Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
Nuevo en 2MCI
Crear cuenta gratis Ver herramientas sin registro
Ya tengo cuenta
Iniciar sesión
Equipo
Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ui" — 2785 resultados ✕ Limpiar búsqueda
22,181
Total alertas
4701
Críticas
16892
Altas
8
Ransomware
1055
Esta semana
RSS
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102114] A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administr…
A command injection vulnerability in Kiteworks could allow a high-privileged authenticated administrator to execute arbitrary operating-system commands as root on the affected appliance node. Successful exploitation requires an administrative account with elevated privileges.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102108] An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serializ…
An authenticated administrator of Kiteworks Email Protection Gateway could submit a crafted serialized object to a cluster management interface that was deserialized without sufficient validation, potentially allowing arbitrary code execution in the context of the gateway service account. Exploitation requires an administrator account holding a specific queue-management privilege.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102109] A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the…
A SQL injection vulnerability existed in Kiteworks Secure Data Forms, where a value derived from the authenticated user's stored account data was incorporated into a database query without proper sanitization. An authenticated user could potentially influence that value to inject SQL. Exploitation requires an authenticated session and applies only to deployments where a specific optional feature i…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102098] Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerabi…
Kiteworks Core before version 9.5.0 is vulnerable to SQL Injection. A stored SQL injection vulnerability in a Kiteworks administrative reporting feature could allow an authenticated administrator to read sensitive data from the underlying database and to affect the availability of the service. Exploitation requires an existing, authenticated administrative account with access to the affected repor…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102099] Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction o…
Kiteworks Core before version 9.5.0 is vulnerable to Arbitrary File Write. An improper restriction of a user-supplied file path in a Kiteworks administrative export feature could allow an authenticated administrator to write a file to an arbitrary location on the underlying host, potentially leading to command execution on the appliance. Exploitation requires an existing, authenticated administrat…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-101885] ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerabilit…
ZeroClaw versions before 0.8.5 built with plugins-wasm feature contain a path traversal vulnerability in plugin installation that fails to validate the wasm_path manifest field. Attackers can convince users to install crafted plugins that write arbitrary files to paths outside the plugins directory, such as shell startup files, enabling code execution.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-97256] Editor PHP Object Injection in Page Builder by SiteOrigin <= 2.36.0 versions.
Editor PHP Object Injection in Page Builder by SiteOrigin

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-53605] Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image fo…
Reachy Mini ISO for Wireless contains the necessary files to build a custom Raspberry Pi OS image for the Reachy Mini Wireless robot, using pi-gen. Prior to version 0.2.4, the Reachy Mini Wireless OS image shipped with an overly broad sudoers entry granting the pollen daemon user (uid 1000) passwordless sudo access to /usr/bin/systemctl with no subcommand or argument restriction. This is a local p…
M Alto vulnerabilidad
30/09/2026
[CVE-2026-102391] Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder
M Alto vulnerabilidad
30/09/2026
[CVE-2026-100510] Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid <= 1.27.14 versions.
Unauthenticated Cross Site Scripting (XSS) in Post and Page Builder by BoldGrid
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47594] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user …
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, data tampering, and information disclosure.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47588] NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause …
NVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service and information disclosure.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47589] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user …
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and information disclosure.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-47590] NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user …
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by issuing a sequence of driver commands. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and information disclosure.
M Alto vulnerabilidad
30/09/2026
[CVE-2026-97289] Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master <= 11.2.6 versions.
Unauthenticated Cross Site Scripting (XSS) in Quiz And Survey Master

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
30/09/2026
[CVE-2026-96831] Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions.
Contributor PHP Object Injection in Themify Builder
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94082] Author SQL Injection in Quiz Cat <= 3.1.1 versions.
Author SQL Injection in Quiz Cat
M Alto vulnerabilidad
30/09/2026
[CVE-2026-94076] Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO
M Alto vulnerabilidad
30/09/2026
[CVE-2026-92121] In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves…
In the WSS4J streaming (StAX) code, a signature reference using the WS-Security STR-Transform leaves an internal "inside signed content" flag permanently set. The WS-SecurityPolicy enforcer uses that flag to decide whether an element needs checking, so it stops evaluating SignedParts and SignedElements for the rest of the message. A policy requiring the SOAP Body to be signed is then satisfied eve…
M Alto vulnerabilidad
30/09/2026
Vulnerabilidad en Apache MINA SSHD permite eludir autenticación multifactor SSH
Apache MINA SSHD, librería Java para SSH cliente-servidor, presenta una vulnerabilidad alta (CVSS 8.1) que permite eludir esquemas de autenticación multifactor configurados en servidores SSH. Afecta principalmente a infraestructuras Java en LATAM que implementan autenticación de múltiples claves públicas. La falla compromete sistemas de acceso remoto en empresas, data centers y plataformas en la nube que dependen de esta librería.