Empresa
¿Quiénes somos? Visión y Valores
Herramientas
Email Checker Vigía DNS SSL Checker Password Strength HTTP Headers
Alertas
Todas las alertas Vulnerabilidades Incidentes Solo críticas En CISA KEV
Editorial
Análisis técnico ¿Cuál es mi IP?
Blog
Blog 2MCI ISO 27001 Amenazas LATAM Recursos Gratuitos eBook Gratuito Newsletter Podcast / YouTube
Empresa
Servicios Contacto Suscribirse al Newsletter
🆕 Nuevo en 2MCI
✨ Crear cuenta gratis 🛠️ Ver herramientas sin registro
Ya tengo cuenta
🔒 Iniciar sesión
Equipo
🏠 Portal interno 2MCI
Seguridad de la Información

Alertas de Seguridad de la Información

Vulnerabilidades explotadas activamente, incidentes y análisis relevantes para México y LATAM. Actualizado automáticamente desde fuentes oficiales.

48 vulnerabilidades en CISA KEV — explotación activa confirmada Ver todas →
Última alerta publicada ahora mismo
Buscando: "Ni" — 3226 resultados ✕ Limpiar búsqueda
13,566
Total alertas
3081
Críticas
10213
Altas
8
Ransomware
1783
Esta semana
RSS
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-75140] jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnera…
jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attackers to exhaust JVM heap memory by supplying a deeply nested XML document with uniquely-namespaced elements. The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers ca…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-19611] A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode …
A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to ASCII equivalents. A remote attacker can more easily guess affected passwords by using an ASCII-only dictionary against accounts whose passwords were intended to include those non-ASCII characters, leading to unauthorized access.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76996] A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impact…
A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/view_order.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-16928] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-16924] IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of ser…
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory offset during IPsec decapsulation.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76990] A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue …
A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76633] WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that a…
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can manipulate the redir parameter to point to alterar_senha.php, routin…

📬 Alertas semanales SI directo en tu email

Las vulnerabilidades más críticas para LATAM, con contexto y recomendaciones accionables. Gratis.

Suscribirme →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76635] baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows au…
baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-controlled table names and configuration values directly into SQL statements across sequence update, CSV export, and table management operations. Attackers can chain a backup restore code injection flaw, where PHP code outside class definitions in schema…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-76987] A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. …
A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute::GetAttrData/CipAttribute::SetAttrData of the file ciptypes.h of the component Generic Attribute Logic. Performing a manipulation results in memory corruption. It is possible to initiate the attack remotely. The exploit has been released to the publi…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-74011] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i…
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9.
M Alto vulnerabilidad
Hace 4 días
Inyección SQL en eShipper Commerce <= 2.16.13 afecta aplicaciones de comercio electrónico
Se ha identificado una vulnerabilidad alta de inyección SQL en eShipper Commerce versión 2.16.13 y anteriores que permite a atacantes comprometer bases de datos de suscriptores. Esta vulnerabilidad (CVSS 8.5) afecta directamente a plataformas de e-commerce en México y Latinoamérica que utilizan este sistema de gestión. El acceso no autorizado a datos sensibles de clientes representa un riesgo regulatorio bajo LGPD, LSSI-CE y leyes locales de protección de datos.
M Alto vulnerabilidad
Hace 4 días
Control de Acceso Roto sin Autenticación en EPROLO Dropshipping <= 2.4.2
Se ha identificado una vulnerabilidad de control de acceso roto sin autenticación en EPROLO Dropshipping versiones 2.4.2 y anteriores, con puntuación CVSS de 7.1. Esta falla permite a actores no autenticados acceder a funcionalidades sensibles del sistema, comprometiendo datos de inventario, pedidos y configuraciones altas de tiendas dropshipping en México y Latinoamérica. El impacto es significativo para PyMEs que dependen de esta plataforma para sus operaciones de comercio electrónico.
M Alto vulnerabilidad
Hace 4 días
Control de acceso roto sin autenticación en Koji versiones <= 2.2.1
Se ha identificado una vulnerabilidad de control de acceso quebrantado en Koji
M Alto vulnerabilidad
Hace 4 días
XSS no autenticado en NotificationX Pro versiones <= 3.1.4 (CVSS 7.1)
Se ha identificado una vulnerabilidad de Cross Site Scripting (XSS) no autenticado en NotificationX Pro hasta la versión 3.1.4, que permite a atacantes inyectar código malicioso sin credenciales. Esta falla afecta directamente a plataformas de comercio electrónico y sitios web en México y Latinoamérica que utilizan este plugin para notificaciones. El acceso no autorizado al código del cliente expone datos de usuarios y sesiones activas.
M Alto vulnerabilidad
Hace 4 días
Inyección SQL en WP w3all phpBB <= 3.0.5 afecta cuentas de suscriptores
Se ha identificado una vulnerabilidad de inyección SQL en WP w3all phpBB versiones 3.0.5 y anteriores que permite a usuarios suscritos ejecutar comandos SQL arbitrarios. Esta falla (CVSS 8.5) impacta directamente sitios WordPress que integran foros phpBB, afectando potencialmente bases de datos de clientes, transacciones y datos sensibles. En LATAM, donde muchos portales de e-commerce y comunidades online utilizan esta integración, la exposición es alta.

🛡 ¿Estás expuesto a alguna de estas vulnerabilidades?

Evaluación gratuita inicial con el equipo 2MCI: identifica exposición y plan de remediación.

Habla con un experto →
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-73197] A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by se…
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/migration/migration.py` endpoint. This can force the migration handler to read attacker-controlled request bodies fully into memory, leading to increased memory usage, slower request handling, and potential service disruption or denial of service.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-73198] A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `…
A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitrarily large request body. This can cause the service to consume excessive memory, leading to memory exhaustion, degraded responsiveness, and a denial of service (DoS) condition.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-18917] A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerabil…
A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This flaw allows crafted values to bypass a size check, leading to an undersized memory buffer. Subsequently, real NUMA node data can overwrite this buffer. This heap buffer overflow can corrupt the root libvirt daemon's memory, potentially leading to a denia…
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-14948] A low privileged remote attacker can hijack an active administrative session without needing to know…
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives.
M Alto vulnerabilidad
Hace 4 días
[CVE-2026-14951] An low privileged remote attacker can cause authenticated users to perform unintended actions in the…
An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.