atacantes acceder a archivos arbitrarios y descargar sistemas de archivos completos de contenedores. Esta vulnerabilidad afecta directamente a infraestructuras containerizadas en empresas LATAM que ejecutan Docker en entornos multi-inquilino o con segregación insuficiente de permisos.
M Alto vulnerabilidad
19/08/2026
[CVE-2025-36254] IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 …
IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authentication due to improperly encoding of DSCLI command output to obtain sensitive information or cause a denial of service.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-16869] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to improperly scrubbed environment variables.
M Alto vulnerabilidad
19/08/2026
[CVE-2026-20320] A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an una…
A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML me…